Received: by 2002:ac2:464d:0:0:0:0:0 with SMTP id s13csp3263834lfo; Mon, 23 May 2022 00:16:24 -0700 (PDT) X-Google-Smtp-Source: ABdhPJwNRKidhAYf8gntB8wv3phlzsyXPprsry1sh6S49+RCHNZIcrDcGu1VyDo7gjQTB/veLJdU X-Received: by 2002:a62:8349:0:b0:518:143e:235c with SMTP id h70-20020a628349000000b00518143e235cmr22156417pfe.82.1653290184680; Mon, 23 May 2022 00:16:24 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1653290184; cv=none; d=google.com; s=arc-20160816; b=AS578ZfdW+R3mSTahydjI0huaxjkxkUsBXkLlwTjFgk0LAippNBr7v88vTeNvScshI p4jqjuus6SCcYZ2Fr34AZXCoeMbK2OZc+oeZI3yONJiqrivsVT4QvUJFO4fem4YqEKi4 A55zznocTf+q/WAdHFlHkZj4h46HlO9jtQ8ZdGHohP8bR63mte4KWGXqMnMPZC/D9eiW J1qfjGLQJjbxmbgveEFf+3zG/rYZDwI6w/Hc0lLtcu+P2QadAHAjmGvddOKIjmCHT/F+ AgIsbA/tYP5+HNcAg8hM9sgeWUGfIvYuXCnsCLZ769zN9OJ639+CCFHXz1JdvtMIXTSQ ak1w== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:content-transfer-encoding:mime-version :references:in-reply-to:message-id:date:subject:cc:to:from; bh=pNHvSj7Qlaisn5x9H/7CDWdcNlvF8ouTuEdsvQFM/ZA=; b=YhgUd4ohhoNIVLnASYh2LskBgwBK4OmzteZUL0KnN2NJ/cCjkkCglTHDAvsghya1GL 0UEZm5JRDogt0bIqU+zSYZO6NlxMvyfEXk62JRn5ArBW4k3g6lV+/dFDfVyFtGEe/9r+ 6KgF+GOb/aMYPEVt9hMon874wYHSZBoTwvseSbpAW6DhkytixdD2Y4pI4s7i7viumXt9 qjtg2vMjL+q88QYROxCSaS/S8u8Hy/uVZuTFY8+o/mGUF+ZrlybDyL7Hm7iAjTlsxfD4 c5P25ZrNyONPokK+kpWIxrhIEwSy/JzVuzAfHzi+u9sZZ0CpXFNEYubSF1jS5pTr+nHo Mr+Q== ARC-Authentication-Results: i=1; mx.google.com; spf=softfail (google.com: domain of transitioning linux-kernel-owner@vger.kernel.org does not designate 23.128.96.19 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org Return-Path: Received: from lindbergh.monkeyblade.net (lindbergh.monkeyblade.net. [23.128.96.19]) by mx.google.com with ESMTPS id k11-20020a170902ce0b00b001569af11990si9983775plg.507.2022.05.23.00.16.24 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 23 May 2022 00:16:24 -0700 (PDT) Received-SPF: softfail (google.com: domain of transitioning linux-kernel-owner@vger.kernel.org does not designate 23.128.96.19 as permitted sender) client-ip=23.128.96.19; Authentication-Results: mx.google.com; spf=softfail (google.com: domain of transitioning linux-kernel-owner@vger.kernel.org does not designate 23.128.96.19 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org Received: from vger.kernel.org (vger.kernel.org [23.128.96.18]) by lindbergh.monkeyblade.net (Postfix) with ESMTP id E283147550; Sun, 22 May 2022 23:34:20 -0700 (PDT) Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S232395AbiETD6C (ORCPT + 99 others); Thu, 19 May 2022 23:58:02 -0400 Received: from lindbergh.monkeyblade.net ([23.128.96.19]:39806 "EHLO lindbergh.