From fc2b7d2152e345a1399e48b00eeb0af2924c6c25 Mon Sep 17 00:00:00 2001 From: Lincoln Tran Date: Tue, 16 Mar 2021 17:36:39 -0700 Subject: [PATCH] qcacmn: Catch potential OOB for 6G channel list Ensure any access to the master channel list does not go out of bounds Change-Id: I96487a752d1510136f1ecbf92da42eb7b991522b CRs-fixed: 2900945 --- umac/regulatory/core/src/reg_build_chan_list.c | 17 +++++++++++++++-- 1 file changed, 15 insertions(+), 2 deletions(-) diff --git a/umac/regulatory/core/src/reg_build_chan_list.c b/umac/regulatory/core/src/reg_build_chan_list.c index 995023ce4d52..d71603ffa3a2 100644 --- a/umac/regulatory/core/src/reg_build_chan_list.c +++ b/umac/regulatory/core/src/reg_build_chan_list.c @@ -1023,8 +1023,16 @@ static void reg_append_mas_chan_list_for_6g(struct wlan_regulatory_pdev_priv_obj *pdev_priv_obj) { - struct regulatory_channel *master_chan_list_6g_client = - pdev_priv_obj->mas_chan_list_6g_client + struct regulatory_channel *master_chan_list_6g_client; + + if (pdev_priv_obj->reg_cur_6g_ap_pwr_type >= REG_CURRENT_MAX_AP_TYPE || + pdev_priv_obj->reg_cur_6g_client_mobility_type >= + REG_MAX_CLIENT_TYPE) { + reg_debug("invalid 6G AP or client power type"); + return; + } + + master_chan_list_6g_client = pdev_priv_obj->mas_chan_list_6g_client [pdev_priv_obj->reg_cur_6g_ap_pwr_type] [pdev_priv_obj->reg_cur_6g_client_mobility_type]; @@ -1040,6 +1048,11 @@ reg_append_mas_chan_list_for_6g(struct wlan_regulatory_pdev_priv_obj { enum reg_6g_ap_type ap_pwr_type = pdev_priv_obj->reg_cur_6g_ap_pwr_type; + if (ap_pwr_type >= REG_CURRENT_MAX_AP_TYPE) { + reg_debug("invalid 6G AP power type"); + return; + } + qdf_mem_copy(&pdev_priv_obj->mas_chan_list[MIN_6GHZ_CHANNEL], pdev_priv_obj->mas_chan_list_6g_ap[ap_pwr_type], NUM_6GHZ_CHANNELS * sizeof(struct regulatory_channel));