forked from rubenslte/android_kernel_samsung_msm8226
prima: Validate pkt buffer size.
In function parse_Bufferforpkt, pkt data index is not validated. This may lead to a buffer overflow if the incoming buffer is too large. Validate packet buffer length with the total allowed pkt buffer size. Change-Id: I9b9ffa592cbe3a0d87af3cbbef3608bc59e01cfc CRs-Fixed: 1092599
This commit is contained in:
committed by
Francescodario Cuzzocrea
parent
295030a4c5
commit
90996a04c7
@@ -3859,6 +3859,9 @@ static void parse_Bufferforpkt(tSirpkt80211 *pkt, u8 *pBuffer, u16 len)
|
||||
length += getByte(&temp) << 8;
|
||||
hddLog(VOS_TRACE_LEVEL_INFO,"Payload length : %d", length);
|
||||
|
||||
if (length >= WLAN_DISA_MAX_PAYLOAD_SIZE)
|
||||
length = WLAN_DISA_MAX_PAYLOAD_SIZE;
|
||||
|
||||
pkt->data.length = length;
|
||||
|
||||
for (i = 0; i< length; i++) {
|
||||
|
||||
Reference in New Issue
Block a user