diff options
| author | Felix Fietkau <nbd@openwrt.org> | 2013-01-09 16:16:53 +0100 | 
|---|---|---|
| committer | Greg Kroah-Hartman <gregkh@linuxfoundation.org> | 2013-02-03 18:21:37 -0600 | 
| commit | bed37001b6919a386dab95dc42084d755233ea60 (patch) | |
| tree | f7d8ff795358542b80cc58a8835a95bf2526720a /drivers/net | |
| parent | a2e1c3918e77ad6a13b43cb04e3cfe19f55d8cd0 (diff) | |
ath9k: fix double-free bug on beacon generate failure
commit 1adb2e2b5f85023d17eb4f95386a57029df27c88 upstream.
When the next beacon is sent, the ath_buf from the previous run is reused.
If getting a new beacon from mac80211 fails, bf->bf_mpdu is not reset, yet
the skb is freed, leading to a double-free on the next beacon tx attempt,
resulting in a system crash.
Signed-off-by: Felix Fietkau <nbd@openwrt.org>
Signed-off-by: John W. Linville <linville@tuxdriver.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Diffstat (limited to 'drivers/net')
| -rw-r--r-- | drivers/net/wireless/ath/ath9k/beacon.c | 1 | 
1 files changed, 1 insertions, 0 deletions
| diff --git a/drivers/net/wireless/ath/ath9k/beacon.c b/drivers/net/wireless/ath/ath9k/beacon.c index d4d8ceced89b..b109c4708587 100644 --- a/drivers/net/wireless/ath/ath9k/beacon.c +++ b/drivers/net/wireless/ath/ath9k/beacon.c @@ -159,6 +159,7 @@ static struct ath_buf *ath_beacon_generate(struct ieee80211_hw *hw,  				 skb->len, DMA_TO_DEVICE);  		dev_kfree_skb_any(skb);  		bf->bf_buf_addr = 0; +		bf->bf_mpdu = NULL;  	}  	/* Get a new beacon from mac80211 */ | 
