diff options
author | Holger Hans Peter Freyther <zecke@selfish.org> | 2010-05-15 23:52:21 +0800 |
---|---|---|
committer | Holger Hans Peter Freyther <zecke@selfish.org> | 2010-05-15 23:55:28 +0800 |
commit | 45bb8bfc1a14676bd6c599eff7980bc3f141f99e (patch) | |
tree | 5b91b1c92790c06a39cbad5f88089e2864630c61 /openbsc/src/gsm_04_08.c | |
parent | 57900f00088e99731ad0d22cb1701eaa22cc25f0 (diff) |
gsm48: Add size checks to the paging response mi parsing.
We go from no size checks to some content checking. We should
refactor the whole classmark2 + mi parsing that is used throughout
the code into one place with proper size checking. This is the
start and requires a new libosmocore as well.
Diffstat (limited to 'openbsc/src/gsm_04_08.c')
-rw-r--r-- | openbsc/src/gsm_04_08.c | 5 |
1 files changed, 4 insertions, 1 deletions
diff --git a/openbsc/src/gsm_04_08.c b/openbsc/src/gsm_04_08.c index 17457736a..c98643883 100644 --- a/openbsc/src/gsm_04_08.c +++ b/openbsc/src/gsm_04_08.c @@ -779,13 +779,16 @@ static int gsm48_rx_rr_pag_resp(struct msgb *msg) { struct gsm_bts *bts = msg->lchan->ts->trx->bts; struct gsm48_hdr *gh = msgb_l3(msg); + struct gsm48_pag_resp *resp; u_int8_t *classmark2_lv = gh->data + 1; u_int8_t mi_type; char mi_string[GSM48_MI_SIZE]; struct gsm_subscriber *subscr = NULL; int rc = 0; - gsm48_paging_extract_mi(msg, mi_string, &mi_type); + resp = (struct gsm48_pag_resp *) &gh->data[0]; + gsm48_paging_extract_mi(resp, msgb_l3len(msg) - sizeof(*gh), + mi_string, &mi_type); DEBUGP(DRR, "PAGING RESPONSE: mi_type=0x%02x MI(%s)\n", mi_type, mi_string); |