Skip to content

Commit 69e4b75

Browse files
committed
Miri Korenblit says: ==================== iwlwifi fix avoid use after free ==================== Signed-off-by: Johannes Berg <johannes.berg@intel.com>
2 parents 249e144 + 77e67d5 commit 69e4b75

1 file changed

Lines changed: 3 additions & 2 deletions

File tree

  • drivers/net/wireless/intel/iwlwifi/mld

drivers/net/wireless/intel/iwlwifi/mld/link.c

Lines changed: 3 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -501,6 +501,7 @@ void iwl_mld_remove_link(struct iwl_mld *mld,
501501
struct iwl_mld_vif *mld_vif = iwl_mld_vif_from_mac80211(bss_conf->vif);
502502
struct iwl_mld_link *link = iwl_mld_link_from_mac80211(bss_conf);
503503
bool is_deflink = link == &mld_vif->deflink;
504+
u8 fw_id = link->fw_id;
504505

505506
if (WARN_ON(!link || link->active))
506507
return;
@@ -513,10 +514,10 @@ void iwl_mld_remove_link(struct iwl_mld *mld,
513514

514515
RCU_INIT_POINTER(mld_vif->link[bss_conf->link_id], NULL);
515516

516-
if (WARN_ON(link->fw_id >= mld->fw->ucode_capa.num_links))
517+
if (WARN_ON(fw_id >= mld->fw->ucode_capa.num_links))
517518
return;
518519

519-
RCU_INIT_POINTER(mld->fw_id_to_bss_conf[link->fw_id], NULL);
520+
RCU_INIT_POINTER(mld->fw_id_to_bss_conf[fw_id], NULL);
520521
}
521522

522523
void iwl_mld_handle_missed_beacon_notif(struct iwl_mld *mld,

0 commit comments

Comments
 (0)