From 97b9687c83cfb36d3eecedfaa4c1cfa6f8fcf4e7 Mon Sep 17 00:00:00 2001 From: Abhinav Kumar Date: Thu, 28 Dec 2017 14:09:17 +0530 Subject: [PATCH] wlan: Fix potential OOB read in dot11f.c In function get_container_ies_len, nBuf is passed from caller function as length of the buffer remaining in the frame. len is calculated from the length field present in the IE. Then find_ie_defn is called with nBuf + len as buffer length available leading to potential OOB read in the function find_ie_defn. Also in function get_container_ies_len, if len is greater than nBuf, OOB read would occur in the caller function unpack_core. In function unpack_core, len is calculated from the length field in the IE buffer, then the IE is parsed in one of the unpack functions where len is decremented without any check for min value of len. If the value of len obtained from the IE buffer is less than the minSize of the IE, then an integer underflow would occur. 1. In function get_container_ies_len, change calling of find_ie_defn to use nbuf - len. 2. In function get_container_ies_len, if len > nbuf, return error. 3. In function unpack_core, add sanity check to make sure len is not less thatn IE's minSize. Change-Id: I8e42fb7e9674845d152d2ec26a592e02a1b562ab CRs-Fixed: 2164275 --- .../staging/prima/CORE/MAC/src/include/dot11f.h | 2 +- .../prima/CORE/SYS/legacy/src/utils/src/dot11f.c | 16 ++++++++++------ 2 files changed, 11 insertions(+), 7 deletions(-) diff --git a/drivers/staging/prima/CORE/MAC/src/include/dot11f.h b/drivers/staging/prima/CORE/MAC/src/include/dot11f.h index 52c714e46ba..f97ea32a76d 100644 --- a/drivers/staging/prima/CORE/MAC/src/include/dot11f.h +++ b/drivers/staging/prima/CORE/MAC/src/include/dot11f.h @@ -30,7 +30,7 @@ * * * This file was automatically generated by 'framesc' - * Tue Jul 4 11:19:48 2017 from the following file(s): + * Thu Dec 28 14:04:50 2017 from the following file(s): * * dot11f.frms * diff --git a/drivers/staging/prima/CORE/SYS/legacy/src/utils/src/dot11f.c b/drivers/staging/prima/CORE/SYS/legacy/src/utils/src/dot11f.c index f3f621cf99a..2cd555c21d1 100644 --- a/drivers/staging/prima/CORE/SYS/legacy/src/utils/src/dot11f.c +++ b/drivers/staging/prima/CORE/SYS/legacy/src/utils/src/dot11f.c @@ -28,7 +28,7 @@ * * * This file was automatically generated by 'framesc' - * Tue Jul 4 11:19:48 2017 from the following file(s): + * Thu Dec 28 14:04:50 2017 from the following file(s): * * dot11f.frms * @@ -482,7 +482,7 @@ static tANI_U32 GetContainerIesLen(tpAniSirGlobal pCtx, len += 2; while ( len < nBuf ) { - if( NULL == (pIe = FindIEDefn(pCtx, pBufRemaining, nBuf + len, IEs))) + if( NULL == (pIe = FindIEDefn(pCtx, pBufRemaining, nBuf - len, IEs))) break; if( pIe->eid == pIeFirst->eid ) break; @@ -490,6 +490,8 @@ static tANI_U32 GetContainerIesLen(tpAniSirGlobal pCtx, pBufRemaining += *(pBufRemaining + 1) + 2; } + if ((len > 0xFF) || (len > nBuf)) + return DOT11F_INTERNAL_ERROR; *pnConsumed = len; return DOT11F_PARSE_SUCCESS; @@ -20710,11 +20712,13 @@ static tANI_U32 UnpackCore(tpAniSirGlobal pCtx, if (pIe) { - if (nBufRemaining < pIe->minSize - pIe->noui - 2U) + if ((nBufRemaining < pIe->minSize - pIe->noui - 2U) || + (len < pIe->minSize - pIe->noui - 2U)) { - FRAMES_LOG3(pCtx, FRLOGW, FRFL("The IE %s must be " - "at least %d bytes in size, but there are onl" - "y %d bytes remaining in this frame.\n"), + FRAMES_LOG3(pCtx, FRLOGW, FRFL("The IE %s must " + "be at least %d bytes in size, but " + "there are only %d bytes remaining in " + "this frame\n"), pIe->name, pIe->minSize, nBufRemaining); FRAMES_DUMP(pCtx, FRLOG1, pBuf, nBuf); status |= DOT11F_INCOMPLETE_IE;