Donate to e Foundation | Murena handsets with /e/OS | Own a part of Murena! Learn more

Commit 926f70d3 authored by CNSS_WLAN Service's avatar CNSS_WLAN Service Committed by Gerrit - the friendly Code Review server
Browse files

Merge "wlan: Fix integer overflow in rrm_fill_beacon_ies()" into wlan-driver.lnx.1.0

parents 78d0ef99 17937822
Loading
Loading
Loading
Loading
+10 −2
Original line number Diff line number Diff line
@@ -678,7 +678,8 @@ rrmFillBeaconIes( tpAniSirGlobal pMac,
                  tANI_U8 *eids, tANI_U8 numEids,
                  tpSirBssDescription pBssDesc )
{
   tANI_U8 len, *pBcnIes, BcnNumIes, count = 0, i;
   tANI_U8 len, *pBcnIes, count = 0, i;
   tANI_U16 BcnNumIes = 0;

   if( (pIes == NULL) || (pNumIes == NULL) || (pBssDesc == NULL) )
   {
@@ -705,10 +706,17 @@ rrmFillBeaconIes( tpAniSirGlobal pMac,

   while ( BcnNumIes > 0 )
   {
      len = *(pBcnIes + 1) + 2; //element id + length.
      len = *(pBcnIes + 1); //element id + length.
      len += 2;
      limLog( pMac, LOG3, "EID = %d, len = %d total = %d",
             *pBcnIes, *(pBcnIes+1), len );

      if (BcnNumIes < len || len <= 2) {
          limLog(pMac, LOGE, "RRM: Invalid IE len:%d exp_len:%d",
                 len, BcnNumIes);
          break;
      }

      i = 0;
      do
      {