forked from rubenslte/android_kernel_samsung_msm8226
wlan: Resolve overflow while processing setHostOffload ioctl
qcacld-2.0 to prima propagation While processing setHostOffload ioctl there is a possibility of sending invalid data to lower layers as user sent data structure is different from local buffer structure. To mitigate this issue, initialize local buffer to zero and then update local buffer member by member. Change-Id: I657d2a8c7d37435b1ad28ef6de60ea80a235ead9 CRs-Fixed: 2147130
This commit is contained in:
committed by
Francescodario Cuzzocrea
parent
8d935f40c8
commit
bb73fcc012
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* Copyright (c) 2011-2015 The Linux Foundation. All rights reserved.
|
||||
* Copyright (c) 2011-2018 The Linux Foundation. All rights reserved.
|
||||
*
|
||||
* Previously licensed under the ISC license by Qualcomm Atheros, Inc.
|
||||
*
|
||||
@@ -8010,11 +8010,14 @@ static int __iw_set_host_offload(struct net_device *dev,
|
||||
}
|
||||
}
|
||||
|
||||
/* Execute offload request. The reason that we can copy the request information
|
||||
from the ioctl structure to the SME structure is that they are laid out
|
||||
exactly the same. Otherwise, each piece of information would have to be
|
||||
copied individually. */
|
||||
memcpy(&offloadRequest, pRequest, wrqu->data.length);
|
||||
vos_mem_zero(&offloadRequest, sizeof(offloadRequest));
|
||||
offloadRequest.offloadType = pRequest->offloadType;
|
||||
offloadRequest.enableOrDisable = pRequest->enableOrDisable;
|
||||
vos_mem_copy(&offloadRequest.params, &pRequest->params,
|
||||
sizeof(pRequest->params));
|
||||
vos_mem_copy(&offloadRequest.bssId, &pRequest->bssId.bytes,
|
||||
VOS_MAC_ADDRESS_LEN);
|
||||
|
||||
if (eHAL_STATUS_SUCCESS != sme_SetHostOffload(WLAN_HDD_GET_HAL_CTX(pAdapter),
|
||||
pAdapter->sessionId, &offloadRequest))
|
||||
{
|
||||
|
||||
Reference in New Issue
Block a user