qcacld-3.0: Fix possible OOB access in ol_rx_reorder_detect_hole

Currently tid is extracted from HTT message and it is used without
check. This may cause possible OOB array read. To address this add
check for valid tid.

Change-Id: Idb03236e05fe43326f9ab46ae8368adc9a92d92a
CRs-Fixed: 2225497
This commit is contained in:
Sravan Kumar Kairam 2018-05-09 16:38:26 +05:30 • committed by nshrivas
commit adbff87a09

View file

@ -457,6 +457,11 @@ static void ol_rx_reorder_detect_hole(struct ol_txrx_peer_t *peer,
{
uint32_t win_sz_mask, next_rel_idx, hole_size;
if (tid >= OL_TXRX_NUM_EXT_TIDS) {
ol_txrx_err("%s: invalid tid, %u\n", __FUNCTION__, tid);
return;
}
if (peer->tids_next_rel_idx[tid] == INVALID_REORDER_INDEX)
return;