[PATCH wireless-next 0/4] wifi: mm81x: firmware and host table parsing fixes

Linmao Li <[email protected]>
Newsgroups org.kernel.vger.linux-wireless,org.kernel.vger.linux-kernel
Message-ID <[email protected]>
Four fixes to the firmware paths of the mm81x driver, found by reading
fw.c.  I have no MM81x hardware, so all of them were established from
the code and none was tested on a device.

Patches 1 and 2 are error handling: a scratch buffer that is only freed
on the success path, and a failed segment download whose -EIO is
overwritten by the boot address write that follows it, so an
incompletely downloaded image is reported as loaded.

Patches 3 and 4 bound two TLV walks that currently only require a TLV
header to start inside the region being walked, and that read structures
larger than the header without checking the declared length.  Patch 4 is
the one that does not need a corrupt file: firmware reporting a TLV
shorter than the structure the driver casts it to is enough to read past
the allocation.

Patch 2 depends on the out_free label added by patch 1.

Linmao Li (4):
  wifi: mm81x: free the firmware scratch buffer on parse failures
  wifi: mm81x: do not discard a failed firmware segment write
  wifi: mm81x: bound the .fw_info TLV walk
  wifi: mm81x: bound the extended host table walk

 drivers/net/wireless/morsemicro/mm81x/fw.c | 80 +++++++++++++++-------
 1 file changed, 54 insertions(+), 26 deletions(-)

-- 
2.25.1
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.