diff options
author | Felix Fietkau <nbd@openwrt.org> | 2013-01-09 16:16:53 +0100 |
---|---|---|
committer | Ben Hutchings <ben@decadent.org.uk> | 2013-02-06 04:33:43 +0000 |
commit | a282707dd03b6cbf4acc77e2d0e9a4ea1ccb2d04 (patch) | |
tree | 2b034233563059fb2f6480561207edd83dbd1445 | |
parent | 8e75bb199071d3c86cd04ecb98b35e5b65d39594 (diff) | |
download | lwn-a282707dd03b6cbf4acc77e2d0e9a4ea1ccb2d04.tar.gz lwn-a282707dd03b6cbf4acc77e2d0e9a4ea1ccb2d04.zip |
ath9k: fix double-free bug on beacon generate failure
commit 1adb2e2b5f85023d17eb4f95386a57029df27c88 upstream.
When the next beacon is sent, the ath_buf from the previous run is reused.
If getting a new beacon from mac80211 fails, bf->bf_mpdu is not reset, yet
the skb is freed, leading to a double-free on the next beacon tx attempt,
resulting in a system crash.
Signed-off-by: Felix Fietkau <nbd@openwrt.org>
Signed-off-by: John W. Linville <linville@tuxdriver.com>
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
-rw-r--r-- | drivers/net/wireless/ath/ath9k/beacon.c | 1 |
1 files changed, 1 insertions, 0 deletions
diff --git a/drivers/net/wireless/ath/ath9k/beacon.c b/drivers/net/wireless/ath/ath9k/beacon.c index a13cabb95435..2bbc83e1cfff 100644 --- a/drivers/net/wireless/ath/ath9k/beacon.c +++ b/drivers/net/wireless/ath/ath9k/beacon.c @@ -155,6 +155,7 @@ static struct ath_buf *ath_beacon_generate(struct ieee80211_hw *hw, skb->len, DMA_TO_DEVICE); dev_kfree_skb_any(skb); bf->bf_buf_addr = 0; + bf->bf_mpdu = NULL; } /* Get a new beacon from mac80211 */ |