qcacmn: Add length checks for noninheritance_ie

In util_scan_find_noninheritance_ie API,
ies[ELEM_ID_EXTN_POS] may lead to OOB access if
len==MIN_IE_LEN.

util_parse_noninheritance_list may lead to OOB
read access extn_elem[ELEM_ID_LIST_LEN_POS]

Fix is to add length checks and add sub_copy and length
subie_len checks before accessing extn_elem to avoid any
OOB read.

Change-Id: I7758c6e4d8d568a5050011603b48a23e0b11da94
CRs-Fixed: 3717569
This commit is contained in:
Sheenam Monga 2024-04-30 10:58:07 +05:30 • committed by Ravindra Konda
commit aab3fa668d

View file

@ -1825,7 +1825,8 @@ static uint8_t
if (!ies)
return NULL;
while (len >= MIN_IE_LEN && len >= ies[TAG_LEN_POS] + MIN_IE_LEN) {
while ((len >= MIN_IE_LEN + 1) && len >= ies[TAG_LEN_POS] + MIN_IE_LEN)
{
if ((ies[ID_POS] == elem_id) &&
(ies[ELEM_ID_EXTN_POS] ==
WLAN_EXTN_ELEMID_NONINHERITANCE)) {
@ -2016,9 +2017,11 @@ static uint32_t util_gen_new_ie(uint8_t *ie, uint32_t ielen,
extn_elem = util_scan_find_noninheritance_ie(WLAN_ELEMID_EXTN_ELEM,
sub_copy, subie_len);
if (extn_elem && extn_elem[TAG_LEN_POS]) {
util_parse_noninheritance_list(extn_elem, &elem_list,
&extn_elem_list, &ninh);
if (extn_elem && extn_elem[TAG_LEN_POS] >= VALID_ELEM_LEAST_LEN) {
if (((extn_elem + extn_elem[1] + MIN_IE_LEN) - sub_copy)
< subie_len)
util_parse_noninheritance_list(extn_elem, &elem_list,
&extn_elem_list, &ninh);
}
/* go through IEs in ie (skip SSID) and subelement,