mirror of
https://github.com/BobTheBlinker/android_kernel_motorola_sm6375.git
synced 2026-10-10 06:09:23 -04:00
No description
- C 98.2%
- Assembly 1%
- Makefile 0.3%
- Shell 0.2%
- Python 0.1%
| Filename | Latest commit message | Latest commit date |
|---|---|---|
While parsing ESP IE from beacon/probe response frame, the condition in loop to copy ESP_INFO from the ESP IE is incorrect which will iterate for 5 times rather than 4 times, this may cause OOB access. data < ((uint8_t *)esp_ie + esp_ie->esp_len + 3) Here adding 3 for esp_ie->esp_len, actually esp_len itself is 1 byte extra (esp_ len = ESP_ID_EXTN + ESP_INFO * 4), but by adding 3 again will loop for one more iteration this will cause OOB access. Remove 3 in loop condition to avoid one more extra iteration and ignore ESP_ID_EXTN element for total elements, in function util_scan_update_esp_data. Change-Id: Ia9226e483672369af36c6914e3ac914fe9de45e5 CRs-Fixed: 3710081 |
||
| cfg | ||
| dp | ||
| ftm | ||
| global_lmac_if | ||
| hal/wifi3.0 | ||
| hif | ||
| htc | ||
| init_deinit/dispatcher | ||
| iot_sim | ||
| os_if/linux | ||
| qal | ||
| qdf | ||
| scheduler | ||
| spectral | ||
| target_if | ||
| umac | ||
| utils | ||
| wbuff | ||
| wlan_cfg | ||
| wmi | ||
| README.txt | ||
| VERSION.txt | ||
This is CNSS WLAN Host Driver for products starting from iHelium