Skip to content

Commit 52137e5

Browse files
committed
wifi: cfg80211: clear link ID from bitmap during link delete after clean up
JIRA: https://issues.redhat.com/browse/RHEL-73817 JIRA: https://issues.redhat.com/browse/RHEL-74089 CVE: CVE-2024-57898 commit b5c32ff Author: Aditya Kumar Singh <quic_adisi@quicinc.com> Date: Thu Nov 21 09:45:30 2024 +0530 wifi: cfg80211: clear link ID from bitmap during link delete after clean up Currently, during link deletion, the link ID is first removed from the valid_links bitmap before performing any clean-up operations. However, some functions require the link ID to remain in the valid_links bitmap. One such example is cfg80211_cac_event(). The flow is - nl80211_remove_link() cfg80211_remove_link() ieee80211_del_intf_link() ieee80211_vif_set_links() ieee80211_vif_update_links() ieee80211_link_stop() cfg80211_cac_event() cfg80211_cac_event() requires link ID to be present but it is cleared already in cfg80211_remove_link(). Ultimately, WARN_ON() is hit. Therefore, clear the link ID from the bitmap only after completing the link clean-up. Signed-off-by: Aditya Kumar Singh <quic_adisi@quicinc.com> Link: https://patch.msgid.link/20241121-mlo_dfs_fix-v2-1-92c3bf7ab551@quicinc.com Signed-off-by: Johannes Berg <johannes.berg@intel.com> Signed-off-by: Jose Ignacio Tornos Martinez <jtornosm@redhat.com>
1 parent 6209451 commit 52137e5

File tree

2 files changed

+8
-3
lines changed

2 files changed

+8
-3
lines changed

net/mac80211/cfg.c

Lines changed: 7 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -4992,10 +4992,16 @@ static void ieee80211_del_intf_link(struct wiphy *wiphy,
49924992
unsigned int link_id)
49934993
{
49944994
struct ieee80211_sub_if_data *sdata = IEEE80211_WDEV_TO_SUB_IF(wdev);
4995+
u16 new_links = wdev->valid_links & ~BIT(link_id);
49954996

49964997
lockdep_assert_wiphy(sdata->local->hw.wiphy);
49974998

4998-
ieee80211_vif_set_links(sdata, wdev->valid_links, 0);
4999+
/* During the link teardown process, certain functions require the
5000+
* link_id to remain in the valid_links bitmap. Therefore, instead
5001+
* of removing the link_id from the bitmap, pass a masked value to
5002+
* simulate as if link_id does not exist anymore.
5003+
*/
5004+
ieee80211_vif_set_links(sdata, new_links, 0);
49995005
}
50005006

50015007
static int

net/wireless/util.c

Lines changed: 1 addition & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -2843,10 +2843,9 @@ void cfg80211_remove_link(struct wireless_dev *wdev, unsigned int link_id)
28432843
break;
28442844
}
28452845

2846-
wdev->valid_links &= ~BIT(link_id);
2847-
28482846
rdev_del_intf_link(rdev, wdev, link_id);
28492847

2848+
wdev->valid_links &= ~BIT(link_id);
28502849
eth_zero_addr(wdev->links[link_id].addr);
28512850
}
28522851

0 commit comments

Comments
 (0)