forked from rubenslte/android_kernel_samsung_msm8226
wlan: check BcnNumIes against size of header instead of 0
Currently, for while loop BcnNumIes is checked against 0 which may cause OOB read for len = *(pBcnIes + 1). Fix is to check BcnNumIes against size of header i.e 2 instead of 0 to avoid 00B read. Change-Id: Id167410da790e449d36853d8505142e1b218e9b8 CRs-Fixed: 2635666 (cherry picked from commit 7957db59a545ac43b260401546f4bc72470783df)
This commit is contained in:
committed by
Francescodario Cuzzocrea
parent
4ca08288d1
commit
cbd27d9917
@@ -737,7 +737,7 @@ rrmFillBeaconIes( tpAniSirGlobal pMac,
|
|||||||
*((tANI_U16*)pIes) = pBssDesc->capabilityInfo;
|
*((tANI_U16*)pIes) = pBssDesc->capabilityInfo;
|
||||||
*pNumIes+=sizeof(tANI_U16); pIes+=sizeof(tANI_U16);
|
*pNumIes+=sizeof(tANI_U16); pIes+=sizeof(tANI_U16);
|
||||||
|
|
||||||
while ( BcnNumIes > 0 )
|
while ( BcnNumIes >= 2 )
|
||||||
{
|
{
|
||||||
len = *(pBcnIes + 1) + 2; //element id + length.
|
len = *(pBcnIes + 1) + 2; //element id + length.
|
||||||
limLog( pMac, LOG3, "EID = %d, len = %d total = %d",
|
limLog( pMac, LOG3, "EID = %d, len = %d total = %d",
|
||||||
|
|||||||
Reference in New Issue
Block a user