No description
  • C 98.2%
  • Assembly 1%
  • Makefile 0.3%
  • Shell 0.2%
  • Python 0.1%
Find a file
Repository files (latest commit first)
Filename Latest commit message Latest commit date
Deeksha Gupta bd1cf8222a qcacld-3.0: Fix possible OOB in unpack_tlv_core
Currently in unpack_tlv_core(), nBufRemaining is validated
after calling framesntohs API. Since, framesntohs() copies
pIn address to pOut address with length = 2 bytes as below.
DOT11F_MEMCPY(pCtx, (uint16_t *)pOut, pIn, 2);
which could cause OOB issue if pIn contains less than 2 bytes.

Fix is to validate the nBufRemaining size before calling
framesntohs().

Change-Id: I3ead03ec948282a410ddba5b01f82ca31d3d9199
CRs-Fixed: 3042282
2021-09-30 13:32:35 -07:00
components
configs
core qcacld-3.0: Fix possible OOB in unpack_tlv_core 2021-09-30 13:32:35 -07:00
os_if
uapi/linux
Android.mk
Kbuild
Kconfig
Makefile
README.txt

This is CNSS WLAN Host Driver for products starting from iHelium