Skip to content
Commit 8c55dedb authored by Laura Abbott's avatar Laura Abbott Committed by Kalle Valo
Browse files

rtlwifi: Fix potential overflow on P2P code



Nicolas Waisman noticed that even though noa_len is checked for
a compatible length it's still possible to overrun the buffers
of p2pinfo since there's no check on the upper bound of noa_num.
Bound noa_num against P2P_MAX_NOA_NUM.

Reported-by: default avatarNicolas Waisman <nico@semmle.com>
Signed-off-by: default avatarLaura Abbott <labbott@redhat.com>
Acked-by: default avatarPing-Ke Shih <pkshih@realtek.com>
Signed-off-by: default avatarKalle Valo <kvalo@codeaurora.org>
parent 7cded565
0% or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment