The driver fills the mcs set array in hdd_update_tgt_ht_cap for all rf chains and does not have a upper boundary check to cfg->num_rf_chains, which could lead to out of bound write a valid value to a memory which not allocated to mcs set Fix is to have a check to cfg->num_rf_chains Change-Id: Ibeb5e783e2369ebee1bbf3fc724d06736c174c69 CRs-Fixed: 2221902 |
||
---|---|---|
.. | ||
inc | ||
src |