From 2cce0794e6daed030e33334e85ba08c21ad33a6a Mon Sep 17 00:00:00 2001 From: Deeksha Gupta Date: Wed, 22 Sep 2021 13:56:37 +0530 Subject: [PATCH] qcacld-3.0: Fix possible OOB in extract_peer_stats_count_tlv Currently in function extract_peer_stats_count_tlv, num_peers is copied directly to wmi_host_stats_event structure without any validation which may cause out of bound issue if num_peers provided in fixed param becomes greater than actual number of peer stats info. Fix is to validate num_peer_stats_info before populating stats_param->num_peer_stats_info_ext. Change-Id: Icfb1c4fd34d3ec9120064e14bb65e35f8539f7fd CRs-Fixed: 3032139 --- components/wmi/src/wmi_unified_mc_cp_stats_tlv.c | 7 +++++++ 1 file changed, 7 insertions(+) diff --git a/components/wmi/src/wmi_unified_mc_cp_stats_tlv.c b/components/wmi/src/wmi_unified_mc_cp_stats_tlv.c index 069e46fb1e8e..423351292d85 100644 --- a/components/wmi/src/wmi_unified_mc_cp_stats_tlv.c +++ b/components/wmi/src/wmi_unified_mc_cp_stats_tlv.c @@ -327,6 +327,13 @@ extract_peer_stats_count_tlv(wmi_unified_t wmi_handle, void *evt_buf, if (!ev_param) return QDF_STATUS_E_FAILURE; + if (!param_buf->num_peer_stats_info || + param_buf->num_peer_stats_info < ev_param->num_peers) { + wmi_err_rl("actual num of peers stats info: %d is less than provided peers: %d", + param_buf->num_peer_stats_info, ev_param->num_peers); + return QDF_STATUS_E_FAULT; + } + if (!stats_param) return QDF_STATUS_E_FAILURE;