Re: [PATCH] ath10k: fix use-after-free in ath10k_wmi_cmd_send_nowait

2018-03-01 Thread Brian Norris
On Sun, Feb 11, 2018 at 10:56:45AM +0800, Carl Huang wrote: > The skb may be freed in tx completion context before > trace_ath10k_wmi_cmd is called. This can be easily captured > when KASAN(Kernel Address Sanitizer) is enabled. The fix is > to add a reference count to the skb and release it after >

RE: [PATCH] ath10k: fix use-after-free in ath10k_wmi_cmd_send_nowait

2018-02-11 Thread Carl Huang
> -Original Message- > From: ath10k [mailto:ath10k-boun...@lists.infradead.org] On Behalf Of Felix > Fietkau > Sent: Sunday, February 11, 2018 5:59 PM > To: Carl Huang ; ath...@lists.infradead.org > Cc: linux-wireless@vger.kernel.org > Subject: Re: [PATCH] ath10k:

Re: [PATCH] ath10k: fix use-after-free in ath10k_wmi_cmd_send_nowait

2018-02-11 Thread Felix Fietkau
On 2018-02-11 03:56, Carl Huang wrote: > The skb may be freed in tx completion context before > trace_ath10k_wmi_cmd is called. This can be easily captured > when KASAN(Kernel Address Sanitizer) is enabled. The fix is > to add a reference count to the skb and release it after > trace_ath10k_wmi_cmd

[PATCH] ath10k: fix use-after-free in ath10k_wmi_cmd_send_nowait

2018-02-10 Thread Carl Huang
The skb may be freed in tx completion context before trace_ath10k_wmi_cmd is called. This can be easily captured when KASAN(Kernel Address Sanitizer) is enabled. The fix is to add a reference count to the skb and release it after trace_ath10k_wmi_cmd is called. Signed-off-by: Carl Huang --- driv

[PATCH] ath10k: fix use-after-free in ath10k_wmi_cmd_send_nowait

2018-02-10 Thread Carl Huang
The skb may be freed in tx completion context before trace_ath10k_wmi_cmd is called. This can be easily captured when KASAN(Kernel Address Sanitizer) is enabled. The fix is to add a reference count to the skb and release it after trace_ath10k_wmi_cmd is called. Signed-off-by: Carl Huang --- driv