[PATCH 3.2 42/79] radiotap: fix bitmap-end-finding buffer overrun

2014-02-12 Thread Ben Hutchings
3.2.55-rc1 review patch. If anyone has any objections, please let me know. -- From: Johannes Berg commit bd02cd2549cfcdfc57cb5ce57ffc3feb94f70575 upstream. Evan Huus found (by fuzzing in wireshark) that the radiotap iterator code can access beyond the length of the buffer if

[PATCH 3.2 42/79] radiotap: fix bitmap-end-finding buffer overrun

2014-02-12 Thread Ben Hutchings
3.2.55-rc1 review patch. If anyone has any objections, please let me know. -- From: Johannes Berg johannes.b...@intel.com commit bd02cd2549cfcdfc57cb5ce57ffc3feb94f70575 upstream. Evan Huus found (by fuzzing in wireshark) that the radiotap iterator code can access beyond the