mirror of
https://github.com/BobTheBlinker/android_kernel_motorola_sm6375.git
synced 2026-10-11 07:03:09 -04:00
qcacld-3.0: Fix buffer overread in lim_process_fils_auth_frame2
qcacld-2.0 to qcacld-3.0 propagation The return value validation is missing for dot11fUnpackIeRSN, thus "dot11f_ie_rsn.pmkid_count" could be larger than 4. When it is larger than 4 there will be a buffer over-read in vos_mem_compare. Add status check of dot11fUnpackIeRSN in lim_process_fils_auth_frame2. Change-Id: If563ddb13bbfcad5660d136c35c39846010594e1 CRs-Fixed: 2147955
This commit is contained in:
parent
920397d930
commit
70a5ee609e
1 changed files with 4 additions and 2 deletions
|
|
@ -1075,10 +1075,12 @@ bool lim_process_fils_auth_frame2(tpAniSirGlobal mac_ctx,
|
|||
if (rx_auth_frm_body->authAlgoNumber != SIR_FILS_SK_WITHOUT_PFS)
|
||||
return false;
|
||||
|
||||
dot11f_unpack_ie_rsn(mac_ctx,
|
||||
if (dot11f_unpack_ie_rsn(mac_ctx,
|
||||
&rx_auth_frm_body->rsn_ie.info[0],
|
||||
rx_auth_frm_body->rsn_ie.length,
|
||||
&dot11f_ie_rsn, 0);
|
||||
&dot11f_ie_rsn, 0) != DOT11F_PARSE_SUCCESS) {
|
||||
return false;
|
||||
}
|
||||
|
||||
for (i = 0; i < dot11f_ie_rsn.pmkid_count; i++) {
|
||||
if (qdf_mem_cmp(dot11f_ie_rsn.pmkid[i],
|
||||
|
|
|
|||
Loading…
Reference in a new issue