Jouni Malinen 32162a4dab mac80211: Fix key freeing to handle unlinked keys
Key locking simplification removed key->sdata != NULL verification from
ieee80211_key_free(). While that is fine for most use cases, there is one
path where this function can be called with an unlinked key (i.e.,
key->sdata == NULL && key->local == NULL). This results in a NULL pointer
dereference with the current implementation. This is known to happen at
least with FT protocol when wpa_supplicant tries to configure the key
before association.

Avoid the issue by passing in the local pointer to
ieee80211_key_free(). In addition, do not clear the key from hw_accel
or debugfs if it has not yet been added. At least the hw_accel one could
trigger another NULL pointer dereference.

Signed-off-by: Jouni Malinen <j@w1.fi>
Reviewed-by: Johannes Berg <johannes@sipsolutions.net>
Signed-off-by: John W. Linville <linville@tuxdriver.com>
2010-07-27 14:59:58 -04:00
..
2010-05-28 13:41:27 -04:00
2010-06-03 14:14:41 -04:00
2009-07-10 15:01:49 -04:00
2010-07-21 15:13:42 -04:00
2008-04-08 16:44:45 -04:00
2010-07-08 16:35:50 -04:00
2010-06-14 15:38:17 -04:00
2010-06-14 15:38:17 -04:00
2010-07-08 16:35:50 -04:00
2010-07-08 16:35:50 -04:00
2010-07-26 15:32:42 -04:00
2010-07-08 16:35:50 -04:00
2010-01-05 16:21:40 -05:00
2010-07-08 16:35:50 -04:00