diff options
author | Brian Norris <briannorris@chromium.org> | 2017-03-28 16:59:32 -0700 |
---|---|---|
committer | Kalle Valo <kvalo@codeaurora.org> | 2017-04-05 15:44:03 +0300 |
commit | ce8fad9a1f09009ec3918a99685d9e3176f50ce3 (patch) | |
tree | b907bf425f6e9cebf17c1c17f165bb8e2dd21b39 /drivers/net/wireless/marvell/mwifiex/main.c | |
parent | 78b9ccb81377ba908b2c18daf6e1a7beddc281e3 (diff) | |
download | op-kernel-dev-ce8fad9a1f09009ec3918a99685d9e3176f50ce3.zip op-kernel-dev-ce8fad9a1f09009ec3918a99685d9e3176f50ce3.tar.gz |
mwifiex: fix use-after-free for FW reinit errors
If we fail to reinit the FW when resetting the device (in the
synchronous version of mwifiex_init_hw_fw() -> mwifiex_fw_dpc()),
mwifiex_fw_dpc() will tear down the interface and free up the adapter.
But we don't actually check for all failure cases of mwifiex_fw_dpc(),
so some of them fall through and dereference adapter->fw_done with a
freed adapter, causing a use-after-free bug.
In any case, mwifiex_fw_dpc() will always signal FW completion -- in the
error OR success case -- so at best, this was repeat work. Let's not do
it.
Signed-off-by: Brian Norris <briannorris@chromium.org>
Signed-off-by: Kalle Valo <kvalo@codeaurora.org>
Diffstat (limited to 'drivers/net/wireless/marvell/mwifiex/main.c')
-rw-r--r-- | drivers/net/wireless/marvell/mwifiex/main.c | 1 |
1 files changed, 0 insertions, 1 deletions
diff --git a/drivers/net/wireless/marvell/mwifiex/main.c b/drivers/net/wireless/marvell/mwifiex/main.c index 30f4994..98c8345 100644 --- a/drivers/net/wireless/marvell/mwifiex/main.c +++ b/drivers/net/wireless/marvell/mwifiex/main.c @@ -1475,7 +1475,6 @@ mwifiex_reinit_sw(struct mwifiex_adapter *adapter) } mwifiex_dbg(adapter, INFO, "%s, successful\n", __func__); - complete_all(adapter->fw_done); return 0; err_init_fw: |