mirror of
https://github.com/BobTheBlinker/android_kernel_motorola_sm6375.git
synced 2026-10-10 06:09:23 -04:00
No description
- C 98.2%
- Assembly 1%
- Makefile 0.3%
- Shell 0.2%
- Python 0.1%
| Filename | Latest commit message | Latest commit date |
|---|---|---|
When handling WMI_ROAM_SCAN_STATS_EVENTID, the number of channels scanned for each roam trigger is fetched from wmi_roam_scan_info TLV (wmi_roam_scan_info->roam_scan_channel_count), The total number of channels for all the roam triggers is fetched from param_buf->num_roam_scan_chan_info. chan_idx is the index used to fetch the current channel info TLV to be read. So if wmi_roam_scan_info->roam_scan_channel_count provided by firmware exceeds the total param_buf->num_roam_scan_chan_info starting from given chan_idx then OOB access of event buffer can happen. To avoid this, validate the sum of the current chan_idx and src_data->roam_scan_channel_count against evt_buf->num_roam_scan_chan_info. Change-Id: Ied94464d1f12690cf8832962b94595c2e00c33f8 CRs-Fixed: 3357714 |
||
| cfg | ||
| dp | ||
| ftm | ||
| global_lmac_if | ||
| hal/wifi3.0 | ||
| hif | ||
| htc | ||
| init_deinit/dispatcher | ||
| iot_sim | ||
| os_if/linux | ||
| qal | ||
| qdf | ||
| scheduler | ||
| spectral | ||
| target_if | ||
| umac | ||
| utils | ||
| wbuff | ||
| wlan_cfg | ||
| wmi | ||
| README.txt | ||
| VERSION.txt | ||
This is CNSS WLAN Host Driver for products starting from iHelium