From d400de634f2666cf9ecab0aaef302edf4a3165a4 Mon Sep 17 00:00:00 2001 From: Paul Zhang Date: Thu, 17 Aug 2023 16:20:01 +0800 Subject: [PATCH] qcacmn: Fix use-after-free issue in util_scan_parse_mbssid In some scenario, mbssid_info->prof_residue could be set to true, hence mbssid_info->split_prof_continue will also be set to true. Then for the next loop if buffer split_prof_start is freed but split_prof_end does not reinitialize to NULL, then use-after-free happens. To address this issue, reinitialize split_prof_end properly when split_prof_start is freed. Change-Id: Iad7448868cfa4c2dd7922f6c1b2622cf20a6a28c CRs-Fixed: 3583521 --- umac/scan/dispatcher/src/wlan_scan_utils_api.c | 3 +++ 1 file changed, 3 insertions(+) diff --git a/umac/scan/dispatcher/src/wlan_scan_utils_api.c b/umac/scan/dispatcher/src/wlan_scan_utils_api.c index dc3791c1f1a6..7ffe30b413d1 100644 --- a/umac/scan/dispatcher/src/wlan_scan_utils_api.c +++ b/umac/scan/dispatcher/src/wlan_scan_utils_api.c @@ -2540,6 +2540,7 @@ static QDF_STATUS util_scan_parse_mbssid(struct wlan_objmgr_pdev *pdev, if (mbssid_info.split_prof_continue) { qdf_mem_free(split_prof_start); split_prof_start = NULL; + split_prof_end = NULL; } continue; } @@ -2604,6 +2605,7 @@ static QDF_STATUS util_scan_parse_mbssid(struct wlan_objmgr_pdev *pdev, if (mbssid_info.split_prof_continue) { qdf_mem_free(split_prof_start); split_prof_start = NULL; + split_prof_end = NULL; qdf_mem_zero(&mbssid_info, sizeof(mbssid_info)); } @@ -2617,6 +2619,7 @@ static QDF_STATUS util_scan_parse_mbssid(struct wlan_objmgr_pdev *pdev, if (mbssid_info.split_prof_continue) { qdf_mem_free(split_prof_start); split_prof_start = NULL; + split_prof_end = NULL; } qdf_mem_free(new_frame); }