mac80211: fix NULL pointer crash in monitor frame injection TX path
authorJohn Crispin <john@openwrt.org>
Fri, 30 Jan 2015 08:06:28 +0000 (08:06 +0000)
committerJohn Crispin <john@openwrt.org>
Fri, 30 Jan 2015 08:06:28 +0000 (08:06 +0000)
This "patch to the patch" fixes a NULL pointer derefence crash in the new
intermediate software queues. The crash can be reproduced by injecting an
802.11 frame with a BSSID that does not belong to a configured vif. The
wperf tool (https://github.com/anyfi/wperf) may be convenient for doing
this.

Signed-off-by: Johan Almbladh <ja@anyfi.net>
SVN-Revision: 44220

package/kernel/mac80211/patches/321-mac80211-add-an-intermediate-software-queue-implemen.patch

index ce5d4dcc3eb6b181d3733a6201a79b27051da3b1..a9e95fff6e81dd7cc45dfb89bb1514edc30ff5b6 100644 (file)
@@ -384,7 +384,7 @@ Signed-off-by: Felix Fietkau <nbd@openwrt.org>
 +      if (pubsta) {
 +              u8 tid = skb->priority & IEEE80211_QOS_CTL_TID_MASK;
 +              pubtxq = pubsta->txq[tid];
-+      } else {
++      } else if (vif) {
 +              pubtxq = vif->txq;
 +      }
 +