From c4de71cec539f3d28fa9a6b2a0cf6a0345b3d8b9 Mon Sep 17 00:00:00 2001 From: Jouni Malinen Date: Sun, 23 Nov 2014 20:36:17 +0200 Subject: [PATCH] EAP-FAST: Make PAC file A_ID parser easier to analyze Some static analyzers seem to have issues with "pos + len > end" validation (CID 62875), so convert this to "len > end - pos" to make it more obvious that len is validated against its bounds. Signed-off-by: Jouni Malinen --- src/eap_peer/eap_fast_pac.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/src/eap_peer/eap_fast_pac.c b/src/eap_peer/eap_fast_pac.c index 377080f83..32da82ce8 100644 --- a/src/eap_peer/eap_fast_pac.c +++ b/src/eap_peer/eap_fast_pac.c @@ -714,7 +714,7 @@ static void eap_fast_pac_get_a_id(struct eap_fast_pac *pac) pos += 2; len = WPA_GET_BE16(pos); pos += 2; - if (pos + len > end) + if (len > (unsigned int) (end - pos)) break; if (type == PAC_TYPE_A_ID) {