diff options
| author | Eliad Peller <eliad@wizery.com> | 2011-11-24 11:13:56 -0500 |
|---|---|---|
| committer | Herton Ronaldo Krzesinski <herton.krzesinski@canonical.com> | 2011-12-12 08:07:05 -0500 |
| commit | 64f6a226e2b5d16f60735dc7da9f1890f194ba40 (patch) | |
| tree | 0b1475dfd9d4e1d810fb8504867c33d048005607 /net/wireless | |
| parent | b70ca92367f7723aeab6ce323f52a9313944984d (diff) | |
nl80211: fix MAC address validation
BugLink: http://bugs.launchpad.net/bugs/902312
commit e007b857e88097c96c45620bf3b04a4e309053d1 upstream.
MAC addresses have a fixed length. The current
policy allows passing < ETH_ALEN bytes, which
might result in reading beyond the buffer.
Signed-off-by: Eliad Peller <eliad@wizery.com>
Signed-off-by: John W. Linville <linville@tuxdriver.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@suse.de>
Signed-off-by: Tim Gardner <tim.gardner@canonical.com>
Diffstat (limited to 'net/wireless')
| -rw-r--r-- | net/wireless/nl80211.c | 4 |
1 files changed, 2 insertions, 2 deletions
diff --git a/net/wireless/nl80211.c b/net/wireless/nl80211.c index 3dac76f33b9..0c2b8080547 100644 --- a/net/wireless/nl80211.c +++ b/net/wireless/nl80211.c | |||
| @@ -83,8 +83,8 @@ static const struct nla_policy nl80211_policy[NL80211_ATTR_MAX+1] = { | |||
| 83 | [NL80211_ATTR_IFINDEX] = { .type = NLA_U32 }, | 83 | [NL80211_ATTR_IFINDEX] = { .type = NLA_U32 }, |
| 84 | [NL80211_ATTR_IFNAME] = { .type = NLA_NUL_STRING, .len = IFNAMSIZ-1 }, | 84 | [NL80211_ATTR_IFNAME] = { .type = NLA_NUL_STRING, .len = IFNAMSIZ-1 }, |
| 85 | 85 | ||
| 86 | [NL80211_ATTR_MAC] = { .type = NLA_BINARY, .len = ETH_ALEN }, | 86 | [NL80211_ATTR_MAC] = { .len = ETH_ALEN }, |
| 87 | [NL80211_ATTR_PREV_BSSID] = { .type = NLA_BINARY, .len = ETH_ALEN }, | 87 | [NL80211_ATTR_PREV_BSSID] = { .len = ETH_ALEN }, |
| 88 | 88 | ||
| 89 | [NL80211_ATTR_KEY] = { .type = NLA_NESTED, }, | 89 | [NL80211_ATTR_KEY] = { .type = NLA_NESTED, }, |
| 90 | [NL80211_ATTR_KEY_DATA] = { .type = NLA_BINARY, | 90 | [NL80211_ATTR_KEY_DATA] = { .type = NLA_BINARY, |
