mirror of
https://github.com/BobTheBlinker/android_kernel_motorola_sm6375.git
synced 2026-10-10 22:40:54 -04:00
No description
- C 98.2%
- Assembly 1%
- Makefile 0.3%
- Shell 0.2%
- Python 0.1%
| Filename | Latest commit message | Latest commit date |
|---|---|---|
In the function wma_passpoint_match_event_handler, fixed param event data from firmware is filled in the destination buffer and indication is sent to upper layers. The buffer allocation is done for the size (wmi_passpoint_event_hdr*) + event->ie_length + event->anqp_length. The maximum firmware event message size is WMI_SVC_MSG_MAX_SIZE. If either, ie_length and anqp_length combined is greater than WMI_SVC_MSG_MAX_SIZE or either of the two exceeds WMI_SVC_MSG_MAC_SIZE, an OOB write will occur in wma_passpoint_match_event_handler. Add check to ensure either of the values ie_length or anqp_lenth or (ie_length + anqp_length) doesnt exceed the WMI_SVC_MAX_SIZE. Return failure if it exceeds. Change-Id: I21f473ca0b99ebb8488f2cca3c0774817ea97c3a CRs-Fixed: 2201190 |
||
| components | ||
| core | ||
| uapi/linux | ||
| Android.mk | ||
| Kbuild | ||
| Kconfig | ||
| Makefile | ||
| README.txt | ||
This is CNSS WLAN Host Driver for products starting from iHelium