]> git.proxmox.com Git - mirror_ubuntu-disco-kernel.git/commit
brcmfmac: assure SSID length from firmware is limited
authorArend van Spriel <arend.vanspriel@broadcom.com>
Thu, 18 Apr 2019 07:18:00 +0000 (09:18 +0200)
committerKleber Sacilotto de Souza <kleber.souza@canonical.com>
Tue, 23 Apr 2019 15:25:28 +0000 (17:25 +0200)
commite8c0fc11c19e5f8ebceb2948c2d331e5c627c226
tree3a2ebd721c856da207fd7f0c736938e62d0222f2
parent4699437726e3f99e5da4cede82dc7473f0b9e956
brcmfmac: assure SSID length from firmware is limited

The SSID length as received from firmware should not exceed
IEEE80211_MAX_SSID_LEN as that would result in heap overflow.

Reviewed-by: Hante Meuleman <hante.meuleman@broadcom.com>
Reviewed-by: Pieter-Paul Giesberts <pieter-paul.giesberts@broadcom.com>
Reviewed-by: Franky Lin <franky.lin@broadcom.com>
Signed-off-by: Arend van Spriel <arend.vanspriel@broadcom.com>
Signed-off-by: Kalle Valo <kvalo@codeaurora.org>
CVE-2019-9500

(cherry picked from commit 1b5e2423164b3670e8bc9174e4762d297990deff)
Signed-off-by: Tyler Hicks <tyhicks@canonical.com>
Acked-by: Stefan Bader <stefan.bader@canonical.com>
Acked-by: Colin Ian King <colin.king@canonical.com>
Signed-off-by: Kleber Sacilotto de Souza <kleber.souza@canonical.com>
drivers/net/wireless/broadcom/brcm80211/brcmfmac/cfg80211.c