mirror of
https://github.com/BobTheBlinker/android_kernel_motorola_sm6375.git
synced 2026-10-07 20:33:58 -04:00
qcacld-3.0: Drop mcast and plaintext frags in protected network
Multicast frames should not be fragmented and plaintext frags should not be reassembeld in protected network. Fix is to drop mcast frags and plaintext frags received in protected network. Change-Id: I6629c2351884b880525c10cf9259d506af89dd10 CVE-Fixed: CVE-2020-26145 Mot-CRs-fixed: (CR) CRs-Fixed: 2860245 Reviewed-on: https://gerrit.mot.com/1929644 SME-Granted: SME Approvals Granted SLTApproved: Slta Waiver Tested-by: Jira Key Reviewed-by: Bin Liu <liubin7@motorola.com> Submit-Approved: Jira Key
This commit is contained in:
parent
e95eba2bdd
commit
5df7339711
1 changed files with 22 additions and 0 deletions
|
|
@ -453,6 +453,28 @@ ol_rx_reorder_store_frag(ol_txrx_pdev_handle pdev,
|
|||
return;
|
||||
}
|
||||
|
||||
rx_desc = htt_rx_msdu_desc_retrieve(htt_pdev, frag);
|
||||
qdf_assert(htt_rx_msdu_has_wlan_mcast_flag(htt_pdev, rx_desc));
|
||||
index = htt_rx_msdu_is_wlan_mcast(htt_pdev, rx_desc) ?
|
||||
txrx_sec_mcast : txrx_sec_ucast;
|
||||
|
||||
/*
|
||||
* Multicast/Broadcast frames should not be fragmented so drop
|
||||
* such frames.
|
||||
*/
|
||||
if (index != txrx_sec_ucast) {
|
||||
ol_rx_frames_free(htt_pdev, frag);
|
||||
return;
|
||||
}
|
||||
|
||||
if (peer->security[index].sec_type != htt_sec_type_none &&
|
||||
!htt_rx_mpdu_is_encrypted(htt_pdev, rx_desc)) {
|
||||
ol_txrx_err("Unencrypted fragment received in security mode %d",
|
||||
peer->security[index].sec_type);
|
||||
ol_rx_frames_free(htt_pdev, frag);
|
||||
return;
|
||||
}
|
||||
|
||||
if ((!more_frag) && (!fragno) && (!rx_reorder_array_elem->head)) {
|
||||
rx_reorder_array_elem->head = frag;
|
||||
rx_reorder_array_elem->tail = frag;
|
||||
|
|
|
|||
Loading…
Reference in a new issue