mirror of
https://github.com/BobTheBlinker/android_kernel_motorola_sm6375.git
synced 2026-10-08 12:58:12 -04:00
qcacld-3.0: fix code defects for RRM frame processing
Directly dereferencing pointer beacon_xmit_ind before null-checking, which may result in null pointer issue. Meanwhile, measurement_idx should be checked to avoid out-of-bounds read. Fix is to check before dereferencing it. CRs-Fixed: 2751550 Change-Id: I5241b3b16fcd9a04da121fd938b27d4070ea4e06
This commit is contained in:
parent
014e2991c8
commit
499e2ccc29
1 changed files with 11 additions and 3 deletions
|
|
@ -921,9 +921,7 @@ rrm_process_beacon_report_xmit(struct mac_context *mac_ctx,
|
|||
tSirMacRadioMeasureReport *report = NULL;
|
||||
tSirMacBeaconReport *beacon_report;
|
||||
struct bss_description *bss_desc;
|
||||
tpRRMReq curr_req =
|
||||
mac_ctx->rrm.rrmPEContext.
|
||||
pCurrentReq[beacon_xmit_ind->measurement_idx];
|
||||
tpRRMReq curr_req;
|
||||
struct pe_session *session_entry;
|
||||
uint8_t session_id, counter;
|
||||
uint8_t i, j;
|
||||
|
|
@ -941,6 +939,16 @@ rrm_process_beacon_report_xmit(struct mac_context *mac_ctx,
|
|||
return QDF_STATUS_E_FAILURE;
|
||||
}
|
||||
|
||||
if (beacon_xmit_ind->measurement_idx >=
|
||||
QDF_ARRAY_SIZE(mac_ctx->rrm.rrmPEContext.pCurrentReq)) {
|
||||
pe_err("Received measurement_idx is out of range: %u - %lu",
|
||||
beacon_xmit_ind->measurement_idx,
|
||||
QDF_ARRAY_SIZE(mac_ctx->rrm.rrmPEContext.pCurrentReq));
|
||||
return QDF_STATUS_E_FAILURE;
|
||||
}
|
||||
|
||||
curr_req = mac_ctx->rrm.rrmPEContext.
|
||||
pCurrentReq[beacon_xmit_ind->measurement_idx];
|
||||
if (!curr_req) {
|
||||
pe_err("Received report xmit while there is no request pending in PE");
|
||||
status = QDF_STATUS_E_FAILURE;
|
||||
|
|
|
|||
Loading…
Reference in a new issue