From: Ping-Ke Shih <pkshih@realtek.com>
To: <linux-wireless@vger.kernel.org>
Cc: <gary.chang@realtek.com>, <kevin_yang@realtek.com>
Subject: [PATCH rtw-next 3/3] wifi: rtw89: wow: check AOAC report key index
Date: Wed, 23 Sep 2026 15:27:41 +0800 [thread overview]
Message-ID: <20260923072741.54118-4-pkshih@realtek.com> (raw)
In-Reply-To: <20260923072741.54118-1-pkshih@realtek.com>
From: Chih-Kang Chang <gary.chang@realtek.com>
Check the key index reported by firmware before updating the GTK RX IV
information in the AOAC report.
The key index is obtained from the firmware C2H register and is used
to select the GTK RX IV entry. Make sure the reported index is within
the available GTK RX IV entries before processing the report.
Signed-off-by: Chih-Kang Chang <gary.chang@realtek.com>
Signed-off-by: Ping-Ke Shih <pkshih@realtek.com>
---
drivers/net/wireless/realtek/rtw89/wow.c | 3 +++
1 file changed, 3 insertions(+)
diff --git a/drivers/net/wireless/realtek/rtw89/wow.c b/drivers/net/wireless/realtek/rtw89/wow.c
index 0bf34692c7ce..7a2d6904951f 100644
--- a/drivers/net/wireless/realtek/rtw89/wow.c
+++ b/drivers/net/wireless/realtek/rtw89/wow.c
@@ -546,6 +546,9 @@ static int rtw89_wow_get_aoac_rpt_reg(struct rtw89_dev *rtwdev)
aoac_rpt->key_idx =
u32_get_bits(c2h_info.u.c2hreg[0], RTW89_C2HREG_AOAC_RPT_1_W0_KEY_IDX);
key_idx = aoac_rpt->key_idx;
+ if (key_idx >= ARRAY_SIZE(aoac_rpt->gtk_rx_iv))
+ return -EINVAL;
+
aoac_rpt->gtk_rx_iv[key_idx][0] =
u32_get_bits(c2h_info.u.c2hreg[1], RTW89_C2HREG_AOAC_RPT_1_W1_IV_0);
aoac_rpt->gtk_rx_iv[key_idx][1] =
--
2.25.1
prev parent reply other threads:[~2026-09-23 7:28 UTC|newest]
Thread overview: 5+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-23 7:27 [PATCH rtw-next 0/3] wifi: rtw89: add out-of-bound checking and reset map for hw_reconfig flow Ping-Ke Shih
2026-09-23 7:27 ` [PATCH rtw-next 1/3] wifi: rtw89: ser: reset map of associated links when L2 SER Ping-Ke Shih
2026-09-30 2:17 ` Ping-Ke Shih
2026-09-23 7:27 ` [PATCH rtw-next 2/3] wifi: rtw89: wow: check AOAC report C2H event length Ping-Ke Shih
2026-09-23 7:27 ` Ping-Ke Shih [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260923072741.54118-4-pkshih@realtek.com \
--to=pkshih@realtek.com \
--cc=gary.chang@realtek.com \
--cc=kevin_yang@realtek.com \
--cc=linux-wireless@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox