From: Johannes Berg <redacted>
If we get to the WARN_ONCE(..., "Got a HT rate (...)", ...)
here with a NULL sta, then we crash because mvmsta is bad
and we try to dereference it. Fix that by printing -1 as the
state if no station was given.
Signed-off-by: Johannes Berg <redacted>
Fixes: 6761a718263a ("iwlwifi: mvm: add explicit check for non-data frames in get Tx rate")
Signed-off-by: Luca Coelho <redacted>
---
drivers/net/wireless/intel/iwlwifi/mvm/tx.c | 5 +++--
1 file changed, 3 insertions(+), 2 deletions(-)
@@ -269,17 +269,18 @@ static u32 iwl_mvm_get_tx_rate(struct iwl_mvm *mvm,u8rate_plcp;u32rate_flags=0;boolis_cck;-structiwl_mvm_sta*mvmsta=iwl_mvm_sta_from_mac80211(sta);/* info->control is only relevant for non HW rate control */if(!ieee80211_hw_check(mvm->hw,HAS_RATE_CONTROL)){+structiwl_mvm_sta*mvmsta=iwl_mvm_sta_from_mac80211(sta);+/* HT rate doesn't make sense for a non data frame */WARN_ONCE(info->control.rates[0].flags&IEEE80211_TX_RC_MCS&&!ieee80211_is_data(fc),"Got a HT rate (flags:0x%x/mcs:%d/fc:0x%x/state:%d) for a non data frame\n",info->control.rates[0].flags,info->control.rates[0].idx,-le16_to_cpu(fc),mvmsta->sta_state);+le16_to_cpu(fc),sta?mvmsta->sta_state:-1);rate_idx=info->control.rates[0].idx;}
On Fri, 2021-12-03 at 14:04 +0200, Luca Coelho wrote:
From: Johannes Berg <redacted>
If we get to the WARN_ONCE(..., "Got a HT rate (...)", ...)
here with a NULL sta, then we crash because mvmsta is bad
and we try to dereference it. Fix that by printing -1 as the
state if no station was given.
Signed-off-by: Johannes Berg <redacted>
Fixes: 6761a718263a ("iwlwifi: mvm: add explicit check for non-data frames in get Tx rate")
Signed-off-by: Luca Coelho <redacted>
---
Kalle,
Can you take this one directly to wireless-drivers? This fixes a kernel
crash in some situations.
--
Cheers,
Luca.
From: Kalle Valo <kvalo@kernel.org> Date: 2021-12-03 12:26:28
Luca Coelho [off-list ref] writes:
On Fri, 2021-12-03 at 14:04 +0200, Luca Coelho wrote:
quoted
From: Johannes Berg <redacted>
If we get to the WARN_ONCE(..., "Got a HT rate (...)", ...)
here with a NULL sta, then we crash because mvmsta is bad
and we try to dereference it. Fix that by printing -1 as the
state if no station was given.
Signed-off-by: Johannes Berg <redacted>
Fixes: 6761a718263a ("iwlwifi: mvm: add explicit check for non-data
frames in get Tx rate")
Signed-off-by: Luca Coelho <redacted>
---
Kalle,
Can you take this one directly to wireless-drivers? This fixes a kernel
crash in some situations.
From: Kalle Valo <kvalo@kernel.org> Date: 2021-12-08 18:15:30
Luca Coelho [off-list ref] wrote:
From: Johannes Berg <redacted>
If we get to the WARN_ONCE(..., "Got a HT rate (...)", ...)
here with a NULL sta, then we crash because mvmsta is bad
and we try to dereference it. Fix that by printing -1 as the
state if no station was given.
Signed-off-by: Johannes Berg <redacted>
Fixes: 6761a718263a ("iwlwifi: mvm: add explicit check for non-data frames in get Tx rate")
Signed-off-by: Luca Coelho <redacted>