mirror of
https://github.com/BobTheBlinker/android_kernel_motorola_sm6375.git
synced 2026-10-11 15:11:48 -04:00
qcacld-3.0: Fix possible OOB access in ol_rx_reorder_detect_hole
Currently tid is extracted from HTT message and it is used without check. This may cause possible OOB array read. To address this add check for valid tid. Change-Id: Idb03236e05fe43326f9ab46ae8368adc9a92d92a CRs-Fixed: 2225497
This commit is contained in:
parent
24e5b21555
commit
adbff87a09
1 changed files with 5 additions and 0 deletions
|
|
@ -457,6 +457,11 @@ static void ol_rx_reorder_detect_hole(struct ol_txrx_peer_t *peer,
|
|||
{
|
||||
uint32_t win_sz_mask, next_rel_idx, hole_size;
|
||||
|
||||
if (tid >= OL_TXRX_NUM_EXT_TIDS) {
|
||||
ol_txrx_err("%s: invalid tid, %u\n", __FUNCTION__, tid);
|
||||
return;
|
||||
}
|
||||
|
||||
if (peer->tids_next_rel_idx[tid] == INVALID_REORDER_INDEX)
|
||||
return;
|
||||
|
||||
|
|
|
|||
Loading…
Reference in a new issue