wlan: fix buffer overflow in psessionEntry->pSchBeaconFrameBegin

psessionEntry->pSchBeaconFrameBegin is allocated with fix length
SCH_MAX_BEACON_SIZE. Do not copy the value to the buffer exceeding
psessionEntry->pSchBeaconFrameBegin.

Change-Id: I539692c01753b991a963b0416177cf5b474cfdf8
CRs-Fixed: 2579375
This commit is contained in:
bings
2021-10-10 23:46:47 +02:00
committed by Francescodario Cuzzocrea
parent e3b0411e00
commit 155f6cd98d
@@ -742,6 +742,13 @@ void writeBeaconToMemory(tpAniSirGlobal pMac, tANI_U16 size, tANI_U16 length, tp
// copy end of beacon only if length > 0
if (length > 0)
{
if (size + pMac->sch.schObject.gSchBeaconOffsetEnd >
SCH_MAX_BEACON_SIZE) {
PELOGE(schLog(pMac, LOGE,
FL("beacon template fail size %d BeaconOffsetEnd %d"),
size, pMac->sch.schObject.gSchBeaconOffsetEnd);)
return;
}
for (i=0; i < pMac->sch.schObject.gSchBeaconOffsetEnd; i++)
pMac->sch.schObject.gSchBeaconFrameBegin[size++] = pMac->sch.schObject.gSchBeaconFrameEnd[i];
}