From 59e699aa03107e35b56bbbd8d9b9d73bdacacc34 Mon Sep 17 00:00:00 2001 From: Yeshwanth Sriram Guntuka Date: Wed, 8 Jul 2020 09:49:41 +0530 Subject: [PATCH] qcacld-3.0: Fix possible NULL hdd context dereference On dp_aggregation sysfs store or show, wiphy is fetched from hdd context without validation. This could result in possible NULL hdd context dereference. Fix is to validate the hdd context before dereference to get wiphy. Change-Id: I0d01f64e95c9aa3f09ccc940a64d5a25148c302e CRs-Fixed: 2726433 --- core/hdd/src/wlan_hdd_sysfs_dp_aggregation.c | 20 ++++++++++---------- 1 file changed, 10 insertions(+), 10 deletions(-) diff --git a/core/hdd/src/wlan_hdd_sysfs_dp_aggregation.c b/core/hdd/src/wlan_hdd_sysfs_dp_aggregation.c index e291807a07b9..9eae2be9c5ec 100644 --- a/core/hdd/src/wlan_hdd_sysfs_dp_aggregation.c +++ b/core/hdd/src/wlan_hdd_sysfs_dp_aggregation.c @@ -47,12 +47,6 @@ static ssize_t __hdd_sysfs_dp_aggregation_show(struct hdd_context *hdd_ctx, struct kobj_attribute *attr, char *buf) { - int ret; - - ret = wlan_hdd_validate_context(hdd_ctx); - if (ret != 0) - return ret; - if (!wlan_hdd_validate_modules_state(hdd_ctx)) return -EINVAL; @@ -69,6 +63,11 @@ static ssize_t hdd_sysfs_dp_aggregation_show(struct kobject *kobj, struct osif_psoc_sync *psoc_sync; struct hdd_context *hdd_ctx = cds_get_context(QDF_MODULE_ID_HDD); ssize_t errno_size; + int ret; + + ret = wlan_hdd_validate_context(hdd_ctx); + if (ret != 0) + return ret; errno_size = osif_psoc_sync_op_start(wiphy_dev(hdd_ctx->wiphy), &psoc_sync); @@ -93,10 +92,6 @@ __hdd_sysfs_dp_aggregation_store(struct hdd_context *hdd_ctx, int ret; ol_txrx_soc_handle dp_soc = cds_get_context(QDF_MODULE_ID_SOC); - ret = wlan_hdd_validate_context(hdd_ctx); - if (ret != 0) - return ret; - if (!wlan_hdd_validate_modules_state(hdd_ctx) || !dp_soc) return -EINVAL; @@ -131,6 +126,11 @@ hdd_sysfs_dp_aggregation_store(struct kobject *kobj, struct osif_psoc_sync *psoc_sync; struct hdd_context *hdd_ctx = cds_get_context(QDF_MODULE_ID_HDD); ssize_t errno_size; + int ret; + + ret = wlan_hdd_validate_context(hdd_ctx); + if (ret != 0) + return ret; errno_size = osif_psoc_sync_op_start(wiphy_dev(hdd_ctx->wiphy), &psoc_sync);