Donate to e Foundation | Murena handsets with /e/OS | Own a part of Murena! Learn more

Commit af089c15 authored by Javier Cardona's avatar Javier Cardona Committed by John W. Linville
Browse files

mac80211: Fix RCU pointer dereference in mesh_path_discard_frame()



Reported by Pedro Larbig (ASPj)

Signed-off-by: default avatarJavier Cardona <javier@cozybit.com>
Signed-off-by: default avatarJohn W. Linville <linville@tuxdriver.com>
parent 5982b47a
Loading
Loading
Loading
Loading
+6 −1
Original line number Diff line number Diff line
@@ -991,9 +991,14 @@ void mesh_path_discard_frame(struct sk_buff *skb,

		da = hdr->addr3;
		ra = hdr->addr1;
		rcu_read_lock();
		mpath = mesh_path_lookup(da, sdata);
		if (mpath)
		if (mpath) {
			spin_lock_bh(&mpath->state_lock);
			sn = ++mpath->sn;
			spin_unlock_bh(&mpath->state_lock);
		}
		rcu_read_unlock();
		mesh_path_error_tx(sdata->u.mesh.mshcfg.element_ttl, skb->data,
				   cpu_to_le32(sn), reason, ra, sdata);
	}