wil6210: missing length check in wil_cfg80211_mgmt_tx
Add a length check in wil_cfg80211_mgmt_tx to detect unsigned integer overflow. Change-Id: I37f988481433a2e1238831980715aef32aa89a85 Signed-off-by: Lior David <liord@codeaurora.org>
This commit is contained in:
parent
6e5a9b3250
commit
3d38ac71cc
1 changed files with 7 additions and 3 deletions
|
@ -977,7 +977,7 @@ int wil_cfg80211_mgmt_tx(struct wiphy *wiphy, struct wireless_dev *wdev,
|
||||||
u64 *cookie)
|
u64 *cookie)
|
||||||
{
|
{
|
||||||
const u8 *buf = params->buf;
|
const u8 *buf = params->buf;
|
||||||
size_t len = params->len;
|
size_t len = params->len, total;
|
||||||
struct wil6210_priv *wil = wiphy_to_wil(wiphy);
|
struct wil6210_priv *wil = wiphy_to_wil(wiphy);
|
||||||
int rc;
|
int rc;
|
||||||
bool tx_status = false;
|
bool tx_status = false;
|
||||||
|
@ -1002,7 +1002,11 @@ int wil_cfg80211_mgmt_tx(struct wiphy *wiphy, struct wireless_dev *wdev,
|
||||||
if (len < sizeof(struct ieee80211_hdr_3addr))
|
if (len < sizeof(struct ieee80211_hdr_3addr))
|
||||||
return -EINVAL;
|
return -EINVAL;
|
||||||
|
|
||||||
cmd = kmalloc(sizeof(*cmd) + len, GFP_KERNEL);
|
total = sizeof(*cmd) + len;
|
||||||
|
if (total < len)
|
||||||
|
return -EINVAL;
|
||||||
|
|
||||||
|
cmd = kmalloc(total, GFP_KERNEL);
|
||||||
if (!cmd) {
|
if (!cmd) {
|
||||||
rc = -ENOMEM;
|
rc = -ENOMEM;
|
||||||
goto out;
|
goto out;
|
||||||
|
@ -1012,7 +1016,7 @@ int wil_cfg80211_mgmt_tx(struct wiphy *wiphy, struct wireless_dev *wdev,
|
||||||
cmd->len = cpu_to_le16(len);
|
cmd->len = cpu_to_le16(len);
|
||||||
memcpy(cmd->payload, buf, len);
|
memcpy(cmd->payload, buf, len);
|
||||||
|
|
||||||
rc = wmi_call(wil, WMI_SW_TX_REQ_CMDID, cmd, sizeof(*cmd) + len,
|
rc = wmi_call(wil, WMI_SW_TX_REQ_CMDID, cmd, total,
|
||||||
WMI_SW_TX_COMPLETE_EVENTID, &evt, sizeof(evt), 2000);
|
WMI_SW_TX_COMPLETE_EVENTID, &evt, sizeof(evt), 2000);
|
||||||
if (rc == 0)
|
if (rc == 0)
|
||||||
tx_status = !evt.evt.status;
|
tx_status = !evt.evt.status;
|
||||||
|
|
Loading…
Add table
Reference in a new issue