gsm0408_rcv_cc: guard against NULL subscriber
Check conn->subscr against NULL. gsm0408_rcv_cc() dereferences many conn members without checking presence: the bts and lchan members may be expected to be NULL in the ongoing MSC split and 3G developments. But the conn->subscr is initially NULL, so an MS sending a CC message before something like a LU or CM Service Request will result in a segfault. Prevent that. Note: the upcoming VLR will be more restrictive on what messages are processed, this is a "backport" to the situation on current master. Change-Id: If067db7cc0dd3210d9eb1da15be6b637795a3ecf
This commit is contained in:
parent
49692af2d3
commit
33913cd612
|
@ -3605,6 +3605,11 @@ static int gsm0408_rcv_cc(struct gsm_subscriber_connection *conn, struct msgb *m
|
|||
return -EINVAL;
|
||||
}
|
||||
|
||||
if (!conn->subscr) {
|
||||
LOGP(DCC, LOGL_ERROR, "Invalid conn, no subscriber\n");
|
||||
return -EINVAL;
|
||||
}
|
||||
|
||||
/* Find transaction */
|
||||
trans = trans_find_by_id(conn, GSM48_PDISC_CC, transaction_id);
|
||||
|
||||
|
|
Loading…
Reference in New Issue