diff options
| author | Dmitry Antipov <[email protected]> | 2025-08-13 13:52:36 +0000 |
|---|---|---|
| committer | Johannes Berg <[email protected]> | 2025-08-26 11:45:09 +0000 |
| commit | 26e84445f02ce6b2fe5f3e0e28ff7add77f35e08 (patch) | |
| tree | 923639243605578568db70b405ac82272ebf2720 /net/wireless/scan.c | |
| parent | wifi: rt2x00: fix CRC_CCITT dependency (diff) | |
| download | kernel-26e84445f02ce6b2fe5f3e0e28ff7add77f35e08.tar.gz kernel-26e84445f02ce6b2fe5f3e0e28ff7add77f35e08.zip | |
wifi: cfg80211: fix use-after-free in cmp_bss()
Following bss_free() quirk introduced in commit 776b3580178f
("cfg80211: track hidden SSID networks properly"), adjust
cfg80211_update_known_bss() to free the last beacon frame
elements only if they're not shared via the corresponding
'hidden_beacon_bss' pointer.
Reported-by: [email protected]
Closes: https://syzkaller.appspot.com/bug?extid=30754ca335e6fb7e3092
Fixes: 3ab8227d3e7d ("cfg80211: refactor cfg80211_bss_update")
Signed-off-by: Dmitry Antipov <[email protected]>
Link: https://patch.msgid.link/[email protected]
Signed-off-by: Johannes Berg <[email protected]>
Diffstat (limited to 'net/wireless/scan.c')
| -rw-r--r-- | net/wireless/scan.c | 3 |
1 files changed, 2 insertions, 1 deletions
diff --git a/net/wireless/scan.c b/net/wireless/scan.c index a8339ed52404..6c7b7c3828a4 100644 --- a/net/wireless/scan.c +++ b/net/wireless/scan.c @@ -1916,7 +1916,8 @@ cfg80211_update_known_bss(struct cfg80211_registered_device *rdev, */ f = rcu_access_pointer(new->pub.beacon_ies); - kfree_rcu((struct cfg80211_bss_ies *)f, rcu_head); + if (!new->pub.hidden_beacon_bss) + kfree_rcu((struct cfg80211_bss_ies *)f, rcu_head); return false; } |
