- 21 Jun, 2019 1 commit
-
-
Dong Anyuan authored
Remove Coverity Scan CID 60241 (Passing &eplmn to function emm_proc_attach_accept which uses it as an array. This might corrupt or misinterpret adjacent memory locations.)
-
- 20 Jun, 2019 39 commits
-
-
Dong Anyuan authored
Fix Coverity Scan CID 339954 (Overrunning callee's array of size 16 by passing argument ue_id (which evaluates to 65535) in call to flexran_set_ue_ul_slice_idx.)
-
Dong Anyuan authored
Fix Coverity Scan CID 339964 (Passing &rrc_eNB_mui to function rrc_eNB_process_S1AP_DOWNLINK_NAS which uses it as an array. This might corrupt or misinterpret adjacent memory locations.)
-
Dong Anyuan authored
-
Dong Anyuan authored
Fix Coverity Scan CID 339974 (Overrunning array eutra_bandtable of 48 24-byte elements at element index 48 (byte offset 1152) using index i (which evaluates to 48).)
-
Dong Anyuan authored
-
Dong Anyuan authored
-
Dong Anyuan authored
Fix Coverity Scan CID 340004 (Overrunning array eutra_bandtable of 48 24-byte elements at element index 48 (byte offset 1152) using index i (which evaluates to 48).)
-
Dong Anyuan authored
Fix Coverity Scan CID 340209 (Variable message_p going out of scope leaks the storage it points to.)
-
Dong Anyuan authored
Fix Coverity Scan CID 340211 (Variable message_p going out of scope leaks the storage it points to.)
-
Dong Anyuan authored
-
Dong Anyuan authored
-
Dong Anyuan authored
Fix Coverity Scan CID 340232 (Variable message_p going out of scope leaks the storage it points to.)
-
Dong Anyuan authored
Fix Coverity Scan CID 340235 (Using variable UE_id_mac as an index to array RC.mac[ctxt_pP->module_id]->UE_list.UE_sched_ctrl.)
-
Dong Anyuan authored
-
Dong Anyuan authored
Fix Coverity Scan CID 340243 (Overrunning array of 1 bytes at byte offset 1 by dereferencing pointer ie->value.choice.UESecurityCapabilities.encryptionAlgorithms.buf + 1.)
-
Dong Anyuan authored
-
Dong Anyuan authored
Fix Coverity Scan CID 340247 (Variable pc5s_header going out of scope leaks the storage it points to.)
-
Dong Anyuan authored
Fix Coverity Scan CID 340261 (Variable securityConfigHO going out of scope leaks the storage it points to.)
-
Dong Anyuan authored
Fix Coverity Scan CID 340263 (Using uninitialized value DRB2LCHAN[i] when calling rrc_mac_config_req_eNB.)
-
Dong Anyuan authored
Fix Coverity Scan CID 340268 (Passing freed pointer pdu_mem_pP as an argument to rlc_um_store_pdu_in_dar_buffer.)
-
Dong Anyuan authored
Fix Coverity Scan CID 340277 (Variable gNB_CUSystemInformation going out of scope leaks the storage it points to.)
-
Dong Anyuan authored
Fix Coverity Scan CID 340278 (Variable quantityConfig going out of scope leaks the storage it points to.)
-
Dong Anyuan authored
-
Dong Anyuan authored
-
Dong Anyuan authored
Fix Coverity Scan CID 21666 (Variable measResultListEUTRA2 going out of scope leaks the storage it points to.)
-
Dong Anyuan authored
Fix Coverity Scan CID 21694 (Variable quantityConfig going out of scope leaks the storage it points to.)
-
Dong Anyuan authored
-
Dong Anyuan authored
Fix Coverity Scan CID 21842 (Using uninitialized value data_req. Field data_req.ue_id_type_indicator is uninitialized.)
-
Dong Anyuan authored
Fix Coverity Scan CID 21843 (Using uninitialized value data_req. Field data_req.buffer_occupancy_in_pdus is uninitialized.)
-
Dong Anyuan authored
-
Dong Anyuan authored
Fix Coverity Scan CID 21911 (Using uninitialized value data_req. Field data_req.buffer_occupancy_in_pdus is uninitialized.)
-
Dong Anyuan authored
Fix Coverity Scan CID 21929 (Using uninitialized value newtbl.num_elements when calling hashtable_insert.)
-
Dong Anyuan authored
Fix Coverity Scan CID 21938 (Using uninitialized value status_resp. Field status_resp.head_sdu_creation_time is uninitialized.)
-
Dong Anyuan authored
Fix Coverity Scan CID 60241 (Passing &eplmn to function emm_proc_attach_accept which uses it as an array. This might corrupt or misinterpret adjacent memory locations.)
-
Dong Anyuan authored
Fix Coverity Scan CID 60277 (Calling strncpy with a maximum size argument of 4096 bytes on destination array user_api_id->recv_buffer of size 4096 bytes might leave the destination string unterminated.)
-
Dong Anyuan authored
-
Dong Anyuan authored
-
Dong Anyuan authored
-
Dong Anyuan authored
-