From: stefan.seyfried@googlemail.com
To: linux-kernel@vger.kernel.org, linux-wireless@vger.kernel.org
Cc: Stefan Seyfried <seife+kernel@b1-systems.com>
Subject: [PATCH] cfg80211: fix wext-compat memory leak
Date: Sun, 30 Sep 2018 12:53:00 +0200 [thread overview]
Message-ID: <20180930105300.30797-1-stefan.seyfried@googlemail.com> (raw)
From: Stefan Seyfried <seife+kernel@b1-systems.com>
cfg80211_wext_giwrate and sinfo.pertid might allocate sinfo.pertid via
rdev_get_station(), but never release it
Signed-off-by: Stefan Seyfried <seife+kernel@b1-systems.com>
---
net/wireless/wext-compat.c | 11 +++++++++--
1 file changed, 9 insertions(+), 2 deletions(-)
diff --git a/net/wireless/wext-compat.c b/net/wireless/wext-compat.c
index 167f7025ac98..f462336aac1c 100644
--- a/net/wireless/wext-compat.c
+++ b/net/wireless/wext-compat.c
@@ -1277,12 +1277,16 @@ static int cfg80211_wext_giwrate(struct net_device *dev,
err = rdev_get_station(rdev, dev, addr, &sinfo);
if (err)
return err;
-
if (!(sinfo.filled & BIT_ULL(NL80211_STA_INFO_TX_BITRATE)))
return -EOPNOTSUPP;
rate->value = 100000 * cfg80211_calculate_bitrate(&sinfo.txrate);
+ /* sta_set_sinfo(), called from ieee80211_get_station(), called from
+ * rdev_get_station via rdev->ops->get_station, allocates pertid struct
+ * which we do not use here. */
+ kfree(sinfo.pertid);
+
return 0;
}
@@ -1293,7 +1297,7 @@ static struct iw_statistics *cfg80211_wireless_stats(struct net_device *dev)
struct cfg80211_registered_device *rdev = wiphy_to_rdev(wdev->wiphy);
/* we are under RTNL - globally locked - so can use static structs */
static struct iw_statistics wstats;
- static struct station_info sinfo;
+ static struct station_info sinfo = {};
u8 bssid[ETH_ALEN];
if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION)
@@ -1352,6 +1356,9 @@ static struct iw_statistics *cfg80211_wireless_stats(struct net_device *dev)
if (sinfo.filled & BIT_ULL(NL80211_STA_INFO_TX_FAILED))
wstats.discard.retries = sinfo.tx_failed;
+ /* see cfg80211_wext_giwrate() above */
+ kfree(sinfo.pertid);
+
return &wstats;
}
--
2.19.0
next reply other threads:[~2018-09-30 10:53 UTC|newest]
Thread overview: 3+ messages / expand[flat|nested] mbox.gz Atom feed top
2018-09-30 10:53 stefan.seyfried [this message]
2018-10-01 7:12 ` Johannes Berg
2018-10-01 8:55 ` Stefan Seyfried
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20180930105300.30797-1-stefan.seyfried@googlemail.com \
--to=stefan.seyfried@googlemail.com \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-wireless@vger.kernel.org \
--cc=seife+kernel@b1-systems.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®