commit | 7df624d4290a73aa4de56f9bb419f9515970b43b | [log] [tgz] |
---|---|---|
author | Madan Mohan Koyyalamudi <c_mkoyya@qca.qualcomm.com> | Wed Oct 31 16:32:50 2012 -0700 |
committer | Jeff Johnson <jjohnson@qca.qualcomm.com> | Fri Nov 30 15:05:57 2012 -0800 |
tree | b058ad40a0660294e70fe83504f3124669e769a9 | |
parent | 613b0a484693f124b1ea3701257b227f64ba0c3e [diff] |
wlan: Buffer overflow due to invalid WscIeLen. The problem was in the function limGetBssDescription the 'pBssDescription->WscIeLen' variable was not extracted from pBuf pointer and there is no check in the code for buffer overflow while copying to the pointer pBssDescription->WscIeProbeRsp from pBuf which leads to kernel crash. Change-Id: I28bcf770853a8840babdfe012a3a578dc652f297 CR-Fixed: 415391