wlan: check BcnNumIes against size of header instead of 0

Currently, for while loop BcnNumIes is checked against 0
which may cause OOB read for len = *(pBcnIes + 1).

Fix is to check BcnNumIes against size of header i.e 2 instead
of 0 to avoid 00B read.

Change-Id: Id167410da790e449d36853d8505142e1b218e9b8
CRs-Fixed: 2635666
(cherry picked from commit 7957db59a545ac43b260401546f4bc72470783df)
This commit is contained in:
sheenam monga
2021-10-10 23:46:47 +02:00
committed by Francescodario Cuzzocrea
parent 4ca08288d1
commit cbd27d9917
@@ -737,7 +737,7 @@ rrmFillBeaconIes( tpAniSirGlobal pMac,
*((tANI_U16*)pIes) = pBssDesc->capabilityInfo;
*pNumIes+=sizeof(tANI_U16); pIes+=sizeof(tANI_U16);
while ( BcnNumIes > 0 )
while ( BcnNumIes >= 2 )
{
len = *(pBcnIes + 1) + 2; //element id + length.
limLog( pMac, LOG3, "EID = %d, len = %d total = %d",