From 77ba18197c2f0a292ca4dbeb9f557d0682b3a02e Mon Sep 17 00:00:00 2001 From: Gururaj Pandurangi Date: Fri, 10 Jul 2020 13:05:38 -0700 Subject: [PATCH] qcacld-3.0: Validate bssDescription before using it Validate bssDescription before dereferencing it. Change-Id: I89f8c07ad2e38e59dd2a002ce95cfac88232ccc9 CRs-Fixed: 2729263 --- core/mac/src/pe/lim/lim_assoc_utils.c | 7 +++++-- 1 file changed, 5 insertions(+), 2 deletions(-) diff --git a/core/mac/src/pe/lim/lim_assoc_utils.c b/core/mac/src/pe/lim/lim_assoc_utils.c index f1c31741713f..c015f31b84d9 100644 --- a/core/mac/src/pe/lim/lim_assoc_utils.c +++ b/core/mac/src/pe/lim/lim_assoc_utils.c @@ -1628,8 +1628,7 @@ QDF_STATUS lim_populate_peer_rate_set(struct mac_context *mac, uint8_t aRateIndex = 0; uint8_t bRateIndex = 0; tDot11fIEhe_cap *peer_he_caps; - struct bss_description *bssDescription = - &pe_session->lim_join_req->bssDescription; + struct bss_description *bssDescription; tSchBeaconStruct *pBeaconStruct = NULL; /* copy operational rate set from pe_session */ @@ -1758,6 +1757,10 @@ QDF_STATUS lim_populate_peer_rate_set(struct mac_context *mac, peer_he_caps = he_caps; } else { bssDescription = &pe_session->lim_join_req->bssDescription; + if (!bssDescription) { + pe_err("bssDescription is NULL"); + return QDF_STATUS_E_INVAL; + } pBeaconStruct = qdf_mem_malloc(sizeof(tSchBeaconStruct)); if (!pBeaconStruct) return QDF_STATUS_E_NOMEM;