From 70c4ce28b877cbe447a02b6e8ec35a23a38df1a7 Mon Sep 17 00:00:00 2001 From: Srinivas Dasari Date: Mon, 21 Dec 2020 23:03:12 +0530 Subject: [PATCH] qcacmn: Possible buffer overflow while copying rnr info A temporary variable "temp" is declared to use it while sorting the channels based on the weightage/rnr info. This is declared as a pointer to hold the reference of struct rnr_chan_weight but memcpy is done to this without allocating memory. Declare this as a variable instead of pointer to use it as an intermediate variable for sorting. Change-Id: If619f5fa462d5400f0a77e57317ac3c8debb34a5 CRs-Fixed: 2842819 --- umac/scan/core/src/wlan_scan_manager_6ghz.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/umac/scan/core/src/wlan_scan_manager_6ghz.c b/umac/scan/core/src/wlan_scan_manager_6ghz.c index cfd8abe29879..4af36bfb2cb4 100644 --- a/umac/scan/core/src/wlan_scan_manager_6ghz.c +++ b/umac/scan/core/src/wlan_scan_manager_6ghz.c @@ -54,7 +54,7 @@ scm_sort_6ghz_channel_list(struct wlan_objmgr_vdev *vdev, uint8_t i, j = 0, max, tmp_list_count; struct meta_rnr_channel *channel; struct chan_info temp_list[MAX_6GHZ_CHANNEL]; - struct rnr_chan_weight *rnr_chan_info, *temp; + struct rnr_chan_weight *rnr_chan_info, temp; uint32_t weight; struct wlan_objmgr_psoc *psoc;