Skip to content

Commit

Permalink
wifi: ath12k: fix possible out-of-bound write in ath12k_wmi_ext_hal_r…
Browse files Browse the repository at this point in the history
…eg_caps()

[ Upstream commit b302dce ]

reg_cap.phy_id is extracted from WMI event and could be an unexpected value
in case some errors happen. As a result out-of-bound write may occur to
soc->hal_reg_cap. Fix it by validating reg_cap.phy_id before using it.

This is found during code review.

Compile tested only.

Signed-off-by: Baochen Qiang <quic_bqiang@quicinc.com>
Acked-by: Jeff Johnson <quic_jjohnson@quicinc.com>
Signed-off-by: Kalle Valo <quic_kvalo@quicinc.com>
Link: https://lore.kernel.org/r/20230830020716.5420-1-quic_bqiang@quicinc.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
  • Loading branch information
Baochen Qiang authored and gregkh committed Nov 28, 2023
1 parent 0b8e7c1 commit dfe13ea
Showing 1 changed file with 6 additions and 0 deletions.
6 changes: 6 additions & 0 deletions drivers/net/wireless/ath/ath12k/wmi.c
Original file line number Diff line number Diff line change
Expand Up @@ -3799,6 +3799,12 @@ static int ath12k_wmi_ext_hal_reg_caps(struct ath12k_base *soc,
ath12k_warn(soc, "failed to extract reg cap %d\n", i);
return ret;
}

if (reg_cap.phy_id >= MAX_RADIOS) {
ath12k_warn(soc, "unexpected phy id %u\n", reg_cap.phy_id);
return -EINVAL;
}

soc->hal_reg_cap[reg_cap.phy_id] = reg_cap;
}
return 0;
Expand Down

0 comments on commit dfe13ea

Please sign in to comment.