From 66b5db4552c007b9d8dcdf4d8f6bdd36adfa937d Mon Sep 17 00:00:00 2001 From: sandhu Date: Thu, 15 Sep 2022 12:21:25 -0700 Subject: [PATCH] qcacld-3.0: check staId index bound into timer array Check whether staId is not out of bound while accessing the timer array. Change-Id: I347c314a324934d4a62808551b1552aa4a76a5d7 CRs-Fixed: 3290301 --- core/mac/src/pe/lim/lim_timer_utils.c | 11 ++++++++--- 1 file changed, 8 insertions(+), 3 deletions(-) diff --git a/core/mac/src/pe/lim/lim_timer_utils.c b/core/mac/src/pe/lim/lim_timer_utils.c index a43ba3293280..2e3892e5293c 100644 --- a/core/mac/src/pe/lim/lim_timer_utils.c +++ b/core/mac/src/pe/lim/lim_timer_utils.c @@ -751,11 +751,16 @@ lim_deactivate_and_change_per_sta_id_timer(struct mac_context *mac, uint32_t tim switch (timerId) { case eLIM_CNF_WAIT_TIMER: - if (tx_timer_deactivate - (&mac->lim.lim_timers.gpLimCnfWaitTimer[staId]) - != TX_SUCCESS) { + if (staId >= (mac->lim.maxStation + 1)) { + pe_err("Invalid staId = %d ", staId); + return; + } + + if (tx_timer_deactivate(&mac->lim.lim_timers.gpLimCnfWaitTimer[staId]) + != TX_SUCCESS) { pe_err("unable to deactivate CNF wait timer"); } + /* Change timer to reactivate it in future */ val = mac->mlme_cfg->sta.wait_cnf_timeout; val = SYS_MS_TO_TICKS(val);