All of lore.kernel.org
 help / color / mirror / Atom feed
* [PATCHv3] mac80211: fix NULL pointer dereference in ieee80211_compatible_rates
@ 2008-05-19 13:41 Helmut Schaa
  2008-05-19 14:09 ` Johannes Berg
  0 siblings, 1 reply; 2+ messages in thread
From: Helmut Schaa @ 2008-05-19 13:41 UTC (permalink / raw)
  To: John Linville; +Cc: Johannes Berg, Larry Finger, linux-wireless

Fix a possible NULL pointer dereference in ieee80211_compatible_rates 
introduced in the patch "mac80211: fix association with some APs". If no bss
is available just use all supported rates in the association request.

Signed-off-by: Helmut Schaa <hschaa@suse.de>
---

diff --git a/net/mac80211/mlme.c b/net/mac80211/mlme.c
index 76ad4ed..277bbda 100644
--- a/net/mac80211/mlme.c
+++ b/net/mac80211/mlme.c
@@ -722,6 +722,10 @@ static void ieee80211_send_assoc(struct net_device *dev,
 		if (bss->wmm_ie)
 			wmm = 1;
 		ieee80211_rx_bss_put(dev, bss);
+		rates_len = ieee80211_compatible_rates(bss, sband, &rates);
+	} else {
+		rates = ~0;
+		rates_len = sband->n_bitrates;
 	}
 
 	mgmt = (struct ieee80211_mgmt *) skb_put(skb, 24);
@@ -755,7 +759,6 @@ static void ieee80211_send_assoc(struct net_device *dev,
 	/* all supported rates should be added here but some APs
 	 * (e.g. D-Link DAP 1353 in b-only mode) don't like that
 	 * Therefore only add rates the AP supports */
-	rates_len = ieee80211_compatible_rates(bss, sband, &rates);
 	supp_rates_len = rates_len;
 	if (supp_rates_len > 8)
 		supp_rates_len = 8;

^ permalink raw reply related	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2008-05-19 14:11 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2008-05-19 13:41 [PATCHv3] mac80211: fix NULL pointer dereference in ieee80211_compatible_rates Helmut Schaa
2008-05-19 14:09 ` Johannes Berg

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.