提交 2636c308 编写于 作者: A Amitkumar Karwar 提交者: John W. Linville

mwifiex: fix invalid memory access in mwifiex_ret_tx_rate_cfg()

As tlv_buf_len is decremented at the end of the loop, we may have
accessed invalid memory in the last iteration.
Modify the while condition and add a break statement at the
begining of the loop to fix the problem.
Reported-by: NDan Carpenter <dan.carpenter@oracle.com>
Signed-off-by: NAmitkumar Karwar <akarwar@marvell.com>
Signed-off-by: NBing Zhao <bzhao@marvell.com>
Signed-off-by: NJohn W. Linville <linville@tuxdriver.com>
上级 fe1c9a44
...@@ -274,17 +274,20 @@ static int mwifiex_ret_tx_rate_cfg(struct mwifiex_private *priv, ...@@ -274,17 +274,20 @@ static int mwifiex_ret_tx_rate_cfg(struct mwifiex_private *priv,
struct host_cmd_ds_tx_rate_cfg *rate_cfg = &resp->params.tx_rate_cfg; struct host_cmd_ds_tx_rate_cfg *rate_cfg = &resp->params.tx_rate_cfg;
struct mwifiex_rate_scope *rate_scope; struct mwifiex_rate_scope *rate_scope;
struct mwifiex_ie_types_header *head; struct mwifiex_ie_types_header *head;
u16 tlv, tlv_buf_len; u16 tlv, tlv_buf_len, tlv_buf_left;
u8 *tlv_buf; u8 *tlv_buf;
u32 i; u32 i;
tlv_buf = ((u8 *)rate_cfg) + tlv_buf = ((u8 *)rate_cfg) + sizeof(struct host_cmd_ds_tx_rate_cfg);
sizeof(struct host_cmd_ds_tx_rate_cfg); tlv_buf_left = le16_to_cpu(resp->size) - S_DS_GEN - sizeof(*rate_cfg);
tlv_buf_len = le16_to_cpu(*(__le16 *) (tlv_buf + sizeof(u16)));
while (tlv_buf && tlv_buf_len > 0) { while (tlv_buf_left >= sizeof(*head)) {
tlv = (*tlv_buf); head = (struct mwifiex_ie_types_header *)tlv_buf;
tlv = tlv | (*(tlv_buf + 1) << 8); tlv = le16_to_cpu(head->type);
tlv_buf_len = le16_to_cpu(head->len);
if (tlv_buf_left < (sizeof(*head) + tlv_buf_len))
break;
switch (tlv) { switch (tlv) {
case TLV_TYPE_RATE_SCOPE: case TLV_TYPE_RATE_SCOPE:
...@@ -304,9 +307,8 @@ static int mwifiex_ret_tx_rate_cfg(struct mwifiex_private *priv, ...@@ -304,9 +307,8 @@ static int mwifiex_ret_tx_rate_cfg(struct mwifiex_private *priv,
/* Add RATE_DROP tlv here */ /* Add RATE_DROP tlv here */
} }
head = (struct mwifiex_ie_types_header *) tlv_buf; tlv_buf += (sizeof(*head) + tlv_buf_len);
tlv_buf += le16_to_cpu(head->len) + sizeof(*head); tlv_buf_left -= (sizeof(*head) + tlv_buf_len);
tlv_buf_len -= le16_to_cpu(head->len);
} }
priv->is_data_rate_auto = mwifiex_is_rate_auto(priv); priv->is_data_rate_auto = mwifiex_is_rate_auto(priv);
......
Markdown is supported
0% .
You are about to add 0 people to the discussion. Proceed with caution.
先完成此消息的编辑!
想要评论请 注册