From 70a5ee609ef6199dfcd8cce6198edc6f48b16bec Mon Sep 17 00:00:00 2001 From: lifeng Date: Tue, 12 Dec 2017 23:03:28 +0800 Subject: [PATCH] qcacld-3.0: Fix buffer overread in lim_process_fils_auth_frame2 qcacld-2.0 to qcacld-3.0 propagation The return value validation is missing for dot11fUnpackIeRSN, thus "dot11f_ie_rsn.pmkid_count" could be larger than 4. When it is larger than 4 there will be a buffer over-read in vos_mem_compare. Add status check of dot11fUnpackIeRSN in lim_process_fils_auth_frame2. Change-Id: If563ddb13bbfcad5660d136c35c39846010594e1 CRs-Fixed: 2147955 --- core/mac/src/pe/lim/lim_process_fils.c | 6 ++++-- 1 file changed, 4 insertions(+), 2 deletions(-) diff --git a/core/mac/src/pe/lim/lim_process_fils.c b/core/mac/src/pe/lim/lim_process_fils.c index 9548901c06d8..55f9c1942b80 100644 --- a/core/mac/src/pe/lim/lim_process_fils.c +++ b/core/mac/src/pe/lim/lim_process_fils.c @@ -1075,10 +1075,12 @@ bool lim_process_fils_auth_frame2(tpAniSirGlobal mac_ctx, if (rx_auth_frm_body->authAlgoNumber != SIR_FILS_SK_WITHOUT_PFS) return false; - dot11f_unpack_ie_rsn(mac_ctx, + if (dot11f_unpack_ie_rsn(mac_ctx, &rx_auth_frm_body->rsn_ie.info[0], rx_auth_frm_body->rsn_ie.length, - &dot11f_ie_rsn, 0); + &dot11f_ie_rsn, 0) != DOT11F_PARSE_SUCCESS) { + return false; + } for (i = 0; i < dot11f_ie_rsn.pmkid_count; i++) { if (qdf_mem_cmp(dot11f_ie_rsn.pmkid[i],