From patchwork Sat Mar 17 11:29:27 2018 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Lorenzo Bianconi X-Patchwork-Id: 10290771 X-Patchwork-Delegate: kvalo@adurom.com Return-Path: Received: from mail.wl.linuxfoundation.org (pdx-wl-mail.web.codeaurora.org [172.30.200.125]) by pdx-korg-patchwork.web.codeaurora.org (Postfix) with ESMTP id D7D3B60386 for ; Sat, 17 Mar 2018 11:32:15 +0000 (UTC) Received: from mail.wl.linuxfoundation.org (localhost [127.0.0.1]) by mail.wl.linuxfoundation.org (Postfix) with ESMTP id C883F290B3 for ; Sat, 17 Mar 2018 11:32:11 +0000 (UTC) Received: by mail.wl.linuxfoundation.org (Postfix, from userid 486) id BCA7029127; Sat, 17 Mar 2018 11:32:11 +0000 (UTC) X-Spam-Checker-Version: SpamAssassin 3.3.1 (2010-03-16) on pdx-wl-mail.web.codeaurora.org X-Spam-Level: X-Spam-Status: No, score=-6.9 required=2.0 tests=BAYES_00,RCVD_IN_DNSWL_HI autolearn=ham version=3.3.1 Received: from vger.kernel.org (vger.kernel.org [209.132.180.67]) by mail.wl.linuxfoundation.org (Postfix) with ESMTP id 5C6B2290B3 for ; Sat, 17 Mar 2018 11:32:10 +0000 (UTC) Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1751829AbeCQL3g (ORCPT ); Sat, 17 Mar 2018 07:29:36 -0400 Received: from mail-wr0-f193.google.com ([209.85.128.193]:33091 "EHLO mail-wr0-f193.google.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1751304AbeCQL3f (ORCPT ); Sat, 17 Mar 2018 07:29:35 -0400 Received: by mail-wr0-f193.google.com with SMTP id z73so9771976wrb.0 for ; Sat, 17 Mar 2018 04:29:35 -0700 (PDT) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:from:to:cc:subject:date:message-id; bh=YhOB87X7qvsK8v6SA1QwPk/QugX63oLnmUbZ2KWeKQs=; b=h2NaJN3klV5pTg7KwtPgKUjfF7exFgjTpuJqlg/fxJAg0tIcp1Py5wfrG0BebGPb/N 877fwRWBNQm9LJO6gocd6Xwxub6GR5eQOgjd5xGHhc+d2QWSDwdeyxoTRYdG6592J4hB sOKxO1ENsCVNdBc6cnuoHTdVJ+1F2eyUdzTxkhZkBXtTWkb79yrsv3CT0dxvNnFUpyVG ucHJG0g+c9KlNqCm98DgYG+Xi+tUK1zTDXbjw7wwKDPmEA320Y+UJghLZtAM9rK7Rtg0 ycpya1HIApp/E8zMOgz7xV3AgX5Km8oCSESPFu6szFKxSXdhp1kyUJSU82d7lFd4t1vb iotw== X-Gm-Message-State: AElRT7E0PAz1j5XFhZB9Z58XBNv8Prz80AzVLRlJF8zpAv3NlVI5NtHs oR1fCynAIy3VZNLrt+xbGN4a8xmkaAA= X-Google-Smtp-Source: AG47ELsI2WUEXQQshuOMK3pj9PwSR/J3JfB8nQZaKv/vHPSA5Hlb36zcDOp5sCQGcKPN4dIRXEqMjw== X-Received: by 10.223.187.147 with SMTP id q19mr4005611wrg.150.1521286174538; Sat, 17 Mar 2018 04:29:34 -0700 (PDT) Received: from localhost.localdomain ([151.66.2.62]) by smtp.gmail.com with ESMTPSA id z16sm15198291wrc.70.2018.03.17.04.29.33 (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Sat, 17 Mar 2018 04:29:33 -0700 (PDT) From: Lorenzo Bianconi To: nbd@nbd.name Cc: linux-wireless@vger.kernel.org Subject: [PATCH] mt76x2: fix possible NULL pointer dereferencing in mt76x2_tx() Date: Sat, 17 Mar 2018 12:29:27 +0100 Message-Id: <20180317112927.18299-1-lorenzo.bianconi@redhat.com> X-Mailer: git-send-email 2.16.2 Sender: linux-wireless-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: linux-wireless@vger.kernel.org X-Virus-Scanned: ClamAV using ClamSMTP Fix a theoretical NULL pointer dereferencing in mt76x2_tx routine that can occurs for injected frames in a monitor vif since vif pointer could be NULL for that interfaces Fixes: 23405236460b ("mt76: fix transmission of encrypted mgmt frames") Signed-off-by: Lorenzo Bianconi Acked-by: Felix Fietkau --- drivers/net/wireless/mediatek/mt76/mt76x2_tx.c | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/drivers/net/wireless/mediatek/mt76/mt76x2_tx.c b/drivers/net/wireless/mediatek/mt76/mt76x2_tx.c index 534e4bf9a34c..e46eafc4c436 100644 --- a/drivers/net/wireless/mediatek/mt76/mt76x2_tx.c +++ b/drivers/net/wireless/mediatek/mt76/mt76x2_tx.c @@ -36,9 +36,12 @@ void mt76x2_tx(struct ieee80211_hw *hw, struct ieee80211_tx_control *control, msta = (struct mt76x2_sta *) control->sta->drv_priv; wcid = &msta->wcid; + /* sw encrypted frames */ + if (!info->control.hw_key && wcid->hw_key_idx != -1) + control->sta = NULL; } - if (vif || (!info->control.hw_key && wcid->hw_key_idx != -1)) { + if (vif && !control->sta) { struct mt76x2_vif *mvif; mvif = (struct mt76x2_vif *) vif->drv_priv;