mirror of
https://github.com/torvalds/linux.git
synced 2026-10-10 04:18:03 +02:00
wifi: ath11k: validate regulatory capability phy_id
ath11k_wmi_tlv_ext_hal_reg_caps() copies firmware regulatory capability records into soc->hal_reg_cap[] using reg_cap.phy_id as the destination index. The loop count is bounded by num_phy, but the phy_id embedded in each record is not checked against the fixed MAX_RADIOS-sized destination array. Reject firmware records whose phy_id does not fit soc->hal_reg_cap[] before copying the parsed capability. Signed-off-by: Pengpeng Hou <pengpeng@iscas.ac.cn> Reviewed-by: Rameshkumar Sundaram <rameshkumar.sundaram@oss.qualcomm.com> Reviewed-by: Baochen Qiang <baochen.qiang@oss.qualcomm.com> Link: https://patch.msgid.link/20260704011040.26233-1-pengpeng@iscas.ac.cn Signed-off-by: Jeff Johnson <jeff.johnson@oss.qualcomm.com>
This commit is contained in:
parent
f78210dd4b
commit
f8729a40eb
|
|
@ -4858,6 +4858,12 @@ static int ath11k_wmi_tlv_ext_hal_reg_caps(struct ath11k_base *soc,
|
|||
return ret;
|
||||
}
|
||||
|
||||
if (reg_cap.phy_id >= ARRAY_SIZE(soc->hal_reg_cap)) {
|
||||
ath11k_warn(soc, "invalid reg cap phy_id %u\n",
|
||||
reg_cap.phy_id);
|
||||
return -EINVAL;
|
||||
}
|
||||
|
||||
memcpy(&soc->hal_reg_cap[reg_cap.phy_id],
|
||||
®_cap, sizeof(reg_cap));
|
||||
}
|
||||
|
|
|
|||
Loading…
Reference in New Issue
Block a user