From bdfbaa9cbffbab299dac0086a755fc8f497b1a43 Mon Sep 17 00:00:00 2001 From: Vignesh Viswanathan Date: Mon, 18 Dec 2017 17:48:02 +0530 Subject: [PATCH] qcacld-3.0: Fix buffer overwrite in lim_send_probe_rsp_template_to_hal In function lim_send_probe_rsp_template_to_hal, memset is done for the allocated packet for length nBytes which is calculated as size of payload + MAC header + addn_ielen. However, the buffer used psessionEntry->pSchProbeRspTemplate is allocated for length 512 (SCH_MAX_PROBE_RESP_SIZE) only as part of create session. This leads to a potential overflow of the memory if nBytes calculated is greater than 512 leading to kernel panic while freeing the memory in delete session. Add sanity check to make sure we do not exceed the SCH_MAX_PROBE_RESP_SIZE before doing a memset on the buffer. Change-Id: I4657d34a429b1f0c11ac8ca24869727c222669b8 CRs-Fixed: 2160086 --- core/mac/src/pe/sch/sch_api.c | 7 +++++++ 1 file changed, 7 insertions(+) diff --git a/core/mac/src/pe/sch/sch_api.c b/core/mac/src/pe/sch/sch_api.c index 879222e14b23..0aa02a0381d2 100644 --- a/core/mac/src/pe/sch/sch_api.c +++ b/core/mac/src/pe/sch/sch_api.c @@ -345,6 +345,13 @@ uint32_t lim_send_probe_rsp_template_to_hal(tpAniSirGlobal pMac, nBytes += nPayload + sizeof(tSirMacMgmtHdr); + /* Make sure we are not exceeding allocated len */ + if (nBytes > SCH_MAX_PROBE_RESP_SIZE) { + pe_err("nBytes %d greater than max size", nBytes); + qdf_mem_free(addIE); + return eSIR_FAILURE; + } + /* Paranoia: */ qdf_mem_set(pFrame2Hal, nBytes, 0);