public inbox for linux-kernel@vger.kernel.org
 help / color / mirror / Atom feed
From: Sasha Levin <sashal@kernel.org>
To: stable@vger.kernel.org, linux-kernel@vger.kernel.org
Cc: Yu Zhao <yuzhao@google.com>,
	Johannes Berg <johannes.berg@intel.com>,
	Sasha Levin <sashal@kernel.org>
Subject: [PATCH AUTOSEL 4.14 43/61] cfg80211: fix use-after-free in reg_process_hint()
Date: Tue, 16 Oct 2018 00:13:45 -0400	[thread overview]
Message-ID: <20181016041403.135678-43-sashal@kernel.org> (raw)
In-Reply-To: <20181016041403.135678-1-sashal@kernel.org>

From: Yu Zhao <yuzhao@google.com>

[ Upstream commit 1db58529454742f67ebd96e3588315e880b72837 ]

reg_process_hint_country_ie() can free regulatory_request and return
REG_REQ_ALREADY_SET. We shouldn't use regulatory_request after it's
called. KASAN error was observed when this happens.

BUG: KASAN: use-after-free in reg_process_hint+0x839/0x8aa [cfg80211]
Read of size 4 at addr ffff8800c430d434 by task kworker/1:3/89
<snipped>
Workqueue: events reg_todo [cfg80211]
Call Trace:
 dump_stack+0xc1/0x10c
 ? _atomic_dec_and_lock+0x1ad/0x1ad
 ? _raw_spin_lock_irqsave+0xa0/0xd2
 print_address_description+0x86/0x26f
 ? reg_process_hint+0x839/0x8aa [cfg80211]
 kasan_report+0x241/0x29b
 reg_process_hint+0x839/0x8aa [cfg80211]
 reg_todo+0x204/0x5b9 [cfg80211]
 process_one_work+0x55f/0x8d0
 ? worker_detach_from_pool+0x1b5/0x1b5
 ? _raw_spin_unlock_irq+0x65/0xdd
 ? _raw_spin_unlock_irqrestore+0xf3/0xf3
 worker_thread+0x5dd/0x841
 ? kthread_parkme+0x1d/0x1d
 kthread+0x270/0x285
 ? pr_cont_work+0xe3/0xe3
 ? rcu_read_unlock_sched_notrace+0xca/0xca
 ret_from_fork+0x22/0x40

Allocated by task 2718:
 set_track+0x63/0xfa
 __kmalloc+0x119/0x1ac
 regulatory_hint_country_ie+0x38/0x329 [cfg80211]
 __cfg80211_connect_result+0x854/0xadd [cfg80211]
 cfg80211_rx_assoc_resp+0x3bc/0x4f0 [cfg80211]
smsc95xx v1.0.6
 ieee80211_sta_rx_queued_mgmt+0x1803/0x7ed5 [mac80211]
 ieee80211_iface_work+0x411/0x696 [mac80211]
 process_one_work+0x55f/0x8d0
 worker_thread+0x5dd/0x841
 kthread+0x270/0x285
 ret_from_fork+0x22/0x40

Freed by task 89:
 set_track+0x63/0xfa
 kasan_slab_free+0x6a/0x87
 kfree+0xdc/0x470
 reg_process_hint+0x31e/0x8aa [cfg80211]
 reg_todo+0x204/0x5b9 [cfg80211]
 process_one_work+0x55f/0x8d0
 worker_thread+0x5dd/0x841
 kthread+0x270/0x285
 ret_from_fork+0x22/0x40
<snipped>

