From e2a792f9b769628c864f138ce7c600ca2ebfd539 Mon Sep 17 00:00:00 2001 From: Bapiraju Alla Date: Wed, 16 Dec 2020 12:42:46 +0530 Subject: [PATCH] qcacmn: Discard QMI events when message with invalid length Currently QMI message length is not being validated before handling QMI event. This is resulting in illegal memory access when QMI message length is invalid. To address this, discard QMI events with invalid length. Change-Id: Ia9f04bcb4fa3b365cbbf2be8885a8d30f78f8f10 CRs-Fixed: 2839277 --- wmi/src/wmi_unified.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/wmi/src/wmi_unified.c b/wmi/src/wmi_unified.c index 2f764c7f7356..ed0a40f1beac 100644 --- a/wmi/src/wmi_unified.c +++ b/wmi/src/wmi_unified.c @@ -2559,7 +2559,7 @@ static int __wmi_process_qmi_fw_event(void *wmi_cb_ctx, void *buf, int len) uint32_t evt_id; int wmi_msg_len; - if (!wmi_handle || !buf) + if (!wmi_handle || !buf || (len < WMI_MIN_HEAD_ROOM)) return -EINVAL; /**