diff options
| author | Pragaspathi Thilagaraj <tpragasp@codeaurora.org> | 2018-07-06 15:43:02 +0530 |
|---|---|---|
| committer | nshrivas <nshrivas@codeaurora.org> | 2018-07-11 19:52:25 -0700 |
| commit | cf0d6ce33a54dcbcf2b26878b1b620e049f7eed5 (patch) | |
| tree | 5dc5be0010913e60cdffdf85788468599bc2deb3 /tools/perf/scripts/python | |
| parent | 1b77e55c6841d4d333d842845ff39bdb17724085 (diff) | |
qcacld-3.0: Fix possible OOB in lim_chk_n_process_wpa_rsn_ie
In the function lim_chk_n_process_wpa_rsn_ie, if wpa IE is
present, then dot11f_unpack_ie_wpa is called to copy the wpa IE
to destination buffer. assoc_req->wpa.length is passed as the
length to copy the IE. As this length includes 4 bytes of the
OUI fields also, this could result in OOB read.
Change the length passed to the dot11f_unpack_ie_wpa as
(assoc_req->wpa.length - 4), so that the additional 4 bytes of
the OUI fields are excluded.
Change-Id: If972b3a19d239bb955c7b4d4c7d94e25aa878f21
CRs-Fixed: 2267557
Diffstat (limited to 'tools/perf/scripts/python')
0 files changed, 0 insertions, 0 deletions
