From 714434efb874944f500fb0abe13c9afa1fa38a04 Mon Sep 17 00:00:00 2001 From: Pragaspathi Thilagaraj Date: Wed, 12 Feb 2020 16:07:38 +0530 Subject: [PATCH] wlan: Fix integer overflow in rrm_fill_beacon_ies() In function rrm_fill_beacon_ies, the total IE length is calculated as sum of length field of the IE and 2 (element id 1 byte and IE length field 1 byte). The total IE length is defined of type uint16_t and will overflow if the *(pBcnIes + 1)=0xfe. Validate the len against total IE length to avoid overflow. Change-Id: If8f86952ce43c5923906fc6ef18705f1785c5d88 CRs-Fixed: 2617004 (cherry picked from commit 949b1745b9e1ddd8f81960723643cdf10e5f1963) --- drivers/staging/prima/CORE/MAC/src/pe/rrm/rrmApi.c | 12 ++++++++++-- 1 file changed, 10 insertions(+), 2 deletions(-) diff --git a/drivers/staging/prima/CORE/MAC/src/pe/rrm/rrmApi.c b/drivers/staging/prima/CORE/MAC/src/pe/rrm/rrmApi.c index aca2007d592..372f604e645 100644 --- a/drivers/staging/prima/CORE/MAC/src/pe/rrm/rrmApi.c +++ b/drivers/staging/prima/CORE/MAC/src/pe/rrm/rrmApi.c @@ -712,7 +712,8 @@ rrmFillBeaconIes( tpAniSirGlobal pMac, tANI_U8 *eids, tANI_U8 numEids, tpSirBssDescription pBssDesc ) { - tANI_U8 len, *pBcnIes, BcnNumIes, count = 0, i; + tANI_U8 len, *pBcnIes, count = 0, i; + tANI_U16 BcnNumIes = 0; if( (pIes == NULL) || (pNumIes == NULL) || (pBssDesc == NULL) ) { @@ -739,10 +740,17 @@ rrmFillBeaconIes( tpAniSirGlobal pMac, while ( BcnNumIes >= 2 ) { - len = *(pBcnIes + 1) + 2; //element id + length. + len = *(pBcnIes + 1); //element id + length. + len += 2; limLog( pMac, LOG3, "EID = %d, len = %d total = %d", *pBcnIes, *(pBcnIes+1), len ); + if (BcnNumIes < len || len <= 2) { + limLog(pMac, LOGE, "RRM: Invalid IE len:%d exp_len:%d", + len, BcnNumIes); + break; + } + i = 0; do {