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S229816AbiETD6A (ORCPT ); Thu, 19 May 2022 23:58:00 -0400 Received: from mail-wm1-f44.google.com (mail-wm1-f44.google.com [209.85.128.44]) by lindbergh.monkeyblade.net (Postfix) with ESMTPS id AFE62B41FB; Thu, 19 May 2022 20:57:59 -0700 (PDT) Received: by mail-wm1-f44.google.com with SMTP id bg25so3885533wmb.4; Thu, 19 May 2022 20:57:59 -0700 (PDT) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20210112; h=x-gm-message-state:from:to:cc:subject:date:message-id:in-reply-to :references:mime-version:content-transfer-encoding; bh=pNHvSj7Qlaisn5x9H/7CDWdcNlvF8ouTuEdsvQFM/ZA=; b=8ImggjWuyOVusKMfYPBklOm88M8uLHN9SLGFLfPTA93qT1VQjQPWma7pxmWZ5jfnPi p2jHeGoKIJj7oRD3F+KwIbJBfI4K7TEbxzlF7NNIXkYV99sZLXZlB1dG6XvUhYtYsR6q QAdLKFOlAPLwnrYXNcH7t1JSMERxQIyCocVwsXBns4JCIe5rd654O4XOcejq7AwtvGwI CMjj3v2ECaUTHK3SMK4Qce/E4j0Gv+ibRmEDdaluHJnoGau/daH/GsXAgCwxxpf80TeO okZS/d6sdCVP+F3oQx7GP5Sb8dAgOaCY4k/6PMyFGxyEbDZMneRGmsdiRwpQ1if3gzTg x2mw== X-Gm-Message-State: AOAM5304Be7pA1lfP1VJudrsBLL9SwMJm3GjNowQZQZKgECNzzSbll6z uujJicNRLw8HAzEv/2+lBDS1ZvOfW3w= X-Received: by 2002:a05:600c:3b0a:b0:394:6373:6c45 with SMTP id m10-20020a05600c3b0a00b0039463736c45mr6731690wms.69.1653019078230; Thu, 19 May 2022 20:57:58 -0700 (PDT) Received: from localhost.localdomain ([94.205.35.240]) by smtp.googlemail.com with ESMTPSA id z17-20020a05600c03d100b0039732f1b4a3sm1146878wmd.14.2022.05.19.20.57.55 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 19 May 2022 20:57:57 -0700 (PDT) From: "Denis Efremov (Oracle)" To: gregkh@linuxfoundation.org Cc: "Denis Efremov (Oracle)" , Larry.Finger@lwfinger.net, phil@philpotter.co.uk, dan.carpenter@oracle.com, straube.linux@gmail.com, linux-staging@lists.linux.dev, linux-kernel@vger.kernel.org, kernel-janitors@vger.kernel.org, stable Subject: [PATCH v5.10] staging: rtl8723bs: prevent ->Ssid overflow in rtw_wx_set_scan() Date: Fri, 20 May 2022 07:57:30 +0400 Message-Id: <20220520035730.5533-1-efremov@linux.com> X-Mailer: git-send-email 2.35.3 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Spam-Status: No, score=-1.9 required=5.0 tests=BAYES_00, HEADER_FROM_DIFFERENT_DOMAINS,MAILING_LIST_MULTI,RDNS_NONE, SPF_HELO_NONE,T_SCC_BODY_TEXT_LINE autolearn=no autolearn_force=no version=3.4.6 X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on lindbergh.monkeyblade.net Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org This code has a check to prevent read overflow but it needs another check to prevent writing beyond the end of the ->Ssid[] array. Fixes: 554c0a3abf21 ("staging: Add rtl8723bs sdio wifi driver") Cc: stable Signed-off-by: Denis Efremov (Oracle) --- drivers/staging/rtl8723bs/os_dep/ioctl_linux.c | 6 ++++-- 1 file changed, 4 insertions(+), 2 deletions(-) diff --git a/drivers/staging/rtl8723bs/os_dep/ioctl_linux.c b/drivers/staging/rtl8723bs/os_dep/ioctl_linux.c index 902ac8169948..083ff72976cf 100644 --- a/drivers/staging/rtl8723bs/os_dep/ioctl_linux.c +++ b/drivers/staging/rtl8723bs/os_dep/ioctl_linux.c @@ -1351,9 +1351,11 @@ static int rtw_wx_set_scan(struct net_device *dev, struct iw_request_info *a, sec_len = *(pos++); len -= 1; - if (sec_len > 0 && sec_len <= len) { + if (sec_len > 0 && + sec_len <= len && + sec_len <= 32) { ssid[ssid_index].SsidLength = sec_len; - memcpy(ssid[ssid_index].Ssid, pos, ssid[ssid_index].SsidLength); + memcpy(ssid[ssid_index].Ssid, pos, sec_len); /* DBG_871X("%s COMBO_SCAN with specific ssid:%s, %d\n", __func__ */ /* , ssid[ssid_index].Ssid, ssid[ssid_index].SsidLength); */ ssid_index++; -- 2.35.3