From c5f96e5b4a9d8e5bc29968b9888730caec658096 Mon Sep 17 00:00:00 2001 From: Augustin Cavalier Date: Thu, 16 May 2019 14:56:44 -0400 Subject: [PATCH] net80211: Merge a memory leak fix from FreeBSD. --- .../compat/freebsd_wlan/net80211/ieee80211_crypto.c | 11 ++++++----- 1 file changed, 6 insertions(+), 5 deletions(-) diff --git a/src/libs/compat/freebsd_wlan/net80211/ieee80211_crypto.c b/src/libs/compat/freebsd_wlan/net80211/ieee80211_crypto.c index cc09c4997f..3e24479704 100644 --- a/src/libs/compat/freebsd_wlan/net80211/ieee80211_crypto.c +++ b/src/libs/compat/freebsd_wlan/net80211/ieee80211_crypto.c @@ -662,14 +662,15 @@ ieee80211_crypto_decap(struct ieee80211_node *ni, struct mbuf *m, int hdrlen, k = &ni->ni_ucastkey; /* - * Insure crypto header is contiguous for all decap work. + * Insure crypto header is contiguous and long enough for all + * decap work. */ cip = k->wk_cipher; - if (m->m_len < hdrlen + cip->ic_header && - (m = m_pullup(m, hdrlen + cip->ic_header)) == NULL) { + if (m->m_len < hdrlen + cip->ic_header) { IEEE80211_NOTE_MAC(vap, IEEE80211_MSG_CRYPTO, wh->i_addr2, - "unable to pullup %s header", cip->ic_name); - vap->iv_stats.is_rx_wepfail++; /* XXX */ + "frame is too short (%d < %u) for crypto decap", + cip->ic_name, m->m_len, hdrlen + cip->ic_header); + vap->iv_stats.is_rx_tooshort++; *key = NULL; return (0); }