]> git.baikalelectronics.ru Git - kernel.git/commit
mac80211: initialize fast-xmit 'info' later
authorJohannes Berg <johannes.berg@intel.com>
Mon, 2 Jan 2017 10:19:29 +0000 (11:19 +0100)
committerJohannes Berg <johannes.berg@intel.com>
Mon, 2 Jan 2017 10:28:25 +0000 (11:28 +0100)
commit30b21a763e5ac3336cdffa329e8335b1cc7d877e
tree67eed715e449fb7460f834c32edf723f2b4efa05
parentde0ed9f9434a89de456e7863889b85b1b878f9a3
mac80211: initialize fast-xmit 'info' later

In ieee80211_xmit_fast(), 'info' is initialized to point to the skb
that's passed in, but that skb may later be replaced by a clone (if
it was shared), leading to an invalid pointer.

This can lead to use-after-free and also later crashes since the
real SKB's info->hw_queue doesn't get initialized properly.

Fix this by assigning info only later, when it's needed, after the
skb replacement (may have) happened.

Cc: stable@vger.kernel.org
Reported-by: Ben Greear <greearb@candelatech.com>
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
net/mac80211/tx.c