mirror of
https://github.com/torvalds/linux.git
synced 2026-07-27 17:47:41 +02:00
wifi: iwlwifi: mvm: validate sta_id in BA window status notif
BA_WINDOW_STATUS_NOTIFICATION_ID extracts a 5-bit sta_id from the firmware notification and uses it to index fw_id_to_mac_id[] without bounds checking. Validate sta_id before array access to prevent out-of-bounds indexing. Assisted-by: GitHubCopilot:gpt-5.3-codex Signed-off-by: Emmanuel Grumbach <emmanuel.grumbach@intel.com> Link: https://patch.msgid.link/20260714141909.2e97f337f3cb.Ic3f0f404082ccdea13809a3c0b70e0f5417e1037@changeid Signed-off-by: Miri Korenblit <miriam.rachel.korenblit@intel.com>
This commit is contained in:
parent
3ed8d1705d
commit
6aa77efaea
|
|
@ -1227,6 +1227,11 @@ void iwl_mvm_window_status_notif(struct iwl_mvm *mvm,
|
|||
/* get the station */
|
||||
sta_id = (ratid & BA_WINDOW_STATUS_STA_ID_MSK)
|
||||
>> BA_WINDOW_STATUS_STA_ID_POS;
|
||||
if (IWL_FW_CHECK(mvm,
|
||||
sta_id >= mvm->fw->ucode_capa.num_stations,
|
||||
"Invalid sta id (%d) in BA window status notification\n",
|
||||
sta_id))
|
||||
continue;
|
||||
sta = rcu_dereference(mvm->fw_id_to_mac_id[sta_id]);
|
||||
if (IS_ERR_OR_NULL(sta))
|
||||
continue;
|
||||
|
|
|
|||
Loading…
Reference in New Issue
Block a user