From mboxrd@z Thu Jan 1 00:00:00 1970 From: Dan Carpenter Date: Tue, 11 May 2010 11:29:38 +0200 Subject: [ath9k-devel] [patch 2/9] ath9k: range checking issues in htc_hst.c In-Reply-To: <19432.61450.971181.675920@gargle.gargle.HOWL> References: <20100508162201.GN27064@bicker> <19432.61450.971181.675920@gargle.gargle.HOWL> Message-ID: <20100511092938.GY27064@bicker> List-Id: MIME-Version: 1.0 Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit To: ath9k-devel@lists.ath9k.org On Tue, May 11, 2010 at 11:20:02AM +0530, Sujith.Manoharan at atheros.com wrote: > Dan Carpenter wrote: > > The original code had ENDPOINT_MAX and HST_ENDPOINT_MAX switched. > > > > Also the first loop was off by one, it started past the end of the array > > and went down to 1 instead of going down to 0. The test at the end of > > the loop to see if we exited via a break wasn't right because > > "tmp_endpoint" is always non-null here. > > This is a very good catch and fixes a stack corruption issue. > Do you mind if I work upon this patch and send out an updated fix ? > > Sujith Sorry, I meant to do that yesterday but I was out of it. Yes. Please send the updated fix. regards, dan carpenter