In wma_roam_synch_event_handler, if vdev_id is out of bounds, code is redirected to cleanup, where iface is dereferenced to set the value of roam_synch_in_progress. This will result in a NULL pointer dereference because iface hasn't yet been set. Since this function does not have logic to set iface->roam_synch_in_progress to true then it does not need "cleanup" logic to undo that. So, remove the cleanup logic. Change-Id: I8ffa0b9186c3595444cb188bbf00624b519e3894 CRs-Fixed: 2427334 |
||
---|---|---|
.. | ||
bmi | ||
cds | ||
dp | ||
hdd | ||
mac | ||
pld | ||
sap | ||
sme | ||
wma |