]> git.ipfire.org Git - thirdparty/kernel/stable.git/commitdiff
mt76: fix possible out-of-bound access in mt7615_fill_txs/mt7603_fill_txs
authorLorenzo Bianconi <lorenzo@kernel.org>
Wed, 6 Nov 2019 23:01:58 +0000 (01:01 +0200)
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Tue, 31 Dec 2019 15:45:43 +0000 (16:45 +0100)
[ Upstream commit e8b970c8e367e85fab9b8ac4f36080e5d653c38e ]

Fix possible out-of-bound access of status rates array in
mt7615_fill_txs/mt7603_fill_txs routines

Fixes: c5211e997eca ("mt76: mt7603: rework and fix tx status reporting")
Fixes: 4af81f02b49c ("mt76: mt7615: sync with mt7603 rate control changes")
Signed-off-by: Lorenzo Bianconi <lorenzo@kernel.org>
Signed-off-by: Felix Fietkau <nbd@nbd.name>
Signed-off-by: Sasha Levin <sashal@kernel.org>
drivers/net/wireless/mediatek/mt76/mt7603/mac.c
drivers/net/wireless/mediatek/mt76/mt7615/mac.c

index c328192307c48d89db91495172c79d7abb9d04bb..ff3f3d98b62527d7caf786dd026fa30f96b55b42 100644 (file)
@@ -1032,8 +1032,10 @@ mt7603_fill_txs(struct mt7603_dev *dev, struct mt7603_sta *sta,
                if (idx && (cur_rate->idx != info->status.rates[i].idx ||
                            cur_rate->flags != info->status.rates[i].flags)) {
                        i++;
-                       if (i == ARRAY_SIZE(info->status.rates))
+                       if (i == ARRAY_SIZE(info->status.rates)) {
+                               i--;
                                break;
+                       }
 
                        info->status.rates[i] = *cur_rate;
                        info->status.rates[i].count = 0;
index e07ce2c100133b1e4a659c59d5bd410409b4b657..111e38ff954a27694947a3171cc0ac8bdf9045c6 100644 (file)
@@ -914,8 +914,10 @@ static bool mt7615_fill_txs(struct mt7615_dev *dev, struct mt7615_sta *sta,
                if (idx && (cur_rate->idx != info->status.rates[i].idx ||
                            cur_rate->flags != info->status.rates[i].flags)) {
                        i++;
-                       if (i == ARRAY_SIZE(info->status.rates))
+                       if (i == ARRAY_SIZE(info->status.rates)) {
+                               i--;
                                break;
+                       }
 
                        info->status.rates[i] = *cur_rate;
                        info->status.rates[i].count = 0;