qcacld-3.0: Drop mcast and plaintext frags in protected network

Multicast frames should not be fragmented and plaintext
frags should not be reassembeld in protected network.

Fix is to drop mcast frags and plaintext frags received
in protected network.

Change-Id: I6629c2351884b880525c10cf9259d506af89dd10
CVE-Fixed: CVE-2020-26145
Mot-CRs-fixed: (CR)
CRs-Fixed: 2860245
Reviewed-on: https://gerrit.mot.com/1929644
SME-Granted: SME Approvals Granted
SLTApproved: Slta Waiver
Tested-by: Jira Key
Reviewed-by: Bin Liu <liubin7@motorola.com>
Submit-Approved: Jira Key
This commit is contained in:
Yeshwanth Sriram Guntuka 2021-02-02 20:33:05 +05:30 • committed by panyq6
commit 5df7339711

View file

@ -453,6 +453,28 @@ ol_rx_reorder_store_frag(ol_txrx_pdev_handle pdev,
return;
}
rx_desc = htt_rx_msdu_desc_retrieve(htt_pdev, frag);
qdf_assert(htt_rx_msdu_has_wlan_mcast_flag(htt_pdev, rx_desc));
index = htt_rx_msdu_is_wlan_mcast(htt_pdev, rx_desc) ?
txrx_sec_mcast : txrx_sec_ucast;
/*
* Multicast/Broadcast frames should not be fragmented so drop
* such frames.
*/
if (index != txrx_sec_ucast) {
ol_rx_frames_free(htt_pdev, frag);
return;
}
if (peer->security[index].sec_type != htt_sec_type_none &&
!htt_rx_mpdu_is_encrypted(htt_pdev, rx_desc)) {
ol_txrx_err("Unencrypted fragment received in security mode %d",
peer->security[index].sec_type);
ol_rx_frames_free(htt_pdev, frag);
return;
}
if ((!more_frag) && (!fragno) && (!rx_reorder_array_elem->head)) {
rx_reorder_array_elem->head = frag;
rx_reorder_array_elem->tail = frag;