mirror of
https://github.com/BobTheBlinker/android_kernel_motorola_sm6375.git
synced 2026-10-07 12:25:00 -04:00
qcacmn: Add a tid check for RX to avoid of OOB access
Tid in RX frame header may be larger than MAX TID allowed value, this will lead a out of boundary array access and lead to kernel crash at last. Change is aimed to do a TID check and discard such frame when necessary. Change-Id: I11f312668a5a42d690c058550f22b0f36f952104 CRs-Fixed: 3264581
This commit is contained in:
parent
c62a279eab
commit
183edd48c1
3 changed files with 12 additions and 1 deletions
|
|
@ -2808,8 +2808,15 @@ done:
|
|||
}
|
||||
|
||||
/* Get TID from struct cb->tid_val, save to tid */
|
||||
if (qdf_nbuf_is_rx_chfrag_start(nbuf))
|
||||
if (qdf_nbuf_is_rx_chfrag_start(nbuf)) {
|
||||
tid = qdf_nbuf_get_tid_val(nbuf);
|
||||
if (tid >= CDP_MAX_DATA_TIDS) {
|
||||
DP_STATS_INC(soc, rx.err.rx_invalid_tid_err, 1);
|
||||
qdf_nbuf_free(nbuf);
|
||||
nbuf = next;
|
||||
continue;
|
||||
}
|
||||
}
|
||||
|
||||
if (qdf_unlikely(!peer)) {
|
||||
peer = dp_peer_get_ref_by_id(soc, peer_id,
|
||||
|
|
|
|||
|
|
@ -6661,6 +6661,8 @@ dp_print_soc_rx_stats(struct dp_soc *soc)
|
|||
soc->stats.rx.rxdma2rel_route_drop);
|
||||
DP_PRINT_STATS("Reo2rel route drop:%d",
|
||||
soc->stats.rx.reo2rel_route_drop);
|
||||
DP_PRINT_STATS("Rx invalid TID count:%d",
|
||||
soc->stats.rx.err.rx_invalid_tid_err);
|
||||
}
|
||||
|
||||
#ifdef FEATURE_TSO_STATS
|
||||
|
|
|
|||
|
|
@ -1072,6 +1072,8 @@ struct dp_soc_stats {
|
|||
uint32_t peer_unauth_rx_pkt_drop;
|
||||
/* MSDU len err count */
|
||||
uint32_t msdu_len_err;
|
||||
/* Rx invalid tid count */
|
||||
uint32_t rx_invalid_tid_err;
|
||||
} err;
|
||||
|
||||
/* packet count per core - per ring */
|
||||
|
|
|
|||
Loading…
Reference in a new issue