From 183edd48c11b839770aa4eb5a8d7ea4a88013c6c Mon Sep 17 00:00:00 2001 From: Amit Mehta Date: Mon, 26 Sep 2022 05:31:19 -0700 Subject: [PATCH] qcacmn: Add a tid check for RX to avoid of OOB access Tid in RX frame header may be larger than MAX TID allowed value, this will lead a out of boundary array access and lead to kernel crash at last. Change is aimed to do a TID check and discard such frame when necessary. Change-Id: I11f312668a5a42d690c058550f22b0f36f952104 CRs-Fixed: 3264581 --- dp/wifi3.0/dp_rx.c | 9 ++++++++- dp/wifi3.0/dp_stats.c | 2 ++ dp/wifi3.0/dp_types.h | 2 ++ 3 files changed, 12 insertions(+), 1 deletion(-) diff --git a/dp/wifi3.0/dp_rx.c b/dp/wifi3.0/dp_rx.c index eebc90a648c0..352832d0b6c4 100644 --- a/dp/wifi3.0/dp_rx.c +++ b/dp/wifi3.0/dp_rx.c @@ -2808,8 +2808,15 @@ done: } /* Get TID from struct cb->tid_val, save to tid */ - if (qdf_nbuf_is_rx_chfrag_start(nbuf)) + if (qdf_nbuf_is_rx_chfrag_start(nbuf)) { tid = qdf_nbuf_get_tid_val(nbuf); + if (tid >= CDP_MAX_DATA_TIDS) { + DP_STATS_INC(soc, rx.err.rx_invalid_tid_err, 1); + qdf_nbuf_free(nbuf); + nbuf = next; + continue; + } + } if (qdf_unlikely(!peer)) { peer = dp_peer_get_ref_by_id(soc, peer_id, diff --git a/dp/wifi3.0/dp_stats.c b/dp/wifi3.0/dp_stats.c index b5356e6b5bee..84d3409cd460 100644 --- a/dp/wifi3.0/dp_stats.c +++ b/dp/wifi3.0/dp_stats.c @@ -6661,6 +6661,8 @@ dp_print_soc_rx_stats(struct dp_soc *soc) soc->stats.rx.rxdma2rel_route_drop); DP_PRINT_STATS("Reo2rel route drop:%d", soc->stats.rx.reo2rel_route_drop); + DP_PRINT_STATS("Rx invalid TID count:%d", + soc->stats.rx.err.rx_invalid_tid_err); } #ifdef FEATURE_TSO_STATS diff --git a/dp/wifi3.0/dp_types.h b/dp/wifi3.0/dp_types.h index 8dd06f7b1efb..637801776a70 100644 --- a/dp/wifi3.0/dp_types.h +++ b/dp/wifi3.0/dp_types.h @@ -1072,6 +1072,8 @@ struct dp_soc_stats { uint32_t peer_unauth_rx_pkt_drop; /* MSDU len err count */ uint32_t msdu_len_err; + /* Rx invalid tid count */ + uint32_t rx_invalid_tid_err; } err; /* packet count per core - per ring */