forked from rubenslte/android_kernel_samsung_msm8226
wlan: Fix possible integer underflow in cfg80211_rx_mgmt
In the function cfg80211_rx_mgmt, data_len is calculated as len - ieee80211_hdrlen(mgmt->frame_control). Len is not validated before this calculation. So a possible integer underflow will occur if len value is less than the value of ieee80211_hdrlen(mgmt->frame_control). Validate the value of len against ieee80211_hdrlen(mgmt->frame_control) in the caller. Change-Id: Iae776daf37b0c052bd4ce4da44ea728d121eae51 CRs-Fixed: 2460252
This commit is contained in:
committed by
Francescodario Cuzzocrea
parent
dce87c8541
commit
cfca93bec9
@@ -11862,6 +11862,8 @@ void hdd_indicate_mgmt_frame(tSirSmeMgmtFrameInd *frame_ind)
|
||||
hdd_context_t *hdd_ctx = NULL;
|
||||
hdd_adapter_t *adapter = NULL;
|
||||
v_CONTEXT_t vos_context = NULL;
|
||||
struct ieee80211_mgmt *mgmt =
|
||||
(struct ieee80211_mgmt *)frame_ind->frameBuf;
|
||||
|
||||
/* Get the global VOSS context.*/
|
||||
vos_context = vos_get_global_context(VOS_MODULE_ID_SYS, NULL);
|
||||
@@ -11877,6 +11879,12 @@ void hdd_indicate_mgmt_frame(tSirSmeMgmtFrameInd *frame_ind)
|
||||
{
|
||||
return;
|
||||
}
|
||||
|
||||
if (frame_ind->frameLen < ieee80211_hdrlen(mgmt->frame_control)) {
|
||||
hddLog(LOGE, FL(" Invalid frame length"));
|
||||
return;
|
||||
}
|
||||
|
||||
adapter = hdd_get_adapter_by_sme_session_id(hdd_ctx,
|
||||
frame_ind->sessionId);
|
||||
|
||||
|
||||
Reference in New Issue
Block a user