From: Dan Carpenter <error27@gmail.com>
To: johannes.berg@intel.com
Cc: linux-wireless@vger.kernel.org
Subject: potential null deref in iwlagn_request_scan()?
Date: Thu, 22 Jul 2010 00:16:16 +0200 [thread overview]
Message-ID: <20100721221616.GT17585@bicker> (raw)
Smatch complains about iwlagn_request_scan().
drivers/net/wireless/iwlwifi/iwl-agn-lib.c +1354 iwlagn_request_scan(204)
error: we previously assumed 'vif' could be null.
1351 if (!priv->is_internal_short_scan) {
1352 cmd_len = iwl_fill_probe_req(priv,
1353 (struct ieee80211_mgmt *)scan->data,
1354 vif->addr,
^^^^^^^^^
1355 priv->scan_request->ie,
1356 priv->scan_request->ie_len,
1357 IWL_MAX_SCAN_SIZE - sizeof(*scan));
1358 } else {
1359 /* use bcast addr, will not be transmitted but must be valid */
This was added in 3a0b9aad0a8166e9f "iwlwifi: use virtual interface
address for scan". Prior to that commit the function assumed that vif
could be NULL throughout.
I don't know the code well enough to know what to do about this.
Also the same thing for:
drivers/net/wireless/iwlwifi/iwl3945-base.c +2963 iwl3945_request_scan(158)
error: we previously assumed 'vif' could be null.
2962 if (!priv->is_internal_short_scan) {
2963 scan->tx_cmd.len = cpu_to_le16(
2964 iwl_fill_probe_req(priv,
2965 (struct ieee80211_mgmt *)scan->data,
2966 vif->addr,
^^^^^^^^^
2967 priv->scan_request->ie,
2968 priv->scan_request->ie_len,
2969 IWL_MAX_SCAN_SIZE - sizeof(*scan)));
2970 } else {
This is from the above commit as well.
regards,
dan carpenter
next reply other threads:[~2010-07-21 22:16 UTC|newest]
Thread overview: 4+ messages / expand[flat|nested] mbox.gz Atom feed top
2010-07-21 22:16 Dan Carpenter [this message]
2010-07-22 19:28 ` potential null deref in iwlagn_request_scan()? John W. Linville
2010-07-22 19:28 ` [PATCH] iwlwifi: assume vif is NULL for internal scans and non-NULL otherwise John W. Linville
2010-07-22 19:36 ` Guy, Wey-Yi
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20100721221616.GT17585@bicker \
--to=error27@gmail.com \
--cc=johannes.berg@intel.com \
--cc=linux-wireless@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.