Commit 450c271d authored by Lorenzo Bianconi's avatar Lorenzo Bianconi Committed by Johannes Berg

mac80211: protect ieee80211_assign_beacon with next_beacon check

Even if it is not a real issue since ieee80211_set_after_csa_beacon()
or ieee80211_set_after_color_change_beacon() are run only when csa or bcc
is active, move next_beacon check before running ieee80211_assign_beacon
routine.
Signed-off-by: default avatarLorenzo Bianconi <lorenzo@kernel.org>
Link: https://lore.kernel.org/r/041764ed7e9781bcee66c33b41f1365aa4205932.1649327683.git.lorenzo@kernel.orgSigned-off-by: default avatarJohannes Berg <johannes.berg@intel.com>
parent 92bbf95d
...@@ -3306,13 +3306,14 @@ static int ieee80211_set_after_csa_beacon(struct ieee80211_sub_if_data *sdata, ...@@ -3306,13 +3306,14 @@ static int ieee80211_set_after_csa_beacon(struct ieee80211_sub_if_data *sdata,
switch (sdata->vif.type) { switch (sdata->vif.type) {
case NL80211_IFTYPE_AP: case NL80211_IFTYPE_AP:
if (!sdata->u.ap.next_beacon)
return -EINVAL;
err = ieee80211_assign_beacon(sdata, sdata->u.ap.next_beacon, err = ieee80211_assign_beacon(sdata, sdata->u.ap.next_beacon,
NULL, NULL); NULL, NULL);
if (sdata->u.ap.next_beacon) { kfree(sdata->u.ap.next_beacon->mbssid_ies);
kfree(sdata->u.ap.next_beacon->mbssid_ies); kfree(sdata->u.ap.next_beacon);
kfree(sdata->u.ap.next_beacon); sdata->u.ap.next_beacon = NULL;
sdata->u.ap.next_beacon = NULL;
}
if (err < 0) if (err < 0)
return err; return err;
...@@ -4314,13 +4315,14 @@ ieee80211_set_after_color_change_beacon(struct ieee80211_sub_if_data *sdata, ...@@ -4314,13 +4315,14 @@ ieee80211_set_after_color_change_beacon(struct ieee80211_sub_if_data *sdata,
case NL80211_IFTYPE_AP: { case NL80211_IFTYPE_AP: {
int ret; int ret;
if (!sdata->u.ap.next_beacon)
return -EINVAL;
ret = ieee80211_assign_beacon(sdata, sdata->u.ap.next_beacon, ret = ieee80211_assign_beacon(sdata, sdata->u.ap.next_beacon,
NULL, NULL); NULL, NULL);
if (sdata->u.ap.next_beacon) { kfree(sdata->u.ap.next_beacon->mbssid_ies);
kfree(sdata->u.ap.next_beacon->mbssid_ies); kfree(sdata->u.ap.next_beacon);
kfree(sdata->u.ap.next_beacon); sdata->u.ap.next_beacon = NULL;
sdata->u.ap.next_beacon = NULL;
}
if (ret < 0) if (ret < 0)
return ret; return ret;
......
Markdown is supported
0%
or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment