aboutsummaryrefslogtreecommitdiffstats
path: root/net/wireless
diff options
context:
space:
mode:
authorFelix Fietkau <nbd@openwrt.org>2011-08-10 21:00:33 -0400
committerJohn W. Linville <linville@tuxdriver.com>2011-08-11 14:23:06 -0400
commit040bdf713d2bec8235f1af705e2d13da5d9baec8 (patch)
tree94bf0221a212b7e88ebaccfe9c4b76f4f210bd0f /net/wireless
parent6a6767b046e2d336e2af06cb605106ed44a852b6 (diff)
cfg80211: fix a crash in nl80211_send_station
mac80211 leaves sinfo->assoc_req_ies uninitialized, causing a random pointer memory access in nl80211_send_station. Instead of checking if the pointer is null, use sinfo->filled, like the rest of the fields. Signed-off-by: Felix Fietkau <nbd@openwrt.org> Signed-off-by: John W. Linville <linville@tuxdriver.com>
Diffstat (limited to 'net/wireless')
-rw-r--r--net/wireless/nl80211.c2
1 files changed, 1 insertions, 1 deletions
diff --git a/net/wireless/nl80211.c b/net/wireless/nl80211.c
index ca7697701076..253e56319d7e 100644
--- a/net/wireless/nl80211.c
+++ b/net/wireless/nl80211.c
@@ -2236,7 +2236,7 @@ static int nl80211_send_station(struct sk_buff *msg, u32 pid, u32 seq,
2236 } 2236 }
2237 nla_nest_end(msg, sinfoattr); 2237 nla_nest_end(msg, sinfoattr);
2238 2238
2239 if (sinfo->assoc_req_ies) 2239 if (sinfo->filled & STATION_INFO_ASSOC_REQ_IES)
2240 NLA_PUT(msg, NL80211_ATTR_IE, sinfo->assoc_req_ies_len, 2240 NLA_PUT(msg, NL80211_ATTR_IE, sinfo->assoc_req_ies_len,
2241 sinfo->assoc_req_ies); 2241 sinfo->assoc_req_ies);
2242 2242