From f56c81fab258a68d1af87f243225d4acb44ea9c2 Mon Sep 17 00:00:00 2001 From: Abhinav Kumar Date: Wed, 6 Jun 2018 16:07:01 +0530 Subject: [PATCH] qcacld-3.0: Fix possible OOB read in wlan_hdd_cfg80211_set_ie In case of WLAN_EID_WAPI, Host assuming that the incoming ie buffer is at least of length (4 + 2 + akmsuiteCount * sizeof(uint32_t)) long and is not checked anywhere before accessing. Results possible OOB read issue could occur. Fix is to add a check for incoming buffer IEs. Change-Id: Ia60cf8c56478b47e5f2f654f0cf77fe6bd5706e4 CRs-Fixed: 2252250 --- core/hdd/src/wlan_hdd_cfg80211.c | 17 +++++++++++++++-- 1 file changed, 15 insertions(+), 2 deletions(-) diff --git a/core/hdd/src/wlan_hdd_cfg80211.c b/core/hdd/src/wlan_hdd_cfg80211.c index 6038864974b5..954798cb7cab 100644 --- a/core/hdd/src/wlan_hdd_cfg80211.c +++ b/core/hdd/src/wlan_hdd_cfg80211.c @@ -18678,12 +18678,25 @@ static int wlan_hdd_cfg80211_set_ie(struct hdd_adapter *adapter, /* Setting WAPI Mode to ON=1 */ adapter->wapi_info.wapi_mode = 1; hdd_debug("WAPI MODE IS %u", adapter->wapi_info.wapi_mode); - tmp = (uint8_t *)ie; - tmp = tmp + 4; /* Skip element Id and Len, Version */ + /* genie is pointing to data field of WAPI IE's buffer */ + tmp = (uint8_t *)genie; + /* Validate length for Version(2 bytes) and Number + * of AKM suite (2 bytes) in WAPI IE buffer, coming from + * supplicant*/ + if (eLen < 4) { + hdd_err("Invalid IE Len: %u", eLen); + return -EINVAL; + } + tmp = tmp + 2; /* Skip Version */ /* Get the number of AKM suite */ akmsuiteCount = WPA_GET_LE16(tmp); /* Skip the number of AKM suite */ tmp = tmp + 2; + /* Validate total length for WAPI IE's buffer */ + if (eLen < (4 + (akmsuiteCount * sizeof(uint32_t)))) { + hdd_err("Invalid IE Len: %u", eLen); + return -EINVAL; + } /* AKM suite list, each OUI contains 4 bytes */ akmlist = (uint32_t *)(tmp); if (akmsuiteCount <= MAX_NUM_AKM_SUITES) {