prima: Validate pkt buffer size.

In function parse_Bufferforpkt, pkt data index is not validated.
This may lead to a buffer overflow if the incoming buffer is too large.

Validate packet buffer length with the total allowed pkt buffer size.

Change-Id: I9b9ffa592cbe3a0d87af3cbbef3608bc59e01cfc
CRs-Fixed: 1092599
This commit is contained in:
Sachin Ahuja
2020-05-21 10:53:53 +02:00
committed by Francescodario Cuzzocrea
parent 295030a4c5
commit 90996a04c7
@@ -3859,6 +3859,9 @@ static void parse_Bufferforpkt(tSirpkt80211 *pkt, u8 *pBuffer, u16 len)
length += getByte(&temp) << 8;
hddLog(VOS_TRACE_LEVEL_INFO,"Payload length : %d", length);
if (length >= WLAN_DISA_MAX_PAYLOAD_SIZE)
length = WLAN_DISA_MAX_PAYLOAD_SIZE;
pkt->data.length = length;
for (i = 0; i< length; i++) {