From a0e2097c6a279dde2c92f3d63b19a73a17955b4f Mon Sep 17 00:00:00 2001 From: Anubhav Rawal Date: Fri, 21 Aug 2026 09:39:18 -0700 Subject: [PATCH] Validate timer command ID lower bound in xTimerGenericCommandFromTask (#1477) The task command path validated the command ID only against the upper bound. Add the corresponding lower-bound check so the accepted range is fully constrained. --- timers.c | 6 ++++-- 1 file changed, 4 insertions(+), 2 deletions(-) diff --git a/timers.c b/timers.c index 1bc40bc46..b978f4298 100644 --- a/timers.c +++ b/timers.c @@ -467,9 +467,11 @@ xMessage.u.xTimerParameters.xMessageValue = xOptionalValue; xMessage.u.xTimerParameters.pxTimer = xTimer; - configASSERT( xCommandID < tmrFIRST_FROM_ISR_COMMAND ); + /* Enforce a lower bound as well as an upper bound so that only + * valid task-issued commands are accepted here. */ + configASSERT( ( xCommandID >= tmrCOMMAND_START_DONT_TRACE ) && ( xCommandID < tmrFIRST_FROM_ISR_COMMAND ) ); - if( xCommandID < tmrFIRST_FROM_ISR_COMMAND ) + if( ( xCommandID >= tmrCOMMAND_START_DONT_TRACE ) && ( xCommandID < tmrFIRST_FROM_ISR_COMMAND ) ) { if( xTaskGetSchedulerState() == taskSCHEDULER_RUNNING ) {