wifi: mac80211: Don't finalize CSA in IBSS mode if state is disconnected
stable inclusion from stable-v5.10.142 commit dd649b49219a0388cc10fc40e4c2ea681566a780 category: bugfix bugzilla: https://gitee.com/openeuler/kernel/issues/I6CSFH Reference: https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?id=dd649b49219a0388cc10fc40e4c2ea681566a780 -------------------------------- commit 15bc8966 upstream. When we are not connected to a channel, sending channel "switch" announcement doesn't make any sense. The BSS list is empty in that case. This causes the for loop in cfg80211_get_bss() to be bypassed, so the function returns NULL (check line 1424 of net/wireless/scan.c), causing the WARN_ON() in ieee80211_ibss_csa_beacon() to get triggered (check line 500 of net/mac80211/ibss.c), which was consequently reported on the syzkaller dashboard. Thus, check if we have an existing connection before generating the CSA beacon in ieee80211_ibss_finish_csa(). Cc: stable@vger.kernel.org Fixes: cd7760e6 ("mac80211: add support for CSA in IBSS mode") Link: https://syzkaller.appspot.com/bug?id=05603ef4ae8926761b678d2939a3b2ad28ab9ca6 Reported-by:<syzbot+b6c9fe29aefe68e4ad34@syzkaller.appspotmail.com> Signed-off-by:
Siddh Raman Pant <code@siddh.me> Tested-by:
<syzbot+b6c9fe29aefe68e4ad34@syzkaller.appspotmail.com> Link: https://lore.kernel.org/r/20220814151512.9985-1-code@siddh.me Signed-off-by:
Johannes Berg <johannes.berg@intel.com> Signed-off-by:
Greg Kroah-Hartman <gregkh@linuxfoundation.org> Signed-off-by:
Jialin Zhang <zhangjialin11@huawei.com> Reviewed-by:
Zheng Zengkai <zhengzengkai@huawei.com>
Loading
Please sign in to comment