On 2 June 2016 at 07:20, Arend Van Spriel [off-list ref] wrote:
Op 2 jun. 2016 06:55 schreef "Rafał Miłecki" [off-list ref]:
quoted
On 1 June 2016 at 23:13, Arend van Spriel [off-list ref] wrote:
quoted
From: Franky Lin <redacted>
A regression was introduced in commit 9c349892ccc9 ("brcmfmac: revise
handling events in receive path") which moves eth_type_trans() call
to brcmf_rx_frame(). Msgbuf layer doesn't use brcmf_rx_frame() but
invokes
brcmf_netif_rx() directly. In such case the Ethernet header was not
stripped out resulting in null pointer dereference in the networking
stack.
(...)
Reported-by: Grey Christoforo <redacted>
Well, I reported this as well, over a month ago :(
Hi Rafał,
Dived into my emails and shameful to admit you are right. Totally missed it.
Sorry for unintended disregard.
It happens, thanks for the fix! :)
--
Rafał