From patchwork Fri Sep 8 19:13:40 2017 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Kevin Cernekee X-Patchwork-Id: 9944903 X-Patchwork-Delegate: kvalo@adurom.com Return-Path: Received: from mail.wl.linuxfoundation.org (pdx-wl-mail.web.codeaurora.org [172.30.200.125]) by pdx-korg-patchwork.web.codeaurora.org (Postfix) with ESMTP id 329A06035D for ; Fri, 8 Sep 2017 19:14:15 +0000 (UTC) Received: from mail.wl.linuxfoundation.org (localhost [127.0.0.1]) by mail.wl.linuxfoundation.org (Postfix) with ESMTP id 1F87528825 for ; Fri, 8 Sep 2017 19:14:15 +0000 (UTC) Received: by mail.wl.linuxfoundation.org (Postfix, from userid 486) id 146DE28842; Fri, 8 Sep 2017 19:14:15 +0000 (UTC) X-Spam-Checker-Version: SpamAssassin 3.3.1 (2010-03-16) on pdx-wl-mail.web.codeaurora.org X-Spam-Level: X-Spam-Status: No, score=-6.9 required=2.0 tests=BAYES_00,RCVD_IN_DNSWL_HI autolearn=ham version=3.3.1 Received: from vger.kernel.org (vger.kernel.org [209.132.180.67]) by mail.wl.linuxfoundation.org (Postfix) with ESMTP id 359EF28825 for ; Fri, 8 Sep 2017 19:14:14 +0000 (UTC) Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1756939AbdIHTOM (ORCPT ); Fri, 8 Sep 2017 15:14:12 -0400 Received: from mail-pg0-f41.google.com ([74.125.83.41]:37912 "EHLO mail-pg0-f41.google.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1756928AbdIHTOL (ORCPT ); Fri, 8 Sep 2017 15:14:11 -0400 Received: by mail-pg0-f41.google.com with SMTP id v66so6247699pgb.5 for ; Fri, 08 Sep 2017 12:14:10 -0700 (PDT) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:from:to:cc:subject:date:message-id:in-reply-to :references; bh=vbsFjLicbXuZHlvuBD7LXpZqhGrvmTNSQy8W4vQ7VmI=; b=Uw635QNvu254E7SmxDmoSz60H7D91QYIfX/cs7SsEGa0JtzJByexY1gJaeMJFZpVd0 fjEVRn3V7VKyWyR5e3SZ8r+Lp1j2LzZmWPv82SlvvauNfcJ5uwEf5wsvm3gZp2947T1c gsRf6fzjL7iSpPqaWVEXa5CsewKle3fkGnoC3Vs7xoY9lureG2XTkjEZZP4rSqj+UvLb Pp1GqdyO42foZcZy59MJ3ddfi454BxUIXr8vWmBzQ2tw8uu5/pLW2xAi4N5Vbpk9gfWL vdHBRFUvbtKirV6OTWykJREVd3eebXSh//zR0PLZvOFWd9uQEfIywKDl25h9k6GolFln KAxw== X-Gm-Message-State: AHPjjUj3NKgh72LvSL2LrzkHDIXjHcG6OeSeQTxbXfeQ7F39flLexLH4 EHd8QAbNE3bQC6Ht X-Google-Smtp-Source: ADKCNb5PB4nAj4RCqHkvEuwsrVgUjRoT3dLuJMm1KXK6FfXPxFYZET3tuOHDGR4o4D7NMlbqFLW4hw== X-Received: by 10.99.95.204 with SMTP id t195mr4108598pgb.135.1504898050446; Fri, 08 Sep 2017 12:14:10 -0700 (PDT) Received: from kcl.mtv.corp.google.com ([172.22.113.159]) by smtp.gmail.com with ESMTPSA id z83sm4794103pfd.10.2017.09.08.12.14.08 (version=TLS1_2 cipher=ECDHE-RSA-AES128-SHA bits=128/128); Fri, 08 Sep 2017 12:14:09 -0700 (PDT) From: Kevin Cernekee To: arend.vanspriel@broadcom.com, franky.lin@broadcom.com Cc: brcm80211-dev-list.pdl@broadcom.com, linux-wireless@vger.kernel.org, mnissler@chromium.org Subject: [PATCH 1/3] brcmfmac: Avoid possible out-of-bounds read Date: Fri, 8 Sep 2017 12:13:40 -0700 Message-Id: <20170908191342.28053-2-cernekee@chromium.org> X-Mailer: git-send-email 2.14.1.581.gf28d330327-goog In-Reply-To: <20170908191342.28053-1-cernekee@chromium.org> References: <20170908191342.28053-1-cernekee@chromium.org> Sender: linux-wireless-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: linux-wireless@vger.kernel.org X-Virus-Scanned: ClamAV using ClamSMTP In brcmf_p2p_notify_rx_mgmt_p2p_probereq(), chanspec is assigned before the length of rxframe is validated. This could lead to uninitialized data being printed in a debug message. Since we already have a perfectly good endian-swapped copy of rxframe->chanspec in ch.chspec, and ch.chspec is not modified by decchspec(), avoid the extra assignment and use ch.chspec in the debug print. Suggested-by: Mattias Nissler Signed-off-by: Kevin Cernekee Reviewed-by: Arend van Spriel --- drivers/net/wireless/broadcom/brcm80211/brcmfmac/p2p.c | 3 +-- 1 file changed, 1 insertion(+), 2 deletions(-) diff --git a/drivers/net/wireless/broadcom/brcm80211/brcmfmac/p2p.c b/drivers/net/wireless/broadcom/brcm80211/brcmfmac/p2p.c index 2ce675ab40ef..1c450c0727cb 100644 --- a/drivers/net/wireless/broadcom/brcm80211/brcmfmac/p2p.c +++ b/drivers/net/wireless/broadcom/brcm80211/brcmfmac/p2p.c @@ -1853,7 +1853,6 @@ s32 brcmf_p2p_notify_rx_mgmt_p2p_probereq(struct brcmf_if *ifp, struct afx_hdl *afx_hdl = &p2p->afx_hdl; struct brcmf_cfg80211_vif *vif = ifp->vif; struct brcmf_rx_mgmt_data *rxframe = (struct brcmf_rx_mgmt_data *)data; - u16 chanspec = be16_to_cpu(rxframe->chanspec); struct brcmu_chan ch; u8 *mgmt_frame; u32 mgmt_frame_len; @@ -1906,7 +1905,7 @@ s32 brcmf_p2p_notify_rx_mgmt_p2p_probereq(struct brcmf_if *ifp, cfg80211_rx_mgmt(&vif->wdev, freq, 0, mgmt_frame, mgmt_frame_len, 0); brcmf_dbg(INFO, "mgmt_frame_len (%d) , e->datalen (%d), chanspec (%04x), freq (%d)\n", - mgmt_frame_len, e->datalen, chanspec, freq); + mgmt_frame_len, e->datalen, ch.chspec, freq); return 0; }