ath10k: avoid possible memory access violation
authorK.T.VIJAYAKUMAAR <vijay.bvb@samsung.com>
Mon, 3 Sep 2018 17:07:44 +0000 (20:07 +0300)
committerKalle Valo <kvalo@codeaurora.org>
Thu, 6 Sep 2018 16:04:10 +0000 (19:04 +0300)
array "ctl_power_table" access index "pream" is initialized with -1 and
is raised as a static analysis tool issue.
[drivers\net\wireless\ath\ath10k\wmi.c:4719] ->
[drivers\net\wireless\ath\ath10k\wmi.c:4730]: (error) Array index -1 is
out of bounds.

Since the "pream" index for accessing ctl_power_table array is initialized
with -1, there is a chance of memory access violation for the cases below.
1) wmi_pdev_tpc_final_table_event change frequency is between 2483 and 5180
2) pream_idx is out of the enumeration ranges of wmi_tpc_pream_2ghz,
wmi_tpc_pream_5ghz

Signed-off-by: K.T.VIJAYAKUMAAR <vijay.bvb@samsung.com>
[kvalo@codeaurora.org: clean up the warning message]
Signed-off-by: Kalle Valo <kvalo@codeaurora.org>
drivers/net/wireless/ath/ath10k/wmi.c

index 212005cd06466571eb287a5dc89af89c7c1d9c30..43daa4e57bc17ff5b9836461167a121455b3a4f8 100644 (file)
@@ -4780,6 +4780,13 @@ ath10k_wmi_tpc_final_get_rate(struct ath10k *ar,
                }
        }
 
+       if (pream == -1) {
+               ath10k_warn(ar, "unknown wmi tpc final index and frequency: %u, %u\n",
+                           pream_idx, __le32_to_cpu(ev->chan_freq));
+               tpc = 0;
+               goto out;
+       }
+
        if (pream == 4)
                tpc = min_t(u8, ev->rates_array[rate_idx],
                            ev->max_reg_allow_pow[ch]);