From: Greg KH <gregkh@suse.de>
To: linux-kernel@vger.kernel.org, stable@kernel.org, jejb@kernel.org
Cc: Justin Forbes <jmforbes@linuxtx.org>,
Zwane Mwaikambo <zwane@arm.linux.org.uk>,
"Theodore Ts'o" <tytso@mit.edu>,
Randy Dunlap <rdunlap@xenotime.net>,
Dave Jones <davej@redhat.com>,
Chuck Wolber <chuckw@quantumlinux.com>,
Chris Wedgwood <reviews@ml.cw.f00f.org>,
Michael Krufky <mkrufky@linuxtv.org>,
Chuck Ebbert <cebbert@redhat.com>,
Domenico Andreoli <cavokz@gmail.com>, Willy Tarreau <w@1wt.eu>,
Rodrigo Rubira Branco <rbranco@la.checkpoint.com>,
Jake Edge <jake@lwn.net>, Eugene Teo <eteo@redhat.com>,
torvalds@linux-foundation.org, akpm@linux-foundation.org,
alan@lxorguk.ukuu.org.uk,
Johannes Berg <johannes@sipsolutions.net>,
"John W. Linville" <linville@tuxdriver.com>
Subject: [patch 06/23] libertas: fix buffer overrun
Date: Fri, 7 Nov 2008 15:15:25 -0800 [thread overview]
Message-ID: <20081107231525.GG1108@kroah.com> (raw)
In-Reply-To: <20081107231457.GA1108@kroah.com>
[-- Attachment #1: libertas-fix-buffer-overrun.patch --]
[-- Type: text/plain, Size: 1204 bytes --]
2.6.26-stable review patch. If anyone has any objections, please let us know.
------------------
From: Johannes Berg <johannes@sipsolutions.net>
commit 48735d8d8bd701b1e0cd3d49c21e5e385ddcb077 upstream
If somebody sends an invalid beacon/probe response, that can trash the
whole BSS descriptor. The descriptor is, luckily, large enough so that
it cannot scribble past the end of it; it's well above 400 bytes long.
Signed-off-by: Johannes Berg <johannes@sipsolutions.net>
Signed-off-by: John W. Linville <linville@tuxdriver.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@suse.de>
---
drivers/net/wireless/libertas/scan.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
--- a/drivers/net/wireless/libertas/scan.c
+++ b/drivers/net/wireless/libertas/scan.c
@@ -598,8 +598,8 @@ static int lbs_process_bss(struct bss_de
switch (elem->id) {
case MFIE_TYPE_SSID:
- bss->ssid_len = elem->len;
- memcpy(bss->ssid, elem->data, elem->len);
+ bss->ssid_len = min_t(int, 32, elem->len);
+ memcpy(bss->ssid, elem->data, bss->ssid_len);
lbs_deb_scan("got SSID IE: '%s', len %u\n",
escape_essid(bss->ssid, bss->ssid_len),
bss->ssid_len);
--
next prev parent reply other threads:[~2008-11-07 23:25 UTC|newest]
Thread overview: 35+ messages / expand[flat|nested] mbox.gz Atom feed top
[not found] <20081107224818.593212310@mini.kroah.org>
2008-11-07 23:14 ` [patch 00/23] 2.6.26.8-stable review Greg KH
2008-11-07 23:15 ` [patch 01/23] gpiolib: fix oops in gpio_get_value_cansleep() Greg KH
2008-11-07 23:15 ` [patch 02/23] ext: Avoid printk floods in the face of directory corruption (CVE-2008-3528) Greg KH
2008-11-10 2:42 ` Eugene Teo
2008-11-10 18:06 ` Greg KH
2008-11-10 18:14 ` Eric Sandeen
2008-11-07 23:15 ` [patch 03/23] edac cell: fix incorrect edac_mode Greg KH
2008-11-07 23:15 ` [patch 04/23] SCSI: qla2xxx: Skip FDMI registration on ISP21xx/22xx parts Greg KH
2008-11-07 23:15 ` [patch 05/23] net: Fix recursive descent in __scm_destroy() Greg KH
2008-11-07 23:15 ` Greg KH [this message]
2008-11-07 23:15 ` [patch 07/23] file caps: always start with clear bprm->caps_* Greg KH
2008-11-07 23:15 ` [patch 08/23] ALSA: use correct lock in snd_ctl_dev_disconnect() Greg KH
2008-11-07 23:15 ` [patch 09/23] ACPI: Always report a sync event after a lid state change Greg KH
2008-11-07 23:15 ` Greg KH
2008-11-07 23:15 ` [patch 10/23] V4L: pvrusb2: Keep MPEG PTSs from drifting away Greg KH
2008-11-07 23:15 ` [patch 11/23] DVB: s5h1411: bugfix: Setting serial or parallel mode could destroy bits Greg KH
2008-11-07 23:15 ` [patch 12/23] DVB: s5h1411: Perform s5h1411 soft reset after tuning Greg KH
2008-11-07 23:15 ` [patch 13/23] DVB: s5h1411: Power down s5h1411 when not in use Greg KH
2008-11-07 23:15 ` [patch 14/23] scx200_i2c: Add missing class parameter Greg KH
2008-11-07 23:15 ` [patch 15/23] net: Fix netdev_run_todo dead-lock Greg KH
2008-11-07 23:15 ` [patch 16/23] tcpv6: fix option space offsets with md5 Greg KH
2008-11-07 23:15 ` [patch 17/23] math-emu: Fix signalling of underflow and inexact while packing result Greg KH
2008-11-07 23:16 ` [patch 18/23] sparc64: Fix race in arch/sparc64/kernel/trampoline.S Greg KH
2008-11-07 23:16 ` [patch 19/23] ACPI: video: fix brightness allocation Greg KH
2008-11-07 23:16 ` [patch 20/23] ACPI: dock: avoid check _STA method Greg KH
2008-11-11 12:16 ` Holger Macht
2008-11-13 21:23 ` [stable] " Greg KH
2008-11-13 21:23 ` Greg KH
2008-11-16 23:36 ` Holger Macht
2008-11-17 4:59 ` Greg KH
2008-11-17 4:59 ` Greg KH
2008-11-07 23:16 ` [patch 21/23] netfilter: xt_iprange: fix range inversion match Greg KH
2008-11-07 23:16 ` [patch 22/23] netfilter: snmp nat leaks memory in case of failure Greg KH
2008-11-07 23:16 ` Greg KH
2008-11-07 23:16 ` [patch 23/23] netfilter: restore lost ifdef guarding defrag exception Greg KH
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20081107231525.GG1108@kroah.com \
--to=gregkh@suse.de \
--cc=akpm@linux-foundation.org \
--cc=alan@lxorguk.ukuu.org.uk \
--cc=cavokz@gmail.com \
--cc=cebbert@redhat.com \
--cc=chuckw@quantumlinux.com \
--cc=davej@redhat.com \
--cc=eteo@redhat.com \
--cc=jake@lwn.net \
--cc=jejb@kernel.org \
--cc=jmforbes@linuxtx.org \
--cc=johannes@sipsolutions.net \
--cc=linux-kernel@vger.kernel.org \
--cc=linville@tuxdriver.com \
--cc=mkrufky@linuxtv.org \
--cc=rbranco@la.checkpoint.com \
--cc=rdunlap@xenotime.net \
--cc=reviews@ml.cw.f00f.org \
--cc=stable@kernel.org \
--cc=torvalds@linux-foundation.org \
--cc=tytso@mit.edu \
--cc=w@1wt.eu \
--cc=zwane@arm.linux.org.uk \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.