]> git.ipfire.org Git - thirdparty/kernel/linux.git/commitdiff
wifi: iwlwifi: fix pointer arithmetic in iwl_add_mcc_to_tas_block_list
authorEmmanuel Grumbach <emmanuel.grumbach@intel.com>
Wed, 15 Jul 2026 18:57:06 +0000 (21:57 +0300)
committerMiri Korenblit <miriam.rachel.korenblit@intel.com>
Thu, 16 Jul 2026 18:12:18 +0000 (21:12 +0300)
The expression list[*size++] increments the pointer 'size'
rather than the u8 value it points to (operator precedence: ++
binds to the pointer before the dereference). As a result the
block-list entry is written at the correct index but *size is
never incremented, so the caller's count stays at zero and
subsequent calls overwrite slot 0 every time.

Change to list[(*size)++] so that the value pointed to by size
is incremented after use as the array index.

Fixes: 5f4656610edb ("wifi: iwlwifi: extend TAS_CONFIG cmd support for v5")
Assisted-by: GitHubCopilot:gpt-5.3-codex
Signed-off-by: Emmanuel Grumbach <emmanuel.grumbach@intel.com>
Signed-off-by: Miri Korenblit <miriam.rachel.korenblit@intel.com>
Link: https://patch.msgid.link/20260715215523.d2cd92242582.Ife4140a4e27be2a1cd9f886c5a9b376ce182a019@changeid
drivers/net/wireless/intel/iwlwifi/fw/regulatory.c

index 8d9ff36e30f5e3631c445c788177938c4333024d..1d6d38ee55b4996ca981ae7a28e8d874a9b19d8d 100644 (file)
@@ -389,7 +389,7 @@ bool iwl_add_mcc_to_tas_block_list(u16 *list, u8 *size, u16 mcc)
        if (*size >= IWL_WTAS_BLACK_LIST_MAX)
                return false;
 
-       list[*size++] = mcc;
+       list[(*size)++] = mcc;
        return true;
 }
 IWL_EXPORT_SYMBOL(iwl_add_mcc_to_tas_block_list);