mirror of
https://github.com/BobTheBlinker/android_kernel_motorola_sm6375.git
synced 2026-10-11 07:03:09 -04:00
qcacmn: Fix use-after-free issue in util_scan_parse_mbssid
In some scenario, mbssid_info->prof_residue could be set to true, hence mbssid_info->split_prof_continue will also be set to true. Then for the next loop if buffer split_prof_start is freed but split_prof_end does not reinitialize to NULL, then use-after-free happens. To address this issue, reinitialize split_prof_end properly when split_prof_start is freed. Change-Id: Iad7448868cfa4c2dd7922f6c1b2622cf20a6a28c CRs-Fixed: 3583521
This commit is contained in:
parent
05fbfac24f
commit
d400de634f
1 changed files with 3 additions and 0 deletions
|
|
@ -2540,6 +2540,7 @@ static QDF_STATUS util_scan_parse_mbssid(struct wlan_objmgr_pdev *pdev,
|
|||
if (mbssid_info.split_prof_continue) {
|
||||
qdf_mem_free(split_prof_start);
|
||||
split_prof_start = NULL;
|
||||
split_prof_end = NULL;
|
||||
}
|
||||
continue;
|
||||
}
|
||||
|
|
@ -2604,6 +2605,7 @@ static QDF_STATUS util_scan_parse_mbssid(struct wlan_objmgr_pdev *pdev,
|
|||
if (mbssid_info.split_prof_continue) {
|
||||
qdf_mem_free(split_prof_start);
|
||||
split_prof_start = NULL;
|
||||
split_prof_end = NULL;
|
||||
qdf_mem_zero(&mbssid_info,
|
||||
sizeof(mbssid_info));
|
||||
}
|
||||
|
|
@ -2617,6 +2619,7 @@ static QDF_STATUS util_scan_parse_mbssid(struct wlan_objmgr_pdev *pdev,
|
|||
if (mbssid_info.split_prof_continue) {
|
||||
qdf_mem_free(split_prof_start);
|
||||
split_prof_start = NULL;
|
||||
split_prof_end = NULL;
|
||||
}
|
||||
qdf_mem_free(new_frame);
|
||||
}
|
||||
|
|
|
|||
Loading…
Reference in a new issue