qcacld-3.0: Fix buffer overread in lim_process_fils_auth_frame2

qcacld-2.0 to qcacld-3.0 propagation

The return value validation is missing for dot11fUnpackIeRSN, thus
"dot11f_ie_rsn.pmkid_count" could be larger than 4. When it is larger
than 4 there will be a buffer over-read in vos_mem_compare. Add status
check of dot11fUnpackIeRSN in lim_process_fils_auth_frame2.

Change-Id: If563ddb13bbfcad5660d136c35c39846010594e1
CRs-Fixed: 2147955
This commit is contained in:
lifeng 2017-12-12 23:03:28 +08:00 • committed by snandini
commit 70a5ee609e

View file

@ -1075,10 +1075,12 @@ bool lim_process_fils_auth_frame2(tpAniSirGlobal mac_ctx,
if (rx_auth_frm_body->authAlgoNumber != SIR_FILS_SK_WITHOUT_PFS)
return false;
dot11f_unpack_ie_rsn(mac_ctx,
if (dot11f_unpack_ie_rsn(mac_ctx,
&rx_auth_frm_body->rsn_ie.info[0],
rx_auth_frm_body->rsn_ie.length,
&dot11f_ie_rsn, 0);
&dot11f_ie_rsn, 0) != DOT11F_PARSE_SUCCESS) {
return false;
}
for (i = 0; i < dot11f_ie_rsn.pmkid_count; i++) {
if (qdf_mem_cmp(dot11f_ie_rsn.pmkid[i],