From c623a40841c7839a5cb55ada66f4034948b1dc82 Mon Sep 17 00:00:00 2001 From: Abhishek Ambure Date: Thu, 30 Jan 2020 19:29:25 +0530 Subject: [PATCH] wlan: Remove off-by-one write condition in sch_beacon_process In the API, the driver inserts 0 after the SSID name, to mark the end of the ssid, but if the SSID name is 32 characters which is the max SSID length possible, the driver puts 0 at the 33rd place of memory which is not the part of the SSID name, which results in OOB write, or off-by-one write condition. Fix is to remove the addition of 0 after ssid, as in every case the driver prints the ssid, taking the ssid length as the input, and in that case insertion of 0 will not serve any purpose. Change-Id: I1d58026ec9f48fe9d00bd2f50783c65899588978 CRs-Fixed: 2598900 (cherry picked from commit ad65dc9f8a5731d4138ba61f2731f0db3b68bc82) --- drivers/staging/prima/CORE/MAC/inc/sirMacProtDef.h | 4 ++-- drivers/staging/prima/CORE/MAC/src/pe/sch/schBeaconProcess.c | 4 ---- 2 files changed, 2 insertions(+), 6 deletions(-) diff --git a/drivers/staging/prima/CORE/MAC/inc/sirMacProtDef.h b/drivers/staging/prima/CORE/MAC/inc/sirMacProtDef.h index c4d1477f8a9..1e37bc97a86 100644 --- a/drivers/staging/prima/CORE/MAC/inc/sirMacProtDef.h +++ b/drivers/staging/prima/CORE/MAC/inc/sirMacProtDef.h @@ -1093,11 +1093,11 @@ typedef __ani_attr_pre_packed struct sSirMacRateSet tANI_U8 rate[SIR_MAC_RATESET_EID_MAX]; } __ani_attr_packed tSirMacRateSet; - +//Reserve 1 byte for NULL character in the SSID name field to print in %s typedef __ani_attr_pre_packed struct sSirMacSSid { tANI_U8 length; - tANI_U8 ssId[32]; + tANI_U8 ssId[SIR_MAC_MAX_SSID_LENGTH + 1]; } __ani_attr_packed tSirMacSSid; typedef __ani_attr_pre_packed struct sSirMacWpaInfo diff --git a/drivers/staging/prima/CORE/MAC/src/pe/sch/schBeaconProcess.c b/drivers/staging/prima/CORE/MAC/src/pe/sch/schBeaconProcess.c index 89c509272ce..2c545947830 100644 --- a/drivers/staging/prima/CORE/MAC/src/pe/sch/schBeaconProcess.c +++ b/drivers/staging/prima/CORE/MAC/src/pe/sch/schBeaconProcess.c @@ -749,10 +749,6 @@ void schBeaconProcess(tpAniSirGlobal pMac, tANI_U8* pRxPacketInfo, tpPESession p return; } - if (beaconStruct.ssidPresent) - { - beaconStruct.ssId.ssId[beaconStruct.ssId.length] = 0; - } /* * First process the beacon in the context of any existing AP or BTAP session.