diff --git a/sys/dev/netif/ath/ath_hal/ar5212/ar5212_keycache.c b/sys/dev/netif/ath/ath_hal/ar5212/ar5212_keycache.c @@ -86,7 +86,21 @@ if (keyType == AR_KEYTABLE_TYPE_TKIP && IS_MIC_ENABLED(ah)) { uint16_t micentry = entry+64; /* MIC goes at slot+64 */ - HALASSERT(micentry < AH_PRIVATE(ah)->ah_caps.halKeyCacheSize); + /* + * Runtime bounds check: HALASSERT is a no-op on GENERIC + * (AH_ASSERT is LINT64-only), so a TKIP slot installed at a + * high index while MIC was disabled (bypassing the + * entry+64= AH_PRIVATE(ah)->ah_caps.halKeyCacheSize) { + HALDEBUG(ah, HAL_DEBUG_ANY, + "%s: MIC entry %u out of range\n", + __func__, micentry); + return AH_FALSE; + } OS_REG_WRITE(ah, AR_KEYTABLE_KEY0(micentry), 0); OS_REG_WRITE(ah, AR_KEYTABLE_KEY1(micentry), 0); OS_REG_WRITE(ah, AR_KEYTABLE_KEY2(micentry), 0);