From 077195346252f03d67fc16dc26c4c252bbdd6aee Mon Sep 17 00:00:00 2001 From: Alok Kumar Date: Tue, 9 Jan 2018 14:41:06 +0530 Subject: [PATCH] qcacld-3.0: Fix buffer over-read issue in htt_t2h_lp_msg_handler Currently type conversion issues are for variables compl_msg and pool_numap_payload. This may cause potential buffer over-read. To address this issue add check for structure size. Change-Id: Id4804eeaf5e80a9045f1c057fa4cb9db15c1ab7d CRs-Fixed: 2148306 --- core/dp/htt/htt_t2h.c | 15 +++++++++++++++ 1 file changed, 15 insertions(+) diff --git a/core/dp/htt/htt_t2h.c b/core/dp/htt/htt_t2h.c index 5b388bf55aab..28c1d1eeec7e 100644 --- a/core/dp/htt/htt_t2h.c +++ b/core/dp/htt/htt_t2h.c @@ -410,6 +410,13 @@ static void htt_t2h_lp_msg_handler(void *context, qdf_nbuf_t htt_t2h_msg, { struct htt_mgmt_tx_compl_ind *compl_msg; int32_t credit_delta = 1; + int msg_len = qdf_nbuf_len(htt_t2h_msg); + if (msg_len < (sizeof(struct htt_mgmt_tx_compl_ind) + sizeof(*msg_word))) { + QDF_TRACE(QDF_MODULE_ID_HTT, QDF_TRACE_LEVEL_ERROR, + "Invalid msg_word lenght in HTT_T2H_MSG_TYPE_MGMT_TX_COMPL_IND"); + WARN_ON(1); + break; + } compl_msg = (struct htt_mgmt_tx_compl_ind *)(msg_word + 1); @@ -533,6 +540,14 @@ static void htt_t2h_lp_msg_handler(void *context, qdf_nbuf_t htt_t2h_msg, case HTT_T2H_MSG_TYPE_FLOW_POOL_UNMAP: { struct htt_flow_pool_unmap_t *pool_numap_payload; + int msg_len = qdf_nbuf_len(htt_t2h_msg); + + if (msg_len < sizeof(struct htt_flow_pool_unmap_t)) { + QDF_TRACE(QDF_MODULE_ID_HTT, QDF_TRACE_LEVEL_ERROR, + "Invalid msg_word lenght in HTT_T2H_MSG_TYPE_FLOW_POOL_UNMAP"); + WARN_ON(1); + break; + } pool_numap_payload = (struct htt_flow_pool_unmap_t *)msg_word; ol_tx_flow_pool_unmap_handler(pool_numap_payload->flow_id,