From 8079aa438f4395546eea71bea50f680860e408df Mon Sep 17 00:00:00 2001 From: Pragaspathi Thilagaraj Date: Thu, 26 Aug 2021 18:56:50 +0530 Subject: [PATCH] qcacld-3.0: Fix invalid bss descriptor length check bss_descriptor->length is calculated as: bss_desc->length = ie_length + sizeof(*bss_desc) - sizeof(bss_desc->len) In csr_parse_bss_description_ies(), the bss_desc length is validated as below to return failure if ie_length is 0: => (bss_desc->length - sizeof(bss_desc->len)) <= ieFields_offset Since the bss_desc->length already has the sizeof(bss_desc->len) subtracted while it was populated. So this could return failure, if the SSID IE length is less than or equal to 4. To avoid this, change the failure condition as below: (bss_desc->length <= (ieFields_offset - sizeof(bss_desc->len)) Change-Id: Ib0af8e967c26ff0ca9a3b8c44107be4e80378e01 CRs-Fixed: 3022657 --- core/sme/src/csr/csr_util.c | 10 ++++++---- 1 file changed, 6 insertions(+), 4 deletions(-) diff --git a/core/sme/src/csr/csr_util.c b/core/sme/src/csr/csr_util.c index 188717201d89..ed61c4c455ab 100644 --- a/core/sme/src/csr/csr_util.c +++ b/core/sme/src/csr/csr_util.c @@ -1,5 +1,5 @@ /* - * Copyright (c) 2011-2020 The Linux Foundation. All rights reserved. + * Copyright (c) 2011-2021 The Linux Foundation. All rights reserved. * * Permission to use, copy, modify, and/or distribute this software for * any purpose with or without fee is hereby granted, provided that the @@ -1389,9 +1389,11 @@ QDF_STATUS csr_parse_bss_description_ies(struct mac_context *mac_ctx, int ieLen; ieFields_offset = GET_FIELD_OFFSET(struct bss_description, ieFields); - if (!bss_desc->length || - (bss_desc->length - sizeof(bss_desc->length) <= ieFields_offset)) + if (bss_desc->length <= (ieFields_offset - sizeof(bss_desc->length))) { + sme_err_rl("Invalid bss_desc IES: len:%d ie_fields_offset:%d", + bss_desc->length, ieFields_offset); return status; + } ieLen = (int)(bss_desc->length + sizeof(bss_desc->length) - ieFields_offset); @@ -1400,7 +1402,7 @@ QDF_STATUS csr_parse_bss_description_ies(struct mac_context *mac_ctx, if (!DOT11F_FAILED(dot11f_unpack_beacon_i_es (mac_ctx, (uint8_t *)bss_desc->ieFields, ieLen, pIEStruct, false))) - status = QDF_STATUS_SUCCESS; + status = QDF_STATUS_SUCCESS; } return status;