esp: check command buffer length before write(CVE-2016-4439)