qcacld-2.0: Fix possible OOB in limProcessAssocReqFrame

propagation from qcacld-3.0 to qcacld-2.0

In the function limProcessAssocReqFrame, if wpa IE is
present, then dot11fUnpackIeWPA is called to copy the wpa IE
to destination buffer. pAssocReq->wpa.length is passed as the
length to copy the IE. As this length includes 4 bytes of the
OUI fields also, this could result in OOB read.

Change the length passed to the dot11fUnpackIeWPA as
(pAssocReq->wpa.length - 4), so that the additional 4 bytes of
the OUI fields are excluded.

Change-Id: If972b3a19d239bb955c7b4d4c7d94e25aa878f21
CRs-Fixed: 2406159
This commit is contained in:
hqu
2020-05-21 10:55:44 +02:00
committed by Francescodario Cuzzocrea
parent 1cfe8ed412
commit 6347c8aaa2
2 changed files with 7 additions and 7 deletions
@@ -1,5 +1,5 @@
/*
* Copyright (c) 2011-2015 The Linux Foundation. All rights reserved.
* Copyright (c) 2011-2019 The Linux Foundation. All rights reserved.
*
* Previously licensed under the ISC license by Qualcomm Atheros, Inc.
*
@@ -436,8 +436,8 @@ limCheckMCSSet(tpAniSirGlobal pMac, tANI_U8* supportedMCSSet)
*
* @param rxRSNIe - received RSN IE in (Re)Assco req
*
* @return status - true if ALL BSS basic rates are present in the
* received rateset else false.
* @return status - true if ALL supported cipher suites are present in the
* received rsn IE else false.
*/
tANI_U8
@@ -563,8 +563,8 @@ limCheckRxRSNIeMatch(tpAniSirGlobal pMac, tDot11fIERSN rxRSNIe,tpPESession pSess
*
* @param rxWPAIe - Received WPA IE in (Re)Assco req
*
* @return status - true if ALL BSS basic rates are present in the
* received rateset else false.
* @return status - true if ALL supported cipher suites are present in the
* received wpa IE else false.
*/
tANI_U8
@@ -1,5 +1,5 @@
/*
* Copyright (c) 2012-2013 The Linux Foundation. All rights reserved.
* Copyright (c) 2012-2019 The Linux Foundation. All rights reserved.
*
* Previously licensed under the ISC license by Qualcomm Atheros, Inc.
*
@@ -781,7 +781,7 @@ limProcessAssocReqFrame(tpAniSirGlobal pMac, tANI_U8 *pRxPacketInfo,
{
if (dot11fUnpackIeWPA(pMac,
&pAssocReq->wpa.info[4], //OUI is not taken care
pAssocReq->wpa.length,
(pAssocReq->wpa.length - 4),
&Dot11fIEWPA) != DOT11F_PARSE_SUCCESS)
{
limLog(pMac, LOGE, FL("Invalid WPA IE"));