From bb73fcc012134ab36bc2b6c042c9adc84ebfc9da Mon Sep 17 00:00:00 2001 From: Hanumanth Reddy Pothula Date: Fri, 1 Dec 2017 13:34:48 +0530 Subject: [PATCH] wlan: Resolve overflow while processing setHostOffload ioctl qcacld-2.0 to prima propagation While processing setHostOffload ioctl there is a possibility of sending invalid data to lower layers as user sent data structure is different from local buffer structure. To mitigate this issue, initialize local buffer to zero and then update local buffer member by member. Change-Id: I657d2a8c7d37435b1ad28ef6de60ea80a235ead9 CRs-Fixed: 2147130 --- .../staging/prima/CORE/HDD/src/wlan_hdd_wext.c | 15 +++++++++------ 1 file changed, 9 insertions(+), 6 deletions(-) diff --git a/drivers/staging/prima/CORE/HDD/src/wlan_hdd_wext.c b/drivers/staging/prima/CORE/HDD/src/wlan_hdd_wext.c index 821683b475d..1ac7201e242 100644 --- a/drivers/staging/prima/CORE/HDD/src/wlan_hdd_wext.c +++ b/drivers/staging/prima/CORE/HDD/src/wlan_hdd_wext.c @@ -1,5 +1,5 @@ /* - * Copyright (c) 2011-2015 The Linux Foundation. All rights reserved. + * Copyright (c) 2011-2018 The Linux Foundation. All rights reserved. * * Previously licensed under the ISC license by Qualcomm Atheros, Inc. * @@ -8010,11 +8010,14 @@ static int __iw_set_host_offload(struct net_device *dev, } } - /* Execute offload request. The reason that we can copy the request information - from the ioctl structure to the SME structure is that they are laid out - exactly the same. Otherwise, each piece of information would have to be - copied individually. */ - memcpy(&offloadRequest, pRequest, wrqu->data.length); + vos_mem_zero(&offloadRequest, sizeof(offloadRequest)); + offloadRequest.offloadType = pRequest->offloadType; + offloadRequest.enableOrDisable = pRequest->enableOrDisable; + vos_mem_copy(&offloadRequest.params, &pRequest->params, + sizeof(pRequest->params)); + vos_mem_copy(&offloadRequest.bssId, &pRequest->bssId.bytes, + VOS_MAC_ADDRESS_LEN); + if (eHAL_STATUS_SUCCESS != sme_SetHostOffload(WLAN_HDD_GET_HAL_CTX(pAdapter), pAdapter->sessionId, &offloadRequest)) {