Signed-off-by: Yu Zhao <yuzhao@google.com>
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 net/wireless/reg.c | 7 ++++---
 1 file changed, 4 insertions(+), 3 deletions(-)

diff --git a/net/wireless/reg.c b/net/wireless/reg.c
index 6f032c7b8732..bd91de416035 100644
--- a/net/wireless/reg.c
+++ b/net/wireless/reg.c
@@ -2170,11 +2170,12 @@ static void reg_process_hint(struct regulatory_request *reg_request)
 {
 	struct wiphy *wiphy = NULL;
 	enum reg_request_treatment treatment;
+	enum nl80211_reg_initiator initiator = reg_request->initiator;
 
 	if (reg_request->wiphy_idx != WIPHY_IDX_INVALID)
 		wiphy = wiphy_idx_to_wiphy(reg_request->wiphy_idx);
 
-	switch (reg_request->initiator) {
+	switch (initiator) {
 	case NL80211_REGDOM_SET_BY_CORE:
 		treatment = reg_process_hint_core(reg_request);
 		break;
@@ -2192,7 +2193,7 @@ static void reg_process_hint(struct regulatory_request *reg_request)
 		treatment = reg_process_hint_country_ie(wiphy, reg_request);
 		break;
 	default:
-		WARN(1, "invalid initiator %d\n", reg_request->initiator);
+		WARN(1, "invalid initiator %d\n", initiator);
 		goto out_free;
 	}
 
@@ -2207,7 +2208,7 @@ static void reg_process_hint(struct regulatory_request *reg_request)
 	 */
 	if (treatment == REG_REQ_ALREADY_SET && wiphy &&
 	    wiphy->regulatory_flags & REGULATORY_STRICT_REG) {
-		wiphy_update_regulatory(wiphy, reg_request->initiator);
+		wiphy_update_regulatory(wiphy, initiator);
 		wiphy_all_share_dfs_chan_state(wiphy);
 		reg_check_channels();
 	}
-- 
2.17.1


  parent reply	other threads:[~2018-10-16  4:24 UTC|newest]

