| From 5fd2f91ad483baffdbe798f8a08f1b41442d1e24 Mon Sep 17 00:00:00 2001 |
| From: Johannes Berg <johannes.berg@intel.com> |
| Date: Thu, 1 Aug 2019 09:30:33 +0200 |
| Subject: mac80211: fix possible sta leak |
| |
| From: Johannes Berg <johannes.berg@intel.com> |
| |
| commit 5fd2f91ad483baffdbe798f8a08f1b41442d1e24 upstream. |
| |
| If TDLS station addition is rejected, the sta memory is leaked. |
| Avoid this by moving the check before the allocation. |
| |
| Cc: stable@vger.kernel.org |
| Fixes: 7ed5285396c2 ("mac80211: don't initiate TDLS connection if station is not associated to AP") |
| Link: https://lore.kernel.org/r/20190801073033.7892-1-johannes@sipsolutions.net |
| Signed-off-by: Johannes Berg <johannes.berg@intel.com> |
| Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org> |
| |
| --- |
| net/mac80211/cfg.c | 9 +++++---- |
| 1 file changed, 5 insertions(+), 4 deletions(-) |
| |
| --- a/net/mac80211/cfg.c |
| +++ b/net/mac80211/cfg.c |
| @@ -1459,6 +1459,11 @@ static int ieee80211_add_station(struct |
| if (is_multicast_ether_addr(mac)) |
| return -EINVAL; |
| |
| + if (params->sta_flags_set & BIT(NL80211_STA_FLAG_TDLS_PEER) && |
| + sdata->vif.type == NL80211_IFTYPE_STATION && |
| + !sdata->u.mgd.associated) |
| + return -EINVAL; |
| + |
| sta = sta_info_alloc(sdata, mac, GFP_KERNEL); |
| if (!sta) |
| return -ENOMEM; |
| @@ -1466,10 +1471,6 @@ static int ieee80211_add_station(struct |
| if (params->sta_flags_set & BIT(NL80211_STA_FLAG_TDLS_PEER)) |
| sta->sta.tdls = true; |
| |
| - if (sta->sta.tdls && sdata->vif.type == NL80211_IFTYPE_STATION && |
| - !sdata->u.mgd.associated) |
| - return -EINVAL; |
| - |
| err = sta_apply_parameters(local, sta, params); |
| if (err) { |
| sta_info_free(local, sta); |