From 164aaa90de1e66784f81644cac40134d39e5a0d0 Mon Sep 17 00:00:00 2001 From: VIJAY RAJ Date: Thu, 26 Aug 2021 17:30:08 +0530 Subject: [PATCH] qcacld-3.0: Fix null pointer dereference in csr_update_pmk_cache_ft() In csr_update_pmk_cache_ft(), the value of the argument pmk_cache could be received as NULL. pmk_cache is deferenced without validation. Validate pmk_cache before dereferencing. Change-Id: I255ce55d07a112c2aa742535c54b71fadea3e7e7 CRs-Fixed: 3023221 --- core/sme/src/csr/csr_api_roam.c | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/core/sme/src/csr/csr_api_roam.c b/core/sme/src/csr/csr_api_roam.c index 5b2f5bb4eecb..12bd90877dd6 100644 --- a/core/sme/src/csr/csr_api_roam.c +++ b/core/sme/src/csr/csr_api_roam.c @@ -14125,7 +14125,8 @@ void csr_update_pmk_cache_ft(struct mac_context *mac, uint32_t vdev_id, (scan_res->BssDescriptor.mdie[1] << 8)); sme_debug("Scan_res MDID:0x%x copied to PMKSA", pmksa.mdid.mobility_domain); - qdf_copy_macaddr(&pmksa.bssid, &pmk_cache->BSSID); + if (pmk_cache) + qdf_copy_macaddr(&pmksa.bssid, &pmk_cache->BSSID); status = wlan_crypto_update_pmk_cache_ft(vdev, &pmksa); if (QDF_IS_STATUS_ERROR(status))