]> www.infradead.org Git - users/hch/misc.git/commitdiff
wifi: mac80211: fix invalid drv_sta_pre_rcu_remove calls for non-uploaded sta
authorFelix Fietkau <nbd@nbd.name>
Fri, 24 Mar 2023 12:09:24 +0000 (13:09 +0100)
committerJohannes Berg <johannes.berg@intel.com>
Thu, 30 Mar 2023 09:19:53 +0000 (11:19 +0200)
Avoid potential data corruption issues caused by uninitialized driver
private data structures.

Reported-by: Brian Coverstone <brian@mainsequence.net>
Fixes: 6a9d1b91f34d ("mac80211: add pre-RCU-sync sta removal driver operation")
Signed-off-by: Felix Fietkau <nbd@nbd.name>
Link: https://lore.kernel.org/r/20230324120924.38412-3-nbd@nbd.name
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
net/mac80211/sta_info.c

index 7d68dbc872d7736f5d72eeb1b6f64ddbdf67ca6f..941bda9141faab6883a0e7a715eee47d1e34d806 100644 (file)
@@ -1264,7 +1264,8 @@ static int __must_check __sta_info_destroy_part1(struct sta_info *sta)
        list_del_rcu(&sta->list);
        sta->removed = true;
 
-       drv_sta_pre_rcu_remove(local, sta->sdata, sta);
+       if (sta->uploaded)
+               drv_sta_pre_rcu_remove(local, sta->sdata, sta);
 
        if (sdata->vif.type == NL80211_IFTYPE_AP_VLAN &&
            rcu_access_pointer(sdata->u.vlan.sta) == sta)