From patchwork Fri Sep 8 19:13:42 2017 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Kevin Cernekee X-Patchwork-Id: 9944907 X-Patchwork-Delegate: kvalo@adurom.com Return-Path: Received: from mail.wl.linuxfoundation.org (pdx-wl-mail.web.codeaurora.org [172.30.200.125]) by pdx-korg-patchwork.web.codeaurora.org (Postfix) with ESMTP id 854716035D for ; Fri, 8 Sep 2017 19:14:19 +0000 (UTC) Received: from mail.wl.linuxfoundation.org (localhost [127.0.0.1]) by mail.wl.linuxfoundation.org (Postfix) with ESMTP id 7209B28825 for ; Fri, 8 Sep 2017 19:14:19 +0000 (UTC) Received: by mail.wl.linuxfoundation.org (Postfix, from userid 486) id 66CB128842; Fri, 8 Sep 2017 19:14:19 +0000 (UTC) X-Spam-Checker-Version: SpamAssassin 3.3.1 (2010-03-16) on pdx-wl-mail.web.codeaurora.org X-Spam-Level: X-Spam-Status: No, score=-6.9 required=2.0 tests=BAYES_00,RCVD_IN_DNSWL_HI autolearn=ham version=3.3.1 Received: from vger.kernel.org (vger.kernel.org [209.132.180.67]) by mail.wl.linuxfoundation.org (Postfix) with ESMTP id 1AEC728825 for ; Fri, 8 Sep 2017 19:14:19 +0000 (UTC) Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1756951AbdIHTOP (ORCPT ); Fri, 8 Sep 2017 15:14:15 -0400 Received: from mail-pf0-f175.google.com ([209.85.192.175]:35623 "EHLO mail-pf0-f175.google.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1756928AbdIHTON (ORCPT ); Fri, 8 Sep 2017 15:14:13 -0400 Received: by mail-pf0-f175.google.com with SMTP id g13so5880886pfm.2 for ; Fri, 08 Sep 2017 12:14:13 -0700 (PDT) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:from:to:cc:subject:date:message-id:in-reply-to :references; bh=CRjcO795KI8U7EDfkDnBQJzXhPaoNBg5dFNJpYlTHMo=; b=b3zjBg9edSOnDVr5Q0hGuhhWuw/GpcWgOCmoCtvcCDmHP+iEEWe/kfTeUxVdp3Uk8Z yi/5eAInVRRfxBRsxna89WALheopd4SW8Fyr7T6rqJAZDYtVtjKMFCtFtRPACGwrxtdi uHl7BIGJV/sXn3gvEz43+wzFYpPETzgl5w006PRZxp5doe1YPJKUNPOxLoGIb/pOumFB w2OvAERTJSHd7GXs0A3nZE6imFIPNh4yUEpugrLx0SLK+9XJoGR20p6wZZ+bjNunl90a ZxAKyLohdZFOuhb/yXtFAK0vhCOX7arB/u+JDjwCtP/qw66vZJbJPUt76XAUfVUDnpgj SiUA== X-Gm-Message-State: AHPjjUjD1Ypyz93qbhhvLqOGSk4VQX2nRhCU01R/LHnguaGML2rbD7Yw +GyhQK0m5HhmNo/O X-Google-Smtp-Source: ADKCNb5KCUcXGk27YZWIYKiwrjIxZKUYiXRtEsaHCPUcsFtRi+0S5Lna51HaoKAxpsth70TSCmkQKg== X-Received: by 10.99.114.19 with SMTP id n19mr4068490pgc.256.1504898052695; Fri, 08 Sep 2017 12:14:12 -0700 (PDT) Received: from kcl.mtv.corp.google.com ([172.22.113.159]) by smtp.gmail.com with ESMTPSA id z83sm4794103pfd.10.2017.09.08.12.14.11 (version=TLS1_2 cipher=ECDHE-RSA-AES128-SHA bits=128/128); Fri, 08 Sep 2017 12:14:11 -0700 (PDT) From: Kevin Cernekee To: arend.vanspriel@broadcom.com, franky.lin@broadcom.com Cc: brcm80211-dev-list.pdl@broadcom.com, linux-wireless@vger.kernel.org, mnissler@chromium.org Subject: [PATCH 3/3] brcmfmac: Add check for short event packets Date: Fri, 8 Sep 2017 12:13:42 -0700 Message-Id: <20170908191342.28053-4-cernekee@chromium.org> X-Mailer: git-send-email 2.14.1.581.gf28d330327-goog In-Reply-To: <20170908191342.28053-1-cernekee@chromium.org> References: <20170908191342.28053-1-cernekee@chromium.org> Sender: linux-wireless-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: linux-wireless@vger.kernel.org X-Virus-Scanned: ClamAV using ClamSMTP The length of the data in the received skb is currently passed into brcmf_fweh_process_event() as packet_len, but this value is not checked. event_packet should be followed by DATALEN bytes of additional event data. Ensure that the received packet actually contains at least DATALEN bytes of additional data, to avoid copying uninitialized memory into event->data. Suggested-by: Mattias Nissler Signed-off-by: Kevin Cernekee Reviewed-by: Arend van Spriel --- drivers/net/wireless/broadcom/brcm80211/brcmfmac/fweh.c | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/drivers/net/wireless/broadcom/brcm80211/brcmfmac/fweh.c b/drivers/net/wireless/broadcom/brcm80211/brcmfmac/fweh.c index 5aabdc9ed7e0..4cad1f0d2a82 100644 --- a/drivers/net/wireless/broadcom/brcm80211/brcmfmac/fweh.c +++ b/drivers/net/wireless/broadcom/brcm80211/brcmfmac/fweh.c @@ -429,7 +429,8 @@ void brcmf_fweh_process_event(struct brcmf_pub *drvr, if (code != BRCMF_E_IF && !fweh->evt_handler[code]) return; - if (datalen > BRCMF_DCMD_MAXLEN) + if (datalen > BRCMF_DCMD_MAXLEN || + datalen + sizeof(*event_packet) < packet_len) return; if (in_interrupt())