mirror of
https://github.com/BobTheBlinker/android_kernel_motorola_sm6375.git
synced 2026-10-11 07:03:09 -04:00
qcacld-3.0: Buffer overwrite in vendor scan request on n_ssid
In function __wlan_hdd_cfg80211_vendor_scan, when SCAN_SSIDS and QCA_WLAN_VENDOR_ATTR_SCAN_FREQUENCIES are parsed, if the number of SSIDs or number of channels are more then 255 in netlink message, n_ssid and n_channels will get overflow because n_ssid and n_channels are of type uint8_t. Add a check to validate the max number of SCAN_SSIDs against MAX_SCAN_SSID and max number of channels against MAX_CHANNEL. Change-Id: Ib31dcc912fee8639e26d836d2fc5a32bf81fb43d CRs-Fixed: 2153343
This commit is contained in:
parent
26b3d04130
commit
d2b9064557
1 changed files with 1 additions and 1 deletions
|
|
@ -926,7 +926,7 @@ static int __wlan_hdd_cfg80211_vendor_scan(struct wiphy *wiphy,
|
|||
struct cfg80211_scan_request *request = NULL;
|
||||
struct nlattr *attr;
|
||||
enum nl80211_band band;
|
||||
uint8_t n_channels = 0, n_ssid = 0;
|
||||
uint32_t n_channels = 0, n_ssid = 0;
|
||||
uint32_t tmp, count, j;
|
||||
size_t len, ie_len;
|
||||
struct ieee80211_channel *chan;
|
||||
|
|
|
|||
Loading…
Reference in a new issue