diff options
| author | Zhao Li <enderaoelyther@gmail.com> | 2026-07-09 03:59:04 +0800 |
|---|---|---|
| committer | Johannes Berg <johannes.berg@intel.com> | 2026-07-21 18:48:42 +0200 |
| commit | 37a77bd1395e8261d1760ae39c7f5eb637300550 (patch) | |
| tree | ac61591ea619c215e0eea3cde98a44d772d69d01 /include/linux/memory | |
| parent | aeea930c7a878957a4b74d4888cd22880db2258c (diff) | |
wifi: mac80211_hwsim: clear PMSR request state on abort
mac80211_hwsim saves the in-flight cfg80211 PMSR request and its wdev
in data->pmsr_request / data->pmsr_request_wdev when a measurement
starts, and clears them only when it reports completion.
mac80211_hwsim_abort_pmsr() never cleared that saved state. cfg80211
owns the request and frees it once the abort callback returns
(cfg80211_pmsr_process_abort() calls rdev_abort_pmsr() then
kfree(req)), so after an abort data->pmsr_request dangles. A later
hwsim PMSR report then dereferences the freed request in
hwsim_pmsr_report_nl() and completes it; a use-after-free.
Clear data->pmsr_request and data->pmsr_request_wdev once the abort
matches the active request. Move the wmediumd/virtio notification check
below the clear so the saved state is dropped even when no notification
is sent.
Assisted-by: Codex:gpt-5
Assisted-by: Claude:opus-4.8
Signed-off-by: Zhao Li <enderaoelyther@gmail.com>
Link: https://patch.msgid.link/20260708195911.84365-2-enderaoelyther@gmail.com
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Diffstat (limited to 'include/linux/memory')
0 files changed, 0 insertions, 0 deletions
