Return-path: Received: from mail.tpi.com ([70.99.223.143]:3689 "EHLO mail.tpi.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1754889Ab2BHVI2 (ORCPT ); Wed, 8 Feb 2012 16:08:28 -0500 From: Tim Gardner To: Larry.Finger@lwfinger.net Cc: Tim Gardner , Chaoming Li , "John W. Linville" , linux-wireless@vger.kernel.org, netdev@vger.kernel.org, linux-kernel@vger.kernel.org Subject: [PATCH] rtlwifi: rtl8192se firmware load can overflow target buffer Date: Wed, 8 Feb 2012 14:08:10 -0700 Message-Id: <1328735291-33220-1-git-send-email-tim.gardner@canonical.com> (sfid-20120208_220854_039195_8815ED95) Sender: linux-wireless-owner@vger.kernel.org List-ID: The firmware file size check does not use the correct limit. Cc: Larry Finger Cc: Chaoming Li Cc: John W. Linville Cc: linux-wireless@vger.kernel.org Cc: netdev@vger.kernel.org Cc: linux-kernel@vger.kernel.org Signed-off-by: Tim Gardner --- drivers/net/wireless/rtlwifi/rtl8192se/fw.h | 3 ++- drivers/net/wireless/rtlwifi/rtl8192se/sw.c | 2 +- 2 files changed, 3 insertions(+), 2 deletions(-) diff --git a/drivers/net/wireless/rtlwifi/rtl8192se/fw.h b/drivers/net/wireless/rtlwifi/rtl8192se/fw.h index babe85d..5c377fc 100644 --- a/drivers/net/wireless/rtlwifi/rtl8192se/fw.h +++ b/drivers/net/wireless/rtlwifi/rtl8192se/fw.h @@ -30,6 +30,7 @@ #define __REALTEK_FIRMWARE92S_H__ #define RTL8190_MAX_FIRMWARE_CODE_SIZE 64000 +#define RTL8190_MAX_RAW_FIRMWARE_CODE_SIZE 164000 #define RTL8190_CPU_START_OFFSET 0x80 /* Firmware Local buffer size. 64k */ #define MAX_FIRMWARE_CODE_SIZE 0xFF00 @@ -217,7 +218,7 @@ struct rt_firmware { u8 fw_emem[RTL8190_MAX_FIRMWARE_CODE_SIZE]; u32 fw_imem_len; u32 fw_emem_len; - u8 sz_fw_tmpbuffer[164000]; + u8 sz_fw_tmpbuffer[RTL8190_MAX_RAW_FIRMWARE_CODE_SIZE]; u32 sz_fw_tmpbufferlen; u16 cmdpacket_fragthresold; }; diff --git a/drivers/net/wireless/rtlwifi/rtl8192se/sw.c b/drivers/net/wireless/rtlwifi/rtl8192se/sw.c index ca38dd9..155da0a 100644 --- a/drivers/net/wireless/rtlwifi/rtl8192se/sw.c +++ b/drivers/net/wireless/rtlwifi/rtl8192se/sw.c @@ -105,7 +105,7 @@ static void rtl92se_fw_cb(const struct firmware *firmware, void *context) rtlpriv->max_fw_size = 0; return; } - if (firmware->size > rtlpriv->max_fw_size) { + if (firmware->size >= RTL8190_MAX_RAW_FIRMWARE_CODE_SIZE) { RT_TRACE(rtlpriv, COMP_ERR, DBG_EMERG, "Firmware is too big!\n"); release_firmware(firmware); -- 1.7.9