mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH 6.6.y] wifi: cfg80211: release locks on error in cfg80211_wext_siwgenie()
@ 2026-10-10  4:30 Wentao Guan
  2026-10-10  4:34 ` Wentao Guan
  0 siblings, 1 reply; 2+ messages in thread
From: Wentao Guan @ 2026-10-10  4:30 UTC (permalink / raw)
  To: sashal, kartikey406; +Cc: johannes, linux-wireless, linux-kernel, Wentao Guan

This error path returns while both wiphy_lock() and wdev_lock() are still
held, so one malformed IE request can permanently block later operations
on this wiphy. Route the error through out to release both locks.

Fixes: d01f1600e8b0 ("wifi: cfg80211: validate IEs in cfg80211_wext_siwgenie()")
Signed-off-by: Wentao Guan <guanwentao@uniontech.com>
---
 net/wireless/wext-sme.c | 6 ++++--
 1 file changed, 4 insertions(+), 2 deletions(-)

diff --git a/net/wireless/wext-sme.c b/net/wireless/wext-sme.c
index cfa903eb0e82f..0e7c314bdeef0 100644
--- a/net/wireless/wext-sme.c
+++ b/net/wireless/wext-sme.c
@@ -354,8 +354,10 @@ int cfg80211_wext_siwgenie(struct net_device *dev,
 			/* nothing */
 		}
 
-		if (!for_each_element_completed(elem, extra, ie_len))
-			return -EINVAL;
+		if (!for_each_element_completed(elem, extra, ie_len)) {
+			err = -EINVAL;
+			goto out;
+		}
 
 		ie = kmemdup(extra, ie_len, GFP_KERNEL);
 		if (!ie) {
-- 
2.39.5


^ permalink raw reply	[flat|nested] 2+ messages in thread

* Re:[PATCH 6.6.y] wifi: cfg80211: release locks on error in cfg80211_wext_siwgenie()
  2026-10-10  4:30 [PATCH 6.6.y] wifi: cfg80211: release locks on error in cfg80211_wext_siwgenie() Wentao Guan
@ 2026-10-10  4:34 ` Wentao Guan
  0 siblings, 0 replies; 2+ messages in thread
From: Wentao Guan @ 2026-10-10  4:34 UTC (permalink / raw)
  To: 关文涛, Sasha Levin, kartikey406
  Cc: johannes, linux-wireless, linux-kernel, stable

Sorry, it is for v6.6.158. cc the stable list.

BRs
Wentao Guan

> ---
> net/wireless/wext-sme.c | 6 ++++--
> 1 file changed, 4 insertions(+), 2 deletions(-)
> 
> diff --git a/net/wireless/wext-sme.c b/net/wireless/wext-sme.c
> index cfa903eb0e82f..0e7c314bdeef0 100644
> --- a/net/wireless/wext-sme.c
> +++ b/net/wireless/wext-sme.c
> @@ -354,8 +354,10 @@ int cfg80211_wext_siwgenie(struct net_device *dev,
>                         /* nothing */
>                 }
>  
> -               if (!for_each_element_completed(elem, extra, ie_len))
> -                       return -EINVAL;
> +               if (!for_each_element_completed(elem, extra, ie_len)) {
> +                       err = -EINVAL;
> +                       goto out;
> +               }
> 
>                ie = kmemdup(extra, ie_len, GFP_KERNEL);
>                 if (!ie) {

^ permalink raw reply	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2026-10-10  4:35 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-10-10  4:30 [PATCH 6.6.y] wifi: cfg80211: release locks on error in cfg80211_wext_siwgenie() Wentao Guan
2026-10-10  4:34 ` Wentao Guan

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®