From: dierk.modrow.opensource@gmail.com
To: iwd@lists.linux.dev
Cc: DEMODDIE <dierk.modrow@sew-eurodrive.de>
Subject: [PATCH] Three bugfixes for iwd SEGVs at receipt of EAPOL M1 msg with legacy roaming and repeated roam scan after ft_auth-/ft_reassoc-timeout occurred:
Date: Wed, 8 Jul 2026 08:16:51 +0200 [thread overview]
Message-ID: <20260708061651.299-1-dierk.modrow.opensource@gmail.com> (raw)
From: DEMODDIE <dierk.modrow@sew-eurodrive.de>
src/eapol.c: next try for a fix of SEGV fault at eapol_rx_packets when using mwifiex / NXP 88W9098 driver
src/station.c: potential bugfix in station_roam_scan_notify to avoid NULL-Ptr access to var hs
src/station.c: next try to fix a SEGV after auth timeout at FT roaming
---
src/eapol.c | 4 ++++
src/station.c | 12 ++++++------
2 files changed, 10 insertions(+), 6 deletions(-)
diff --git a/src/eapol.c b/src/eapol.c
index 372549c6..c2dc4e4c 100644
--- a/src/eapol.c
+++ b/src/eapol.c
@@ -2824,6 +2824,10 @@ void eapol_register(struct eapol_sm *sm)
l_queue_push_head(state_machines, sm);
+ /* workaround against SEGV on fct. eapol_rx_packet by avoiding for two different eapol_frame_watches with different ids, but same eapol_sm ptr */
+ if ((sm->watch_id > 0) && eapol_frame_watch_remove(sm->watch_id)) {
+ l_debug("existing frame_watch for sm=%p with id=%u successfully removed", sm, sm->watch_id);
+ }
sm->watch_id = eapol_frame_watch_add(sm->handshake->ifindex,
rx_handler, sm);
sm->protocol_version = sm->handshake->proto_version;
diff --git a/src/station.c b/src/station.c
index 8fcf8c70..077e510e 100644
--- a/src/station.c
+++ b/src/station.c
@@ -2253,7 +2253,7 @@ static bool station_can_fast_transition(struct station *station,
{
uint16_t mdid;
- if (!hs->mde)
+ if (!hs || !hs->mde)
return false;
if (ie_parse_mobility_domain_from_data(hs->mde, hs->mde[1] + 2,
@@ -2917,7 +2917,7 @@ static bool station_roam_scan_notify(int err, struct l_queue *bss_list,
orig_security = network_get_security(network);
- if (hs->mde)
+ if (hs && hs->mde)
ie_parse_mobility_domain_from_data(hs->mde, hs->mde[1] + 2,
&mdid, NULL, NULL);
@@ -2930,7 +2930,7 @@ static bool station_roam_scan_notify(int err, struct l_queue *bss_list,
if (bss && !station->ap_directed_roaming) {
double cur_bss_rank = bss->rank;
- if (hs->mde && bss->mde_present && l_get_le16(bss->mde) == mdid)
+ if (hs && hs->mde && bss->mde_present && l_get_le16(bss->mde) == mdid)
cur_bss_rank *= RANK_FT_FACTOR;
cur_bss_group_rank = evaluate_bss_group_rank(bss->addr,
@@ -2967,8 +2967,8 @@ static bool station_roam_scan_notify(int err, struct l_queue *bss_list,
goto next;
/* Skip result if it is not part of the ESS */
- if (bss->ssid_len != hs->ssid_len ||
- memcmp(bss->ssid, hs->ssid, hs->ssid_len))
+ if (hs && (bss->ssid_len != hs->ssid_len ||
+ memcmp(bss->ssid, hs->ssid, hs->ssid_len)))
goto next;
if (scan_bss_get_security(bss, &security) < 0)
@@ -2986,7 +2986,7 @@ static bool station_roam_scan_notify(int err, struct l_queue *bss_list,
rank = bss->rank;
- if (hs->mde && bss->mde_present && l_get_le16(bss->mde) == mdid)
+ if (hs && hs->mde && bss->mde_present && l_get_le16(bss->mde) == mdid)
rank *= RANK_FT_FACTOR;
group_rank = evaluate_bss_group_rank(bss->addr, bss->frequency,
--
2.53.0.windows.2
next reply other threads:[~2026-07-08 6:17 UTC|newest]
Thread overview: 3+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-07-08 6:16 dierk.modrow.opensource [this message]
2026-07-08 8:12 ` [PATCH] Three bugfixes for iwd SEGVs at receipt of EAPOL M1 msg with legacy roaming and repeated roam scan after ft_auth-/ft_reassoc-timeout occurred: Paul Menzel
[not found] ` <686f8b3498e645d89bc538456bb847e9@sew-eurodrive.de>
2026-07-08 15:41 ` AW: " Dierk.Modrow
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260708061651.299-1-dierk.modrow.opensource@gmail.com \
--to=dierk.modrow.opensource@gmail.com \
--cc=dierk.modrow@sew-eurodrive.de \
--cc=iwd@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox