Message ID | 20170328235933.950-1-briannorris@chromium.org (mailing list archive) |
---|---|
State | Accepted |
Commit | ce8fad9a1f09009ec3918a99685d9e3176f50ce3 |
Delegated to: | Kalle Valo |
Headers | show |
Brian Norris <briannorris@chromium.org> wrote: > If we fail to reinit the FW when resetting the device (in the > synchronous version of mwifiex_init_hw_fw() -> mwifiex_fw_dpc()), > mwifiex_fw_dpc() will tear down the interface and free up the adapter. > But we don't actually check for all failure cases of mwifiex_fw_dpc(), > so some of them fall through and dereference adapter->fw_done with a > freed adapter, causing a use-after-free bug. > > In any case, mwifiex_fw_dpc() will always signal FW completion -- in the > error OR success case -- so at best, this was repeat work. Let's not do > it. > > Signed-off-by: Brian Norris <briannorris@chromium.org> 2 patches applied to wireless-drivers-next.git, thanks. ce8fad9a1f09 mwifiex: fix use-after-free for FW reinit errors 755b37c93a06 mwifiex: catch mwifiex_fw_dpc() errors properly in reset
diff --git a/drivers/net/wireless/marvell/mwifiex/main.c b/drivers/net/wireless/marvell/mwifiex/main.c index 30f49944661f..98c83453ba5b 100644 --- a/drivers/net/wireless/marvell/mwifiex/main.c +++ b/drivers/net/wireless/marvell/mwifiex/main.c @@ -1475,7 +1475,6 @@ mwifiex_reinit_sw(struct mwifiex_adapter *adapter) } mwifiex_dbg(adapter, INFO, "%s, successful\n", __func__); - complete_all(adapter->fw_done); return 0; err_init_fw:
If we fail to reinit the FW when resetting the device (in the synchronous version of mwifiex_init_hw_fw() -> mwifiex_fw_dpc()), mwifiex_fw_dpc() will tear down the interface and free up the adapter. But we don't actually check for all failure cases of mwifiex_fw_dpc(), so some of them fall through and dereference adapter->fw_done with a freed adapter, causing a use-after-free bug. In any case, mwifiex_fw_dpc() will always signal FW completion -- in the error OR success case -- so at best, this was repeat work. Let's not do it. Signed-off-by: Brian Norris <briannorris@chromium.org> --- drivers/net/wireless/marvell/mwifiex/main.c | 1 - 1 file changed, 1 deletion(-)