All of lore.kernel.org
 help / color / mirror / Atom feed
* [PATCH] mac80211: fix tx select key null pointer crash with hostapd
@ 2010-01-23 18:27 Kalle Valo
  2010-01-23 18:33 ` Kalle Valo
                   ` (2 more replies)
  0 siblings, 3 replies; 4+ messages in thread
From: Kalle Valo @ 2010-01-23 18:27 UTC (permalink / raw)
  To: linux-wireless; +Cc: Pavel Roskin, Johannes Berg

Pavel Roskin reported a crash in ieee80211_tx_h_select_key():

http://marc.info/?l=linux-wireless&m=126419655108528&w=2

This is a regression from patch "mac80211: move control.hw_key assignment".
Fix it as suggested by Johannes, adding an else statement to make sure
that tx->key is not accessed when it's null.

Compile-tested only.

Reported-by: Pavel Roskin <proski@gnu.org>
Cc: Johannes Berg <johannes@sipsolutions.net>
Signed-off-by: Kalle Valo <kalle.valo@iki.fi>
---
 net/mac80211/tx.c |    7 ++++---
 1 files changed, 4 insertions(+), 3 deletions(-)

diff --git a/net/mac80211/tx.c b/net/mac80211/tx.c
index fcfa988..d017b35 100644
--- a/net/mac80211/tx.c
+++ b/net/mac80211/tx.c
@@ -547,9 +547,10 @@ ieee80211_tx_h_select_key(struct ieee80211_tx_data *tx)
 			    !ieee80211_use_mfp(hdr->frame_control, tx->sta,
 					       tx->skb))
 				tx->key = NULL;
-			skip_hw = (tx->key->conf.flags &
-						IEEE80211_KEY_FLAG_SW_MGMT) &&
-				   ieee80211_is_mgmt(hdr->frame_control);
+			else
+				skip_hw = (tx->key->conf.flags &
+					   IEEE80211_KEY_FLAG_SW_MGMT) &&
+					ieee80211_is_mgmt(hdr->frame_control);
 			break;
 		case ALG_AES_CMAC:
 			if (!ieee80211_is_mgmt(hdr->frame_control))


^ permalink raw reply related	[flat|nested] 4+ messages in thread

* Re: [PATCH] mac80211: fix tx select key null pointer crash with hostapd
  2010-01-23 18:27 [PATCH] mac80211: fix tx select key null pointer crash with hostapd Kalle Valo
@ 2010-01-23 18:33 ` Kalle Valo
  2010-01-23 19:01 ` Bob Copeland
  2010-01-23 21:39 ` Markus Baier
  2 siblings, 0 replies; 4+ messages in thread
From: Kalle Valo @ 2010-01-23 18:33 UTC (permalink / raw)
  To: Paul.Hampson; +Cc: Pavel Roskin, Johannes Berg, linux-wireless

Kalle Valo <kalle.valo@iki.fi> writes:

> Pavel Roskin reported a crash in ieee80211_tx_h_select_key():
>
> http://marc.info/?l=linux-wireless&m=126419655108528&w=2
>
> This is a regression from patch "mac80211: move control.hw_key assignment".
> Fix it as suggested by Johannes, adding an else statement to make sure
> that tx->key is not accessed when it's null.

Paul, if you have the time, please try this patch. It should solve
your issue.

In case you are not subcribed to the list, the patch is here:

http://marc.info/?l=linux-wireless&m=126427124317427&w=2

-- 
Kalle Valo

^ permalink raw reply	[flat|nested] 4+ messages in thread

* Re: [PATCH] mac80211: fix tx select key null pointer crash with hostapd
  2010-01-23 18:27 [PATCH] mac80211: fix tx select key null pointer crash with hostapd Kalle Valo
  2010-01-23 18:33 ` Kalle Valo
@ 2010-01-23 19:01 ` Bob Copeland
  2010-01-23 21:39 ` Markus Baier
  2 siblings, 0 replies; 4+ messages in thread
From: Bob Copeland @ 2010-01-23 19:01 UTC (permalink / raw)
  To: Kalle Valo; +Cc: linux-wireless, Pavel Roskin, Johannes Berg

On Sat, Jan 23, 2010 at 1:27 PM, Kalle Valo <kalle.valo@iki.fi> wrote:
> Pavel Roskin reported a crash in ieee80211_tx_h_select_key():
>
> http://marc.info/?l=linux-wireless&m=126419655108528&w=2
>
> This is a regression from patch "mac80211: move control.hw_key assignment".
> Fix it as suggested by Johannes, adding an else statement to make sure
> that tx->key is not accessed when it's null.
>
> Compile-tested only.
>
> Reported-by: Pavel Roskin <proski@gnu.org>
> Cc: Johannes Berg <johannes@sipsolutions.net>
> Signed-off-by: Kalle Valo <kalle.valo@iki.fi>

Tested-by: Bob Copeland <me@bobcopeland.com>

Thanks!

-- 
Bob Copeland %% www.bobcopeland.com

^ permalink raw reply	[flat|nested] 4+ messages in thread

* Re: [PATCH] mac80211: fix tx select key null pointer crash with hostapd
  2010-01-23 18:27 [PATCH] mac80211: fix tx select key null pointer crash with hostapd Kalle Valo
  2010-01-23 18:33 ` Kalle Valo
  2010-01-23 19:01 ` Bob Copeland
@ 2010-01-23 21:39 ` Markus Baier
  2 siblings, 0 replies; 4+ messages in thread
From: Markus Baier @ 2010-01-23 21:39 UTC (permalink / raw)
  To: linux-wireless

Thanks Pavel, Johannes, Kalle

With this patch the kernel works fine again.


^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2010-01-23 21:40 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2010-01-23 18:27 [PATCH] mac80211: fix tx select key null pointer crash with hostapd Kalle Valo
2010-01-23 18:33 ` Kalle Valo
2010-01-23 19:01 ` Bob Copeland
2010-01-23 21:39 ` Markus Baier

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.