Thread overview: 61+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2018-10-16  4:13 [PATCH AUTOSEL 4.14 01/61] xfrm: Validate address prefix lengths in the xfrm selector Sasha Levin
2018-10-16  4:13 ` [PATCH AUTOSEL 4.14 02/61] xfrm6: call kfree_skb when skb is toobig Sasha Levin
2018-10-16  4:13 ` [PATCH AUTOSEL 4.14 03/61] xfrm: reset transport header back to network header after all input transforms ahave been applied Sasha Levin
2018-10-16  4:13 ` [PATCH AUTOSEL 4.14 04/61] xfrm: reset crypto_done when iterating over multiple input xfrms Sasha Levin
2018-10-16  4:13 ` [PATCH AUTOSEL 4.14 05/61] mac80211: Always report TX status Sasha Levin
2018-10-16  4:13 ` [PATCH AUTOSEL 4.14 06/61] cfg80211: reg: Init wiphy_idx in regulatory_hint_core() Sasha Levin
2018-10-16  4:13 ` [PATCH AUTOSEL 4.14 07/61] mac80211: fix pending queue hang due to TX_DROP Sasha Levin
2018-10-16  4:13 ` [PATCH AUTOSEL 4.14 08/61] cfg80211: Address some corner cases in scan result channel updating Sasha Levin
2018-10-16  4:13 ` [PATCH AUTOSEL 4.14 09/61] mac80211: TDLS: fix skb queue/priority assignment Sasha Levin
2018-10-16  4:13 ` [PATCH AUTOSEL 4.14 10/61] mac80211: fix TX status reporting for ieee80211s Sasha Levin
2018-10-16  4:13 ` [PATCH AUTOSEL 4.14 11/61] xfrm: Fix NULL pointer dereference when skb_dst_force clears the dst_entry Sasha Levin
2018-10-16  4:13 ` [PATCH AUTOSEL 4.14 12/61] ARM: 8799/1: mm: fix pci_ioremap_io() offset check Sasha Levin
2018-10-16  4:13 ` [PATCH AUTOSEL 4.14 13/61] xfrm: validate template mode Sasha Levin
2018-10-16  4:13 ` [PATCH AUTOSEL 4.14 14/61] netfilter: bridge: Don't sabotage nf_hook calls from an l3mdev Sasha Levin
2018-10-16  4:13 ` [PATCH AUTOSEL 4.14 15/61] arm64: hugetlb: Fix handling of young ptes Sasha Levin
2018-10-16  4:13 ` [PATCH AUTOSEL 4.14 16/61] ARM: dts: BCM63xx: Fix incorrect interrupt specifiers Sasha Levin
2018-10-16  4:13 ` [PATCH AUTOSEL 4.14 17/61] net: macb: Clean 64b dma addresses if they are not detected Sasha Levin
2018-10-16  4:13 ` [PATCH AUTOSEL 4.14 18/61] net: hns: fix for unmapping problem when SMMU is on Sasha Levin
2018-10-16  4:13 ` [PATCH AUTOSEL 4.14 19/61] soc: fsl: qbman: qman: avoid allocating from non existing gen_pool Sasha Levin
2018-10-16  4:13 ` [PATCH AUTOSEL 4.14 20/61] soc: fsl: qe: Fix copy/paste bug in ucc_get_tdm_sync_shift() Sasha Levin
2018-10-16  4:13 ` [PATCH AUTOSEL 4.14 21/61] nl80211: Fix possible Spectre-v1 for NL80211_TXRATE_HT Sasha Levin
2018-10-16  4:13 ` [PATCH AUTOSEL 4.14 22/61] mac80211_hwsim: do not omit multicast announce of first added radio Sasha Levin
2018-10-16  4:13 ` [PATCH AUTOSEL 4.14 23/61] Bluetooth: SMP: fix crash in unpairing Sasha Levin
2018-10-16  4:13 ` [PATCH AUTOSEL 4.14 24/61] pxa168fb: prepare the clock Sasha Levin
2018-10-16  4:13 ` [PATCH AUTOSEL 4.14 25/61] qed: Avoid implicit enum conversion in qed_set_tunn_cls_info Sasha Levin
2018-10-16  4:13 ` [PATCH AUTOSEL 4.14 26/61] qed: Fix mask parameter in qed_vf_prep_tunn_req_tlv Sasha Levin
2018-10-16  4:13 ` [PATCH AUTOSEL 4.14 27/61] qed: Avoid implicit enum conversion in qed_roce_mode_to_flavor Sasha Levin
2018-10-16  4:13 ` [PATCH AUTOSEL 4.14 28/61] bonding: pass link-local packets to bonding master also Sasha Levin
2018-10-16  4:13 ` [PATCH AUTOSEL 4.14 29/61] bonding: avoid possible dead-lock Sasha Levin
2018-10-16  4:13 ` [PATCH AUTOSEL 4.14 30/61] qed: Avoid constant logical operation warning in qed_vf_pf_acquire Sasha Levin
