]> git.ipfire.org Git - thirdparty/kernel/stable.git/commitdiff
rtw88: don't treat NULL pointer as an array
authorBrian Norris <briannorris@chromium.org>
Fri, 21 Aug 2020 21:17:16 +0000 (14:17 -0700)
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Thu, 29 Oct 2020 09:07:32 +0000 (10:07 +0100)
[ Upstream commit 22b726cbdd09d9891ede8aa122a950d2d0ae5e09 ]

I'm not a standards expert, but this really looks to be undefined
behavior, when chip->dig_cck may be NULL. (And, we're trying to do a
NULL check a few lines down, because some chip variants will use NULL.)

Fixes: fc637a860a82 ("rtw88: 8723d: Set IG register for CCK rate")
Signed-off-by: Brian Norris <briannorris@chromium.org>
Acked-by: Yan-Hsuan Chuang <yhchuang@realtek.com>
Signed-off-by: Kalle Valo <kvalo@codeaurora.org>
Link: https://lore.kernel.org/r/20200821211716.1631556-1-briannorris@chromium.org
Signed-off-by: Sasha Levin <sashal@kernel.org>
drivers/net/wireless/realtek/rtw88/phy.c

index 8d93f315974699dc79d2c4c6dc65f1f51db887bf..9687b376d221b0298945cceb656f85bfa7144a40 100644 (file)
@@ -147,12 +147,13 @@ void rtw_phy_dig_write(struct rtw_dev *rtwdev, u8 igi)
 {
        struct rtw_chip_info *chip = rtwdev->chip;
        struct rtw_hal *hal = &rtwdev->hal;
-       const struct rtw_hw_reg *dig_cck = &chip->dig_cck[0];
        u32 addr, mask;
        u8 path;
 
-       if (dig_cck)
+       if (chip->dig_cck) {
+               const struct rtw_hw_reg *dig_cck = &chip->dig_cck[0];
                rtw_write32_mask(rtwdev, dig_cck->addr, dig_cck->mask, igi >> 1);
+       }
 
        for (path = 0; path < hal->rf_path_num; path++) {
                addr = chip->dig[path].addr;