mirror of
https://github.com/BobTheBlinker/android_kernel_motorola_sm6375.git
synced 2026-10-09 21:59:12 -04:00
qcacmn: Add length checks for noninheritance_ie
In util_scan_find_noninheritance_ie API,
ies[ELEM_ID_EXTN_POS] may lead to OOB access if
len==MIN_IE_LEN.
util_parse_noninheritance_list may lead to OOB
read access extn_elem[ELEM_ID_LIST_LEN_POS]
Fix is to add length checks and add sub_copy and length
subie_len checks before accessing extn_elem to avoid any
OOB read.
Change-Id: I7758c6e4d8d568a5050011603b48a23e0b11da94
CRs-Fixed: 3717569
This commit is contained in:
parent
f363c9105d
commit
aab3fa668d
1 changed files with 7 additions and 4 deletions
|
|
@ -1825,7 +1825,8 @@ static uint8_t
|
|||
if (!ies)
|
||||
return NULL;
|
||||
|
||||
while (len >= MIN_IE_LEN && len >= ies[TAG_LEN_POS] + MIN_IE_LEN) {
|
||||
while ((len >= MIN_IE_LEN + 1) && len >= ies[TAG_LEN_POS] + MIN_IE_LEN)
|
||||
{
|
||||
if ((ies[ID_POS] == elem_id) &&
|
||||
(ies[ELEM_ID_EXTN_POS] ==
|
||||
WLAN_EXTN_ELEMID_NONINHERITANCE)) {
|
||||
|
|
@ -2016,9 +2017,11 @@ static uint32_t util_gen_new_ie(uint8_t *ie, uint32_t ielen,
|
|||
extn_elem = util_scan_find_noninheritance_ie(WLAN_ELEMID_EXTN_ELEM,
|
||||
sub_copy, subie_len);
|
||||
|
||||
if (extn_elem && extn_elem[TAG_LEN_POS]) {
|
||||
util_parse_noninheritance_list(extn_elem, &elem_list,
|
||||
&extn_elem_list, &ninh);
|
||||
if (extn_elem && extn_elem[TAG_LEN_POS] >= VALID_ELEM_LEAST_LEN) {
|
||||
if (((extn_elem + extn_elem[1] + MIN_IE_LEN) - sub_copy)
|
||||
< subie_len)
|
||||
util_parse_noninheritance_list(extn_elem, &elem_list,
|
||||
&extn_elem_list, &ninh);
|
||||
}
|
||||
|
||||
/* go through IEs in ie (skip SSID) and subelement,
|
||||
|
|
|
|||
Loading…
Reference in a new issue