[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Message-ID: <ccf67349-0bb6-4944-8571-e6707a206eaf@RTEXMBS04.realtek.com.tw>
Date: Fri, 16 May 2025 09:01:49 +0800
From: Ping-Ke Shih <pkshih@...ltek.com>
To: Alexey Kodanev <aleksei.kodanev@...l-sw.com>,
<linux-wireless@...r.kernel.org>
CC: <netdev@...r.kernel.org>, Ping-Ke Shih <pkshih@...ltek.com>,
Kalle Valo
<kvalo@...nel.org>,
Alexey Kodanev <aleksei.kodanev@...l-sw.com>
Subject: Re: [PATCH v2] wifi: rtw88: fix the 'para' buffer size to avoid reading out of bounds
Alexey Kodanev <aleksei.kodanev@...l-sw.com> wrote:
> Set the size to 6 instead of 2, since 'para' array is passed to
> 'rtw_fw_bt_wifi_control(rtwdev, para[0], ¶[1])', which reads
> 5 bytes:
>
> void rtw_fw_bt_wifi_control(struct rtw_dev *rtwdev, u8 op_code, u8 *data)
> {
> ...
> SET_BT_WIFI_CONTROL_DATA1(h2c_pkt, *data);
> SET_BT_WIFI_CONTROL_DATA2(h2c_pkt, *(data + 1));
> ...
> SET_BT_WIFI_CONTROL_DATA5(h2c_pkt, *(data + 4));
>
> Detected using the static analysis tool - Svace.
> Fixes: 4136214f7c46 ("rtw88: add BT co-existence support")
> Signed-off-by: Alexey Kodanev <aleksei.kodanev@...l-sw.com>
1 patch(es) applied to rtw-next branch of rtw.git, thanks.
4c2c372de2e1 wifi: rtw88: fix the 'para' buffer size to avoid reading out of bounds
---
https://github.com/pkshih/rtw.git
Powered by blists - more mailing lists