mirror of
https://github.com/BobTheBlinker/android_kernel_motorola_sm6375.git
synced 2026-10-07 20:33:58 -04:00
qcacmn: Possible OOB read in process_fw_diag_event_data
API "fw_diag_data_event_handler" is the handler of an event WMI_DIAG_DATA_CONTAINER_EVENTID comes from FW. Arguments of this handler function come from FW. If num_data may be less than size of(struct wlan_diag_data), possible OOB while extracting event data. Fix is to add a sanity check for num_data to avoid the OOB read. Change-Id: Ia2eb62dbaa154936bdb4ea34065657d441f12810 CRs-Fixed: 3001178
This commit is contained in:
parent
3c26df2598
commit
0596d2f779
1 changed files with 1 additions and 1 deletions
|
|
@ -1693,7 +1693,7 @@ process_fw_diag_event_data(uint8_t *datap, uint32_t num_data)
|
|||
uint32_t diag_data_len; /* each fw diag payload */
|
||||
struct wlan_diag_data *diag_data;
|
||||
|
||||
while (num_data > 0) {
|
||||
while (num_data >= sizeof(struct wlan_diag_data)) {
|
||||
diag_data = (struct wlan_diag_data *)datap;
|
||||
diag_type = WLAN_DIAG_0_TYPE_GET(diag_data->word0);
|
||||
diag_data_len = WLAN_DIAG_0_LEN_GET(diag_data->word0);
|
||||
|
|
|
|||
Loading…
Reference in a new issue