mirror of
https://github.com/BobTheBlinker/android_kernel_motorola_sm6375.git
synced 2026-10-10 22:40:54 -04:00
qcacld-3.0: Fix buffer overwrite in lim_send_probe_rsp_template_to_hal
In function lim_send_probe_rsp_template_to_hal, memset is done for the allocated packet for length nBytes which is calculated as size of payload + MAC header + addn_ielen. However, the buffer used psessionEntry->pSchProbeRspTemplate is allocated for length 512 (SCH_MAX_PROBE_RESP_SIZE) only as part of create session. This leads to a potential overflow of the memory if nBytes calculated is greater than 512 leading to kernel panic while freeing the memory in delete session. Add sanity check to make sure we do not exceed the SCH_MAX_PROBE_RESP_SIZE before doing a memset on the buffer. Change-Id: I4657d34a429b1f0c11ac8ca24869727c222669b8 CRs-Fixed: 2160086
This commit is contained in:
parent
e6bce00c2c
commit
bdfbaa9cbf
1 changed files with 7 additions and 0 deletions
|
|
@ -345,6 +345,13 @@ uint32_t lim_send_probe_rsp_template_to_hal(tpAniSirGlobal pMac,
|
|||
|
||||
nBytes += nPayload + sizeof(tSirMacMgmtHdr);
|
||||
|
||||
/* Make sure we are not exceeding allocated len */
|
||||
if (nBytes > SCH_MAX_PROBE_RESP_SIZE) {
|
||||
pe_err("nBytes %d greater than max size", nBytes);
|
||||
qdf_mem_free(addIE);
|
||||
return eSIR_FAILURE;
|
||||
}
|
||||
|
||||
/* Paranoia: */
|
||||
qdf_mem_set(pFrame2Hal, nBytes, 0);
|
||||
|
||||
|
|
|
|||
Loading…
Reference in a new issue