From 95453252fa5c67661f0e8d236d5a910c0cf52bf3 Mon Sep 17 00:00:00 2001 From: Manikandan Mohan Date: Fri, 7 Sep 2018 15:00:09 -0700 Subject: [PATCH] qcacld-3.0: Check for following radio link stats events When first WMI_RADIO_LINK_STATS_EVENTID is received radio stats buffer is allocated based on num_radio param. There is an option for pending following events. So update wma_unified_link_radio_stats_event_handler to check if following events are valid wrt num_radio values to avoid buffer overwrites. Change-Id: If4675bada5492c3bae98c655b45cac6dc76b6431 CRs-fixed: 2309399 --- core/wma/src/wma_utils.c | 13 ++++++++++++- 1 file changed, 12 insertions(+), 1 deletion(-) diff --git a/core/wma/src/wma_utils.c b/core/wma/src/wma_utils.c index fdea743c56df..f687b2eb9207 100644 --- a/core/wma/src/wma_utils.c +++ b/core/wma/src/wma_utils.c @@ -1682,6 +1682,18 @@ static int wma_unified_link_radio_stats_event_handler(void *handle, } } link_stats_results = wma_handle->link_stats_results; + if (link_stats_results->num_radio == 0) { + link_stats_results->num_radio = fixed_param->num_radio; + } else if (link_stats_results->num_radio < fixed_param->num_radio) { + /* + * The link stats results size allocated based on num_radio of + * first event must be same as following events. Otherwise these + * events may be spoofed. Drop all of them and report error. + */ + WMA_LOGE("Invalid following WMI_RADIO_LINK_STATS_EVENTID. Discarding this set"); + wma_unified_radio_tx_mem_free(handle); + return -EINVAL; + } WMA_LOGD("Radio stats Fixed Param:"); WMA_LOGD("req_id: %u num_radio: %u more_radio_events: %u", @@ -1704,7 +1716,6 @@ static int wma_unified_link_radio_stats_event_handler(void *handle, link_stats_results->paramId = WMI_LINK_STATS_RADIO; link_stats_results->rspId = fixed_param->request_id; link_stats_results->ifaceId = 0; - link_stats_results->num_radio = fixed_param->num_radio; link_stats_results->peer_event_number = 0; /*