From d1372d6e6a71c9ddac28845c1e1bee922ff01bf5 Mon Sep 17 00:00:00 2001 From: Sandeep Puligilla Date: Fri, 30 Sep 2022 00:44:09 -0700 Subject: [PATCH] qcacld-3.0: Incorrect MCS index is passed Fix the potential out of bound read of the supported MCS rate array. Change-Id: I172dcac9d1ce79b16e4cd2a4ee321d9e93102866 CRs-Fixed: 3304227 --- core/hdd/src/wlan_hdd_hostapd.c | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/core/hdd/src/wlan_hdd_hostapd.c b/core/hdd/src/wlan_hdd_hostapd.c index 9025e939a06c..afa99fb8bed5 100644 --- a/core/hdd/src/wlan_hdd_hostapd.c +++ b/core/hdd/src/wlan_hdd_hostapd.c @@ -1,5 +1,6 @@ /* * Copyright (c) 2012-2021 The Linux Foundation. All rights reserved. + * Copyright (c) 2022 Qualcomm Innovation Center, Inc. All rights reserved. * * Permission to use, copy, modify, and/or distribute this software for * any purpose with or without fee is hereby granted, provided that the @@ -1347,6 +1348,10 @@ static int calcuate_max_phy_rate(int mode, int nss, int ch_width, if (mode == SIR_SME_PHY_MODE_HT) { /* check for HT Mode */ maxidx = ht_mcs_idx; + if (maxidx > 7) { + hdd_err("ht_mcs_idx %d is incorrect", ht_mcs_idx); + return maxrate; + } if (nss == 1) { supported_mcs_rate = supported_mcs_rate_nss1; } else if (nss == 2) {