wlan: Add sanity check for data in ptt_sock_rx_nlink_msg

Currently in the driver, while typecasting the skb data to local
structure in function ptt_sock_proc_reg_req, there can occur a potential
OOB read. The length of the data to be typecasted is not verified
properly.

Add a sanity check to verify that the data being typecasted is of proper
size.

Change-Id: Ib88477a2817649e092e25e21f948c33160dfa09b
CRs-Fixed: 2559499
This commit is contained in:
Sourav Mohapatra
2021-10-10 23:46:47 +02:00
committed by Francescodario Cuzzocrea
parent 62e33cb8bb
commit 4ecd853b71
@@ -293,6 +293,11 @@ static int ptt_sock_rx_nlink_msg (struct sk_buff * skb)
wnl = (tAniNlHdr *) skb->data;
radio = wnl->radio;
type = wnl->nlh.nlmsg_type;
if (wnl->nlh.nlmsg_len < (sizeof(struct nlmsghdr) +
sizeof(int) + sizeof(tAniHdr) + wnl->wmsg.length))
return -EINVAL;
switch (type) {
case ANI_NL_MSG_PUMAC: //Message from the PTT socket APP
PTT_TRACE(VOS_TRACE_LEVEL_INFO, "%s: Received ANI_NL_MSG_PUMAC Msg [0x%X]\n",