nl80211/cfg80211: fix potential infinite loop
authorColin Ian King <colin.king@canonical.com>
Thu, 29 Oct 2020 22:24:07 +0000 (22:24 +0000)
committerJohannes Berg <johannes.berg@intel.com>
Fri, 6 Nov 2020 09:02:24 +0000 (10:02 +0100)
The for-loop iterates with a u8 loop counter and compares this
with the loop upper limit of request->n_ssids which is an int type.
There is a potential infinite loop if n_ssids is larger than the
u8 loop counter, so fix this by making the loop counter an int.

Addresses-Coverity: ("Infinite loop")
Fixes: c8cb5b854b40 ("nl80211/cfg80211: support 6 GHz scanning")
Signed-off-by: Colin Ian King <colin.king@canonical.com>
Link: https://lore.kernel.org/r/20201029222407.390218-1-colin.king@canonical.com
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
net/wireless/scan.c

index 8d0e49c..3409f37 100644 (file)
@@ -694,7 +694,7 @@ static  void cfg80211_scan_req_add_chan(struct cfg80211_scan_request *request,
 static bool cfg80211_find_ssid_match(struct cfg80211_colocated_ap *ap,
                                     struct cfg80211_scan_request *request)
 {
-       u8 i;
+       int i;
        u32 s_ssid;
 
        for (i = 0; i < request->n_ssids; i++) {