diff options
| author | Johannes Berg <johannes.berg@intel.com> | 2014-01-23 10:20:29 -0500 |
|---|---|---|
| committer | Johannes Berg <johannes.berg@intel.com> | 2014-02-04 15:58:07 -0500 |
| commit | d8ca16db6bb23d03fcb794df44bae64ae976f27c (patch) | |
| tree | f577a829374c0f9daba8bf70e1ea3d6ac107089c /include/linux | |
| parent | ae811e21df28deb4c2adab0a47fc3da4f56d777b (diff) | |
mac80211: add length check in ieee80211_is_robust_mgmt_frame()
A few places weren't checking that the frame passed to the
function actually has enough data even though the function
clearly documents it must have a payload byte. Make this
safer by changing the function to take an skb and checking
the length inside. The old version is preserved for now as
the rtl* drivers use it and don't have a correct skb.
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Diffstat (limited to 'include/linux')
| -rw-r--r-- | include/linux/ieee80211.h | 15 |
1 files changed, 13 insertions, 2 deletions
diff --git a/include/linux/ieee80211.h b/include/linux/ieee80211.h index e526a8cecb70..923c478030a3 100644 --- a/include/linux/ieee80211.h +++ b/include/linux/ieee80211.h | |||
| @@ -2192,10 +2192,10 @@ static inline u8 *ieee80211_get_DA(struct ieee80211_hdr *hdr) | |||
| 2192 | } | 2192 | } |
| 2193 | 2193 | ||
| 2194 | /** | 2194 | /** |
| 2195 | * ieee80211_is_robust_mgmt_frame - check if frame is a robust management frame | 2195 | * _ieee80211_is_robust_mgmt_frame - check if frame is a robust management frame |
| 2196 | * @hdr: the frame (buffer must include at least the first octet of payload) | 2196 | * @hdr: the frame (buffer must include at least the first octet of payload) |
| 2197 | */ | 2197 | */ |
| 2198 | static inline bool ieee80211_is_robust_mgmt_frame(struct ieee80211_hdr *hdr) | 2198 | static inline bool _ieee80211_is_robust_mgmt_frame(struct ieee80211_hdr *hdr) |
| 2199 | { | 2199 | { |
| 2200 | if (ieee80211_is_disassoc(hdr->frame_control) || | 2200 | if (ieee80211_is_disassoc(hdr->frame_control) || |
| 2201 | ieee80211_is_deauth(hdr->frame_control)) | 2201 | ieee80211_is_deauth(hdr->frame_control)) |
| @@ -2224,6 +2224,17 @@ static inline bool ieee80211_is_robust_mgmt_frame(struct ieee80211_hdr *hdr) | |||
| 2224 | } | 2224 | } |
| 2225 | 2225 | ||
| 2226 | /** | 2226 | /** |
| 2227 | * ieee80211_is_robust_mgmt_frame - check if skb contains a robust mgmt frame | ||
| 2228 | * @skb: the skb containing the frame, length will be checked | ||
| 2229 | */ | ||
| 2230 | static inline bool ieee80211_is_robust_mgmt_frame(struct sk_buff *skb) | ||
| 2231 | { | ||
| 2232 | if (skb->len < 25) | ||
| 2233 | return false; | ||
| 2234 | return _ieee80211_is_robust_mgmt_frame((void *)skb->data); | ||
| 2235 | } | ||
| 2236 | |||
| 2237 | /** | ||
| 2227 | * ieee80211_is_public_action - check if frame is a public action frame | 2238 | * ieee80211_is_public_action - check if frame is a public action frame |
| 2228 | * @hdr: the frame | 2239 | * @hdr: the frame |
| 2229 | * @len: length of the frame | 2240 | * @len: length of the frame |
