Message ID | 20190529125220.17066-2-tiwai@suse.de (mailing list archive) |
---|---|
State | Accepted |
Commit | 13ec7f10b87f5fc04c4ccbd491c94c7980236a74 |
Delegated to: | Kalle Valo |
Headers | show |
Series | Buffer overflow / read checks in mwifiex | expand |
Takashi Iwai <tiwai@suse.de> wrote: > mwifiex_update_bss_desc_with_ie() calls memcpy() unconditionally in > a couple places without checking the destination size. Since the > source is given from user-space, this may trigger a heap buffer > overflow. > > Fix it by putting the length check before performing memcpy(). > > This fix addresses CVE-2019-3846. > > Reported-by: huangwen <huangwen@venustech.com.cn> > Signed-off-by: Takashi Iwai <tiwai@suse.de> 2 patches applied to wireless-drivers.git, thanks. 13ec7f10b87f mwifiex: Fix possible buffer overflows at parsing bss descriptor 685c9b7750bf mwifiex: Abort at too short BSS descriptor element
diff --git a/drivers/net/wireless/marvell/mwifiex/scan.c b/drivers/net/wireless/marvell/mwifiex/scan.c index 935778ec9a1b..64ab6fe78c0d 100644 --- a/drivers/net/wireless/marvell/mwifiex/scan.c +++ b/drivers/net/wireless/marvell/mwifiex/scan.c @@ -1247,6 +1247,8 @@ int mwifiex_update_bss_desc_with_ie(struct mwifiex_adapter *adapter, } switch (element_id) { case WLAN_EID_SSID: + if (element_len > IEEE80211_MAX_SSID_LEN) + return -EINVAL; bss_entry->ssid.ssid_len = element_len; memcpy(bss_entry->ssid.ssid, (current_ptr + 2), element_len); @@ -1256,6 +1258,8 @@ int mwifiex_update_bss_desc_with_ie(struct mwifiex_adapter *adapter, break; case WLAN_EID_SUPP_RATES: + if (element_len > MWIFIEX_SUPPORTED_RATES) + return -EINVAL; memcpy(bss_entry->data_rates, current_ptr + 2, element_len); memcpy(bss_entry->supported_rates, current_ptr + 2,
mwifiex_update_bss_desc_with_ie() calls memcpy() unconditionally in a couple places without checking the destination size. Since the source is given from user-space, this may trigger a heap buffer overflow. Fix it by putting the length check before performing memcpy(). This fix addresses CVE-2019-3846. Reported-by: huangwen <huangwen@venustech.com.cn> Signed-off-by: Takashi Iwai <tiwai@suse.de> --- drivers/net/wireless/marvell/mwifiex/scan.c | 4 ++++ 1 file changed, 4 insertions(+)