WSL2-Linux-Kernel/net/mac80211
Johannes Berg 2965c4cdf7 wifi: mac80211: fix use-after-free in chanctx code
In ieee80211_vif_use_reserved_context(), when we have an
old context and the new context's replace_state is set to
IEEE80211_CHANCTX_REPLACE_NONE, we free the old context
in ieee80211_vif_use_reserved_reassign(). Therefore, we
cannot check the old_ctx anymore, so we should set it to
NULL after this point.

However, since the new_ctx replace state is clearly not
IEEE80211_CHANCTX_REPLACES_OTHER, we're not going to do
anything else in this function and can just return to
avoid accessing the freed old_ctx.

Cc: stable@vger.kernel.org
Fixes: 5bcae31d9c ("mac80211: implement multi-vif in-place reservations")
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Kalle Valo <kvalo@kernel.org>
Link: https://lore.kernel.org/r/20220601091926.df419d91b165.I17a9b3894ff0b8323ce2afdb153b101124c821e5@changeid
2022-06-01 12:41:41 +03:00
..
Kconfig
Makefile
aead_api.c
aead_api.h
aes_ccm.h
aes_cmac.c
aes_cmac.h
aes_gcm.h
aes_gmac.c
aes_gmac.h
agg-rx.c mac80211: prepare sta handling for MLO support 2022-04-11 16:42:03 +02:00
agg-tx.c mac80211: prepare sta handling for MLO support 2022-04-11 16:42:03 +02:00
airtime.c mac80211: prepare sta handling for MLO support 2022-04-11 16:42:03 +02:00
cfg.c mac80211: refactor freeing the next_beacon 2022-05-17 13:03:34 +02:00
chan.c wifi: mac80211: fix use-after-free in chanctx code 2022-06-01 12:41:41 +03:00
debug.h
debugfs.c mac80211: introduce BSS color collision detection 2022-04-11 15:24:15 +02:00
debugfs.h
debugfs_key.c
debugfs_key.h
debugfs_netdev.c mac80211: use ifmgd->bssid instead of ifmgd->associated->bssid 2022-05-16 09:13:22 +02:00
debugfs_netdev.h
debugfs_sta.c wireless-next patches for v5.19 2022-05-03 17:27:51 -07:00
debugfs_sta.h
driver-ops.c
driver-ops.h
eht.c mac80211: prepare sta handling for MLO support 2022-04-11 16:42:03 +02:00
ethtool.c mac80211: prepare sta handling for MLO support 2022-04-11 16:42:03 +02:00
fils_aead.c
fils_aead.h
he.c mac80211: prepare sta handling for MLO support 2022-04-11 16:42:03 +02:00
ht.c mac80211: prepare sta handling for MLO support 2022-04-11 16:42:03 +02:00
ibss.c mac80211: prepare sta handling for MLO support 2022-04-11 16:42:03 +02:00
ieee80211_i.h mac80211: mlme: track assoc_bss/associated separately 2022-05-16 09:16:20 +02:00
iface.c
key.c mac80211: prepare sta handling for MLO support 2022-04-11 16:42:03 +02:00
key.h
led.c
led.h
main.c mac80211: remove unused argument to ieee80211_sta_connection_lost() 2022-05-16 09:15:04 +02:00
mesh.c
mesh.h
mesh_hwmp.c mac80211: prepare sta handling for MLO support 2022-04-11 16:42:03 +02:00
mesh_pathtbl.c
mesh_plink.c mac80211: prepare sta handling for MLO support 2022-04-11 16:42:03 +02:00
mesh_ps.c
mesh_sync.c
michael.c
michael.h
mlme.c wireless-next patches for v5.19 2022-05-19 13:01:08 -07:00
ocb.c mac80211: prepare sta handling for MLO support 2022-04-11 16:42:03 +02:00
offchannel.c mac80211: use ifmgd->bssid instead of ifmgd->associated->bssid 2022-05-16 09:13:22 +02:00
pm.c
rate.c mac80211: prepare sta handling for MLO support 2022-04-11 16:42:03 +02:00
rate.h
rc80211_minstrel_ht.c mac80211: minstrel_ht: support ieee80211_rate_status 2022-05-16 10:07:58 +02:00
rc80211_minstrel_ht.h mac80211: minstrel_ht: support ieee80211_rate_status 2022-05-16 10:07:58 +02:00
rc80211_minstrel_ht_debugfs.c
rx.c Merge git://git.kernel.org/pub/scm/linux/kernel/git/netdev/net 2022-05-12 16:15:30 -07:00
s1g.c mac80211: prepare sta handling for MLO support 2022-04-11 16:42:03 +02:00
scan.c mac80211: upgrade passive scan to active scan on DFS channels after beacon rx 2022-05-04 22:49:38 +02:00
spectmgmt.c
sta_info.c mac80211: prepare sta handling for MLO support 2022-04-11 16:42:03 +02:00
sta_info.h mac80211: prepare sta handling for MLO support 2022-04-11 16:42:03 +02:00
status.c mac80211: extend current rate control tx status API 2022-05-16 10:05:02 +02:00
tdls.c mac80211: prepare sta handling for MLO support 2022-04-11 16:42:03 +02:00
tkip.c
tkip.h
trace.c
trace.h mac80211: prepare sta handling for MLO support 2022-04-11 16:42:03 +02:00
trace_msg.h
tx.c mac80211: tx: delete a redundant if statement in ieee80211_check_fast_xmit() 2022-05-04 22:49:38 +02:00
util.c mac80211: mlme: move in RSSI reporting code 2022-05-16 09:12:34 +02:00
vht.c mac80211: prepare sta handling for MLO support 2022-04-11 16:42:03 +02:00
wep.c
wep.h
wme.c
wme.h
wpa.c mac80211: unify CCMP/GCMP AAD construction 2022-05-16 09:10:38 +02:00
wpa.h