2018-10-16  4:13 ` [PATCH AUTOSEL 4.14 31/61] qed: Avoid implicit enum conversion in qed_iwarp_parse_rx_pkt Sasha Levin
2018-10-16  4:13 ` [PATCH AUTOSEL 4.14 32/61] bnxt_en: Fix TX timeout during netpoll Sasha Levin
2018-10-16  4:13 ` [PATCH AUTOSEL 4.14 33/61] nl80211: Fix possible Spectre-v1 for CQM RSSI thresholds Sasha Levin
2018-10-16  4:13 ` [PATCH AUTOSEL 4.14 34/61] asix: Check for supported Wake-on-LAN modes Sasha Levin
2018-10-16  4:13 ` [PATCH AUTOSEL 4.14 35/61] ax88179_178a: " Sasha Levin
2018-10-16  4:13 ` [PATCH AUTOSEL 4.14 36/61] lan78xx: " Sasha Levin
2018-10-16  4:13 ` [PATCH AUTOSEL 4.14 37/61] sr9800: " Sasha Levin
2018-10-16  4:13 ` [PATCH AUTOSEL 4.14 38/61] r8152: Check for supported Wake-on-LAN Modes Sasha Levin
2018-10-16  4:13 ` [PATCH AUTOSEL 4.14 39/61] smsc75xx: Check for Wake-on-LAN modes Sasha Levin
2018-10-16  4:13 ` [PATCH AUTOSEL 4.14 40/61] smsc95xx: " Sasha Levin
2018-10-16  4:13 ` [PATCH AUTOSEL 4.14 41/61] qlcnic: fix Tx descriptor corruption on 82xx devices Sasha Levin
2018-10-16  4:13 ` [PATCH AUTOSEL 4.14 42/61] i2c: i2c-scmi: fix for i2c_smbus_write_block_data Sasha Levin
2018-10-16  4:13 ` Sasha Levin [this message]
2018-10-16  4:13 ` [PATCH AUTOSEL 4.14 44/61] net/mlx5: E-Switch, Fix out of bound access when setting vport rate Sasha Levin
2018-10-16  4:13 ` [PATCH AUTOSEL 4.14 45/61] net/mlx5e: Set vlan masks for all offloaded TC rules Sasha Levin
2018-10-16  4:13 ` [PATCH AUTOSEL 4.14 46/61] perf/core: Fix perf_pmu_unregister() locking Sasha Levin
2018-10-16  4:13 ` [PATCH AUTOSEL 4.14 47/61] perf/ring_buffer: Prevent concurent ring buffer access Sasha Levin
2018-10-16  4:13 ` [PATCH AUTOSEL 4.14 48/61] perf/x86/intel/uncore: Fix PCI BDF address of M3UPI on SKX Sasha Levin
2018-10-16  4:13 ` [PATCH AUTOSEL 4.14 49/61] perf/x86/amd/uncore: Set ThreadMask and SliceMask for L3 Cache perf events Sasha Levin
2018-10-16  4:13 ` [PATCH AUTOSEL 4.14 50/61] net: fec: fix rare tx timeout Sasha Levin
2018-10-16  4:13 ` [PATCH AUTOSEL 4.14 51/61] declance: Fix continuation with the adapter identification message Sasha Levin
2018-10-16  4:13 ` [PATCH AUTOSEL 4.14 52/61] nfp: avoid soft lockups under control message storm Sasha Levin
2018-10-16  4:13 ` [PATCH AUTOSEL 4.14 53/61] bonding: fix warning message Sasha Levin
2018-10-16  4:13 ` [PATCH AUTOSEL 4.14 54/61] net: qualcomm: rmnet: Skip processing loopback packets Sasha Levin
2018-10-16  4:13 ` [PATCH AUTOSEL 4.14 55/61] locking/ww_mutex: Fix runtime warning in the WW mutex selftest Sasha Levin
2018-10-16  4:13 ` [PATCH AUTOSEL 4.14 56/61] net/usb: cancel pending work when unbinding smsc75xx Sasha Levin
2018-10-16  4:13 ` [PATCH AUTOSEL 4.14 57/61] be2net: don't flip hw_features when VXLANs are added/deleted Sasha Levin
2018-10-16  4:14 ` [PATCH AUTOSEL 4.14 58/61] net: cxgb3_main: fix a missing-check bug Sasha Levin
2018-10-16  4:14 ` [PATCH AUTOSEL 4.14 59/61] yam: " Sasha Levin
2018-10-16  4:14 ` [PATCH AUTOSEL 4.14 60/61] ocfs2: fix crash in ocfs2_duplicate_clusters_by_page() Sasha Levin
2018-10-16  4:14 ` [PATCH AUTOSEL 4.14 61/61] mm/vmstat.c: fix outdated vmstat_text Sasha Levin

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20181016041403.135678-43-sashal@kernel.org \
    --to=sashal@kernel.org \
    --cc=johannes.berg@intel.com \
    --cc=linux-kernel@vger.kernel.org \
    --cc=stable@vger.kernel.org \
    --cc=yuzhao@google.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox