wifi: iwlwifi: mld: fix read in wake packet notification handler

In iwl_mld_handle_wake_pkt_notif(), expected_size was initialized from
notif->wake_packet_length before the IWL_FW_CHECK that validates the
payload covers sizeof(*notif).

Move the assignment of expected_size to after the size check so that
notif->wake_packet_length is only accessed once the payload length has
been validated.

Signed-off-by: Shahar Tzarfati <shahar.tzarfati@intel.com>
Signed-off-by: Miri Korenblit <miriam.rachel.korenblit@intel.com>
Link: https://patch.msgid.link/20260715220243.94c526d2c66e.I065a19a9dcc7f45a7457667c0f625fcd2c7bf6b6@changeid
This commit is contained in:
Shahar Tzarfati 2026-07-15 22:04:26 +03:00 committed by Miri Korenblit
parent 51c45bb2c8
commit c5aeb11489

View File

@ -705,7 +705,7 @@ iwl_mld_handle_wake_pkt_notif(struct iwl_mld *mld,
{
const struct iwl_wowlan_wake_pkt_notif *notif = (void *)pkt->data;
u32 actual_size, len = iwl_rx_packet_payload_len(pkt);
u32 expected_size = le32_to_cpu(notif->wake_packet_length);
u32 expected_size;
if (IWL_FW_CHECK(mld, len < sizeof(*notif),
"Invalid WoWLAN wake packet notification (expected size=%zu got=%u)\n",
@ -718,6 +718,7 @@ iwl_mld_handle_wake_pkt_notif(struct iwl_mld *mld,
wowlan_status->wakeup_reasons))
return true;
expected_size = le32_to_cpu(notif->wake_packet_length);
actual_size = len - offsetof(struct iwl_wowlan_wake_pkt_notif,
wake_packet);