android_kernel_xiaomi_sm8350/core
wadesong bf39868cae qcacld-3.0: Fix an improper parameter type casting
In function csr_check_concurrent_channel_overlap, local
variable intf_ch is defined as uint16_t, but its pointer
is casted to uint32_t * before invoking
policy_mgr_get_sap_mandatory_channel, which will do
32-bit memory write and causes a stack memory over-
writing.

Call Trace:
  dump_stack+0x46/0x59
  print_address_description+0x66/0x22b
  kasan_report+0x21f/0x245
  policy_mgr_get_sap_mandatory_channel+0x1fd/0x258 [wlan]
  csr_check_concurrent_channel_overlap+0xf84/0x10d2 [wlan]
  sme_check_concurrent_channel_overlap+0xaa/0xf0 [wlan]
  wlansap_check_cc_intf+0x102/0x124 [wlan]
  wlan_hdd_get_channel_for_sap_restart+0x506/0x8f8 [wlan]
  policy_mgr_check_sta_ap_concurrent_ch_intf+0x35e/0x425[wlan]
  process_one_work+0x2cc/0x53b
  worker_thread+0x357/0x490

Change the type of the 2nd parameter to uint16_t within
function policy_mgr_get_sap_mandatory_channel, so only
16-bit memory writing will take place.

Change-Id: If514a394e65d005a1fe025c0e753bf7440dd5dde
CRs-Fixed: 2508798
2019-08-19 06:19:15 -07:00
..
bmi qcacld-3.0: Send user space about FW CRASHED indication 2019-07-05 23:07:30 -07:00
cds qcacld-3.0: support monitor mode enablement by changing driver mode 2019-08-18 23:44:56 -07:00
dp qcacld-3.0: Featurize partial reorder properly 2019-08-19 02:10:41 -07:00
hdd qcacld-3.0: Call target_if_init after dispatcher_init 2019-08-19 02:10:46 -07:00
mac Release 5.2.0.144T 2019-08-19 02:10:46 -07:00
pld qcacld-3.0: Add sdio support for pld_wlan_enable 2019-08-08 11:37:51 -07:00
sap qcacld-3.0: Avoid channel 12, 13 for SAP operation 2019-08-16 08:22:37 -07:00
sme qcacld-3.0: Fix an improper parameter type casting 2019-08-19 06:19:15 -07:00
wma qcacld-3.0: Fix compilation issue about wma_init_dbr_params 2019-08-19 01:02:25 -07:00