qcacmn: Avoid buffer overflow in roam scan stats extract handler
In extract_roam_scan_stats_res_evt_tlv(), there is potential buffer-overflow due to no input validation of following event parameters from firmware: (a) Roam scan frequencies against maximum value of 50 (WMI_ROAM_SCAN_STATS_CHANNELS_MAX) and (b) Roam scan candidates against maximum value of 4 (WMI_ROAM_SCAN_STATS_CANDIDATES_MAX) To fix this, validate roam scan stats event parameters. Change-Id: I866b492f7ccb48c4960ff25a9e817cbdb394509e CRs-Fixed: 2348299
Loading
Please register or sign in to comment