From e6b465b3c2d7c35d64ce64ecb42094dfd94e2adf Mon Sep 17 00:00:00 2001 From: Srinivas Girigowda Date: Thu, 30 Mar 2017 18:27:25 -0700 Subject: [PATCH] qcacld-3.0: Add zero to the end of the buffer MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit when wlan_mac.bin doesn’t end with ‘\0’, get_next_line() can access the unexpected area. Fix this by adding 0 to the end of the buffer. Change-Id: I01971aa5ad9679338a19e837f73969367d5b08f8 CRs-Fixed: 2026925 --- core/hdd/src/wlan_hdd_cfg.c | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/core/hdd/src/wlan_hdd_cfg.c b/core/hdd/src/wlan_hdd_cfg.c index 5c2a1c31c537..6f6ac7f1c0aa 100644 --- a/core/hdd/src/wlan_hdd_cfg.c +++ b/core/hdd/src/wlan_hdd_cfg.c @@ -5805,7 +5805,7 @@ QDF_STATUS hdd_update_mac_config(hdd_context_t *pHddCtx) hdd_debug("wlan_mac.bin size %zu", fw->size); - temp = qdf_mem_malloc(fw->size); + temp = qdf_mem_malloc(fw->size + 1); if (temp == NULL) { hdd_err("fail to alloc memory"); @@ -5814,6 +5814,7 @@ QDF_STATUS hdd_update_mac_config(hdd_context_t *pHddCtx) } buffer = temp; qdf_mem_copy(buffer, fw->data, fw->size); + buffer[fw->size + 1] = 0x0; /* data format: * Intf0MacAddress=00AA00BB00CC