From 5e0789d4799bc59f25876c16c40d605d52ec3530 Mon Sep 17 00:00:00 2001 From: Ashish Kumar Dhanotiya Date: Tue, 11 Feb 2020 18:14:46 +0530 Subject: [PATCH] wlan: Validate assoc response IE len before copy When host sends assoc response to supplicant, it allocates a buffer of fixed size and copies a variable length of assoc response IEs to this fixed sized buffer. There is a possibility of OOB write to the allocated buffer if the assoc response IEs length is greater than the allocated buffer size. To avoid above issue validate the assoc response IEs length with the allocated buffer size before data copy to the buffer. Change-Id: Ib12385e9ff04e5172ae8b505faf959e426fda439 CRs-Fixed: 2616226 (cherry picked from commit 9bb1a72f6ebdf5d2b1a466aec732aa9c5bc37c4d) --- drivers/staging/prima/CORE/HDD/src/wlan_hdd_assoc.c | 11 +++++++++-- 1 file changed, 9 insertions(+), 2 deletions(-) diff --git a/drivers/staging/prima/CORE/HDD/src/wlan_hdd_assoc.c b/drivers/staging/prima/CORE/HDD/src/wlan_hdd_assoc.c index e52af45b96d..737635d801a 100644 --- a/drivers/staging/prima/CORE/HDD/src/wlan_hdd_assoc.c +++ b/drivers/staging/prima/CORE/HDD/src/wlan_hdd_assoc.c @@ -1484,8 +1484,10 @@ static void hdd_SendReAssocEvent(struct net_device *dev, hdd_adapter_t *pAdapter goto done; } - if (pCsrRoamInfo->nAssocRspLength == 0) { - hddLog(LOGE, "%s: Invalid assoc response length", __func__); + if (pCsrRoamInfo->nAssocRspLength < FT_ASSOC_RSP_IES_OFFSET) { + + hddLog(LOGE, "%s: Invalid assoc response length %d", + __func__, pCsrRoamInfo->nAssocRspLength); goto done; } @@ -1502,6 +1504,11 @@ static void hdd_SendReAssocEvent(struct net_device *dev, hdd_adapter_t *pAdapter // Send the Assoc Resp, the supplicant needs this for initial Auth. len = pCsrRoamInfo->nAssocRspLength - FT_ASSOC_RSP_IES_OFFSET; + if (len > IW_GENERIC_IE_MAX) { + hddLog(LOGE, "%s: Invalid assoc response length %d", + __func__, pCsrRoamInfo->nAssocRspLength); + goto done; + } rspRsnLength = len; memcpy(rspRsnIe, pFTAssocRsp, len); memset(rspRsnIe + len, 0, IW_GENERIC_IE_MAX - len);