forked from rubenslte/android_kernel_samsung_msm8226
wlan: Fix potential OOB read in dot11f.c
In function get_container_ies_len, nBuf is passed from caller function
as length of the buffer remaining in the frame. len is calculated from
the length field present in the IE. Then find_ie_defn is called with
nBuf + len as buffer length available leading to potential OOB read
in the function find_ie_defn.
Also in function get_container_ies_len, if len is greater than nBuf,
OOB read would occur in the caller function unpack_core.
In function unpack_core, len is calculated from the length field in
the IE buffer, then the IE is parsed in one of the unpack functions
where len is decremented without any check for min value of len.
If the value of len obtained from the IE buffer is less than the
minSize of the IE, then an integer underflow would occur.
1. In function get_container_ies_len, change calling of find_ie_defn
to use nbuf - len.
2. In function get_container_ies_len, if len > nbuf, return error.
3. In function unpack_core, add sanity check to make sure len is not
less thatn IE's minSize.
Change-Id: I8e42fb7e9674845d152d2ec26a592e02a1b562ab
CRs-Fixed: 2164275
This commit is contained in:
committed by
Francescodario Cuzzocrea
parent
7d3e1ba99c
commit
97b9687c83
@@ -30,7 +30,7 @@
|
||||
*
|
||||
*
|
||||
* This file was automatically generated by 'framesc'
|
||||
* Tue Jul 4 11:19:48 2017 from the following file(s):
|
||||
* Thu Dec 28 14:04:50 2017 from the following file(s):
|
||||
*
|
||||
* dot11f.frms
|
||||
*
|
||||
|
||||
@@ -28,7 +28,7 @@
|
||||
*
|
||||
*
|
||||
* This file was automatically generated by 'framesc'
|
||||
* Tue Jul 4 11:19:48 2017 from the following file(s):
|
||||
* Thu Dec 28 14:04:50 2017 from the following file(s):
|
||||
*
|
||||
* dot11f.frms
|
||||
*
|
||||
@@ -482,7 +482,7 @@ static tANI_U32 GetContainerIesLen(tpAniSirGlobal pCtx,
|
||||
len += 2;
|
||||
while ( len < nBuf )
|
||||
{
|
||||
if( NULL == (pIe = FindIEDefn(pCtx, pBufRemaining, nBuf + len, IEs)))
|
||||
if( NULL == (pIe = FindIEDefn(pCtx, pBufRemaining, nBuf - len, IEs)))
|
||||
break;
|
||||
if( pIe->eid == pIeFirst->eid )
|
||||
break;
|
||||
@@ -490,6 +490,8 @@ static tANI_U32 GetContainerIesLen(tpAniSirGlobal pCtx,
|
||||
pBufRemaining += *(pBufRemaining + 1) + 2;
|
||||
}
|
||||
|
||||
if ((len > 0xFF) || (len > nBuf))
|
||||
return DOT11F_INTERNAL_ERROR;
|
||||
*pnConsumed = len;
|
||||
return DOT11F_PARSE_SUCCESS;
|
||||
|
||||
@@ -20710,11 +20712,13 @@ static tANI_U32 UnpackCore(tpAniSirGlobal pCtx,
|
||||
|
||||
if (pIe)
|
||||
{
|
||||
if (nBufRemaining < pIe->minSize - pIe->noui - 2U)
|
||||
if ((nBufRemaining < pIe->minSize - pIe->noui - 2U) ||
|
||||
(len < pIe->minSize - pIe->noui - 2U))
|
||||
{
|
||||
FRAMES_LOG3(pCtx, FRLOGW, FRFL("The IE %s must be "
|
||||
"at least %d bytes in size, but there are onl"
|
||||
"y %d bytes remaining in this frame.\n"),
|
||||
FRAMES_LOG3(pCtx, FRLOGW, FRFL("The IE %s must "
|
||||
"be at least %d bytes in size, but "
|
||||
"there are only %d bytes remaining in "
|
||||
"this frame\n"),
|
||||
pIe->name, pIe->minSize, nBufRemaining);
|
||||
FRAMES_DUMP(pCtx, FRLOG1, pBuf, nBuf);
|
||||
status |= DOT11F_INCOMPLETE_IE;
|
||||
|
||||
Reference in New Issue
Block a user