mirror of
https://github.com/RfidResearchGroup/proxmark3.git
synced 2026-10-05 23:07:39 +00:00
The main loop cleared the whole PacketCommandNG payload before every call to receive_ng(), so a device sitting idle memset PM3_CMD_DATA_SIZE bytes on each pass of the loop whether anything was arriving or not. The zeroing belongs inside receive_ng_internal(), once the preamble has been read and a packet is known to be coming in, and that is where it is now. It has to be before either branch fills the payload, because neither fills all of it: an NG command writes only its own length, and an old style one only PM3_CMD_DATA_SIZE_OLD. Whatever is not written has to start at zero. Moving it also covers two callers that never had it. appmain.c has a second receive_ng() that drains the buffer on a mode switch, and iclass.c has one that picks up EML_MEMSET commands while waiting for RF. Both declare their PacketCommandNG without initialising it, and the iclass one then reads a struct out of the payload -- so a command shorter than that struct was reading stack garbage beyond its length. That is fixed as a side effect. Builds for RDV4 and PM5. Thanks to @Msprg et al