[PATCH] wifi: mt76: mt7996: fix uninitialized buf read in mt7996_variant_fem_init()
Lu Huang
huanglu at kylinos.cn
Wed Sep 30 01:54:35 PDT 2026
When the eFuse block covering MT7976C_EFUSE_OFFSET is invalid,
mt7996_mcu_get_eeprom() returns -EINVAL without writing buf, but
mt7996_variant_fem_init() tolerates -EINVAL and keeps running, so
buf[idx] == 0xc reads uninitialized stack memory. A stale 0x0c byte
misclassifies a 0x7976 aDie as 7976C, selects MT7996_FEM_INT and the
wrong default EEPROM, overriding valid calibration data. Only consult
the eFuse byte when the read succeeded; with an invalid eFuse, fall
back to the three explicit aDie version checks.
Fixes: e8cb33ad546a ("wifi: mt76: mt7996: add support for more variants")
Cc: stable at vger.kernel.org
Signed-off-by: Lu Huang <huanglu at kylinos.cn>
---
drivers/net/wireless/mediatek/mt76/mt7996/init.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/net/wireless/mediatek/mt76/mt7996/init.c b/drivers/net/wireless/mediatek/mt76/mt7996/init.c
index fb635a092584..a42a47c0d285 100644
--- a/drivers/net/wireless/mediatek/mt76/mt7996/init.c
+++ b/drivers/net/wireless/mediatek/mt76/mt7996/init.c
@@ -1247,7 +1247,7 @@ static int mt7996_variant_fem_init(struct mt7996_dev *dev)
adie_ver = u32_get_bits(regval, MT_ADIE_VERSION_MASK);
idx = MT7976C_EFUSE_OFFSET % MT7996_EEPROM_BLOCK_SIZE;
is_7976c = adie_ver == 0x8a10 || adie_ver == 0x8b00 ||
- adie_ver == 0x8c10 || buf[idx] == 0xc;
+ adie_ver == 0x8c10 || (!ret && buf[idx] == 0xc);
adie_id = u32_get_bits(regval, MT_ADIE_CHIP_ID_MASK);
if (adie_id == 0x7975 || adie_id == 0x7979 ||
--
2.25.1
More information about the Linux-mediatek
mailing list