diff options
| author | Shahar Tzarfati <shahar.tzarfati@intel.com> | 2026-07-15 21:57:05 +0300 |
|---|---|---|
| committer | Miri Korenblit <miriam.rachel.korenblit@intel.com> | 2026-07-16 21:12:17 +0300 |
| commit | a31b0e535fd11219556c7382ee9f63b2438c3769 (patch) | |
| tree | 1991d0e15dc607c41b62d12685bbc50ec6b9d540 /tools/perf/scripts/python/task-analyzer.py | |
| parent | 408d7da38272ce48e2db79b8a9895999f94d7655 (diff) | |
wifi: iwlwifi: fw: validate SMEM response size
The SMEM parsers cast firmware response payloads directly to shared
memory configuration structures. A short response can leave fields
outside the received payload while the driver still dereferences them.
Check the response payload length before reading the base fields in
both parser variants. Require the full legacy extended layout before
reading internal TX FIFO data. Valid responses keep the same parsed
values.
Signed-off-by: Shahar Tzarfati <shahar.tzarfati@intel.com>
Reviewed-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Miri Korenblit <miriam.rachel.korenblit@intel.com>
Link: https://patch.msgid.link/20260715215523.fbdb0016a91d.I5f6c6e04589a24a233559191170ccb43372dee63@changeid
Diffstat (limited to 'tools/perf/scripts/python/task-analyzer.py')
0 files changed, 0 insertions, 0 deletions
