Currently in htt_t2h_msg_handler_fast, msg_len, which is in number of bytes, is directly compared with pdev->rx_mpdu_range_offset_words, which is in number of words. Thus their comparison becomes invalid. In htt_t2h_msg_handler, in addition to similar issue as above, the checks for message offset validations do not consider integer overflows occurring. In htt_t2h_msg_handler_fast, the check condition involving pdev_rx_mpdu_range_offset_words were corrected to work with bytes, and in htt_t2h_msg_handler checks for integer overflow were also added. Change-Id: I9ec7d30cc24d288ddcabd3bb30674a2ca21f2251 CRs-Fixed: 2248069 |
||
---|---|---|
.. | ||
bmi | ||
cds | ||
dp | ||
hdd | ||
mac | ||
pld | ||
sap | ||
sme | ||
wma |