Stanse found a memory leak in cfg80211_wext_siwscan. creq is not
freed/assigned on all paths. Fix that.
Signed-off-by: Jiri Slaby <redacted>
---
net/wireless/scan.c | 7 +++++--
1 files changed, 5 insertions(+), 2 deletions(-)
@@ -685,7 +685,7 @@ int cfg80211_wext_siwscan(struct net_device *dev,/* No channels found? */if(!i){err=-EINVAL;-gotoout;+gotoout_free;}/* Set real number of channels specified in creq->channels[] */
@@ -696,7 +696,7 @@ int cfg80211_wext_siwscan(struct net_device *dev,if(wrqu->data.flags&IW_SCAN_THIS_ESSID){if(wreq->essid_len>IEEE80211_MAX_SSID_LEN){err=-EINVAL;-gotoout;+gotoout_free;}memcpy(creq->ssids[0].ssid,wreq->essid,wreq->essid_len);creq->ssids[0].ssid_len=wreq->essid_len;
@@ -717,6 +717,9 @@ int cfg80211_wext_siwscan(struct net_device *dev,out:cfg80211_unlock_rdev(rdev);returnerr;+out_free:+kfree(creq);+gotoout;}EXPORT_SYMBOL_GPL(cfg80211_wext_siwscan);
From: Gertjan van Wingerde <hidden> Date: 2010-01-06 19:07:51
On 01/06/10 17:35, Jiri Slaby wrote:
quoted hunk
Stanse found a memory leak in cfg80211_wext_siwscan. creq is not
freed/assigned on all paths. Fix that.
Signed-off-by: Jiri Slaby <redacted>
---
net/wireless/scan.c | 7 +++++--
1 files changed, 5 insertions(+), 2 deletions(-)
@@ -685,7 +685,7 @@ int cfg80211_wext_siwscan(struct net_device *dev,/* No channels found? */if(!i){err=-EINVAL;-gotoout;+gotoout_free;}/* Set real number of channels specified in creq->channels[] */
@@ -696,7 +696,7 @@ int cfg80211_wext_siwscan(struct net_device *dev,if(wrqu->data.flags&IW_SCAN_THIS_ESSID){if(wreq->essid_len>IEEE80211_MAX_SSID_LEN){err=-EINVAL;-gotoout;+gotoout_free;}memcpy(creq->ssids[0].ssid,wreq->essid,wreq->essid_len);creq->ssids[0].ssid_len=wreq->essid_len;
@@ -717,6 +717,9 @@ int cfg80211_wext_siwscan(struct net_device *dev,out:cfg80211_unlock_rdev(rdev);returnerr;+out_free:+kfree(creq);+gotoout;}EXPORT_SYMBOL_GPL(cfg80211_wext_siwscan);
This last part looks a bit strange. Why don't you put out_free label before out label,
and let it continue after the kfree, instead of jumping back to the out label.
---
Gertjan.
From: John W. Linville <hidden> Date: 2010-01-06 20:00:29
On Wed, Jan 06, 2010 at 05:35:42PM +0100, Jiri Slaby wrote:
One fail path in cfg80211_wext_siwscan omits to unlock rdev->mtx.
Fix that.
Trigerrable by "Scan for SSID" with long enough SSID (> 32).
Signed-off-by: Jiri Slaby <redacted>
Both this and the next one are already fixed in wireless-2.6...
commit 65486c8b30498dd274eea2c542696f22b63fe5b8
Author: Johannes Berg [off-list ref]
Date: Wed Dec 23 15:33:35 2009 +0100
cfg80211: fix error path in cfg80211_wext_siwscan
If there's an invalid channel or SSID, the code leaks
the scan request. Always free the scan request, unless
it was successfully given to the driver.
Reported-by: Dan Carpenter [off-list ref]
Signed-off-by: Johannes Berg [off-list ref]
Acked-by: Dan Carpenter [off-list ref]
Signed-off-by: John W. Linville [off-list ref]
--
John W. Linville Someday the world will need a hero, and you
linville@tuxdriver.com might be all we have. Be ready.
On Wed, Jan 06, 2010 at 05:35:42PM +0100, Jiri Slaby wrote:
quoted
One fail path in cfg80211_wext_siwscan omits to unlock rdev->mtx.
Fix that.
Trigerrable by "Scan for SSID" with long enough SSID (> 32).
Signed-off-by: Jiri Slaby <redacted>
Both this and the next one are already fixed in wireless-2.6...