Patrick Williams | c124f4f | 2015-09-15 14:41:29 -0500 | [diff] [blame] | 1 | From 9ed4eee345f85e3025c33c6e20aa25696e341ccd Mon Sep 17 00:00:00 2001 |
| 2 | From: Jouni Malinen <jouni@qca.qualcomm.com> |
| 3 | Date: Tue, 7 Apr 2015 11:32:11 +0300 |
| 4 | Subject: [PATCH] P2P: Validate SSID element length before copying it |
| 5 | (CVE-2015-1863) |
| 6 | |
| 7 | This fixes a possible memcpy overflow for P2P dev->oper_ssid in |
| 8 | p2p_add_device(). The length provided by the peer device (0..255 bytes) |
| 9 | was used without proper bounds checking and that could have resulted in |
| 10 | arbitrary data of up to 223 bytes being written beyond the end of the |
| 11 | dev->oper_ssid[] array (of which about 150 bytes would be beyond the |
| 12 | heap allocation) when processing a corrupted management frame for P2P |
| 13 | peer discovery purposes. |
| 14 | |
| 15 | This could result in corrupted state in heap, unexpected program |
| 16 | behavior due to corrupted P2P peer device information, denial of service |
| 17 | due to process crash, exposure of memory contents during GO Negotiation, |
| 18 | and potentially arbitrary code execution. |
| 19 | |
| 20 | Thanks to Google security team for reporting this issue and smart |
| 21 | hardware research group of Alibaba security team for discovering it. |
| 22 | |
| 23 | Signed-off-by: Jouni Malinen <jouni@qca.qualcomm.com> |
| 24 | |
| 25 | Upstream-Status: Backport |
| 26 | |
| 27 | Signed-off-by: Yue Tao <yue.tao@windriver.com> |
| 28 | |
| 29 | --- |
| 30 | src/p2p/p2p.c | 1 + |
| 31 | 1 file changed, 1 insertion(+) |
| 32 | |
| 33 | diff --git a/src/p2p/p2p.c b/src/p2p/p2p.c |
| 34 | index f584fae..a45fe73 100644 |
| 35 | --- a/src/p2p/p2p.c |
| 36 | +++ b/src/p2p/p2p.c |
| 37 | @@ -778,6 +778,7 @@ int p2p_add_device(struct p2p_data *p2p, const u8 *addr, int freq, |
| 38 | if (os_memcmp(addr, p2p_dev_addr, ETH_ALEN) != 0) |
| 39 | os_memcpy(dev->interface_addr, addr, ETH_ALEN); |
| 40 | if (msg.ssid && |
| 41 | + msg.ssid[1] <= sizeof(dev->oper_ssid) && |
| 42 | (msg.ssid[1] != P2P_WILDCARD_SSID_LEN || |
| 43 | os_memcmp(msg.ssid + 2, P2P_WILDCARD_SSID, P2P_WILDCARD_SSID_LEN) |
| 44 | != 0)) { |
| 45 | -- |
| 46 | 1.7.9.5 |
| 47 | |