diff options
author | Eyal Shapira <eyal@wizery.com> | 2015-11-19 11:37:31 -0500 |
---|---|---|
committer | Emmanuel Grumbach <emmanuel.grumbach@intel.com> | 2015-12-13 01:22:31 -0500 |
commit | e8b3f7b6e746e5a850d243e1e11d83d2163e16e4 (patch) | |
tree | 7a2f7e435378d1883ea409438419693d6071bff0 /drivers/net/wireless/intel/iwlwifi/mvm/rs.c | |
parent | 355346ba3050f42dc33663d7dd6cba055ba31924 (diff) |
iwlwifi: mvm: rs: fix a potential out of bounds access
Klocwork pointed these out. There is a theoretical possibility
that rate->index might be set to IWL_RATE_INVALID (15).
This could trigger an out of bounds access on ht_vht_rates or
legacy_rates arrays. Fix it by adding some checks.
Signed-off-by: Eyal Shapira <eyalx.shapira@intel.com>
Signed-off-by: Emmanuel Grumbach <emmanuel.grumbach@intel.com>
Diffstat (limited to 'drivers/net/wireless/intel/iwlwifi/mvm/rs.c')
-rw-r--r-- | drivers/net/wireless/intel/iwlwifi/mvm/rs.c | 5 |
1 files changed, 3 insertions, 2 deletions
diff --git a/drivers/net/wireless/intel/iwlwifi/mvm/rs.c b/drivers/net/wireless/intel/iwlwifi/mvm/rs.c index feb775a8223a..31b082edd29e 100644 --- a/drivers/net/wireless/intel/iwlwifi/mvm/rs.c +++ b/drivers/net/wireless/intel/iwlwifi/mvm/rs.c | |||
@@ -552,9 +552,10 @@ static char *rs_pretty_rate(const struct rs_rate *rate) | |||
552 | }; | 552 | }; |
553 | const char *rate_str; | 553 | const char *rate_str; |
554 | 554 | ||
555 | if (is_type_legacy(rate->type)) | 555 | if (is_type_legacy(rate->type) && (rate->index <= IWL_RATE_54M_INDEX)) |
556 | rate_str = legacy_rates[rate->index]; | 556 | rate_str = legacy_rates[rate->index]; |
557 | else if (is_type_ht(rate->type) || is_type_vht(rate->type)) | 557 | else if ((is_type_ht(rate->type) || is_type_vht(rate->type)) && |
558 | (rate->index <= IWL_RATE_MCS_9_INDEX)) | ||
558 | rate_str = ht_vht_rates[rate->index]; | 559 | rate_str = ht_vht_rates[rate->index]; |
559 | else | 560 | else |
560 | rate_str = "BAD_RATE"; | 561 | rate_str = "BAD_RATE"; |