]> git.ipfire.org Git - thirdparty/kernel/linux.git/commitdiff
wifi: mac80211: fix unsol_bcast_probe_resp double free on alloc failure
authorXiang Mei <xmei5@asu.edu>
Sun, 21 Jun 2026 09:35:31 +0000 (02:35 -0700)
committerJohannes Berg <johannes.berg@intel.com>
Mon, 6 Jul 2026 12:11:06 +0000 (14:11 +0200)
ieee80211_set_unsol_bcast_probe_resp() calls kfree_rcu() on the old
template before allocating the replacement. If the kzalloc() then fails,
it returns -ENOMEM while link->u.ap.unsol_bcast_probe_resp still points
at the object already queued for freeing. A later update or AP teardown
re-queues that same rcu_head; the second free is caught by KASAN when the
RCU sheaf is processed in softirq:

  BUG: KASAN: double-free in rcu_free_sheaf (mm/slub.c:5850)
  Free of addr ffff88800d06f300 by task exploit/145
   ...
   __rcu_free_sheaf_prepare (mm/slub.c:2634 mm/slub.c:2940)
   rcu_free_sheaf (mm/slub.c:5850)
   rcu_core (kernel/rcu/tree.c:2617 kernel/rcu/tree.c:2869)
   handle_softirqs (kernel/softirq.c:622)
  The buggy address belongs to the cache kmalloc-128 of size 128

Queue the old object for kfree_rcu() only after the new one is published,
matching ieee80211_set_probe_resp() and ieee80211_set_s1g_short_beacon().

Fixes: 3b1c256eb4ae ("wifi: mac80211: fixes in FILS discovery updates")
Reported-by: Weiming Shi <bestswngs@gmail.com>
Assisted-by: Claude:claude-opus-4-8
Signed-off-by: Xiang Mei <xmei5@asu.edu>
Link: https://patch.msgid.link/20260621093532.884188-1-xmei5@asu.edu
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
net/mac80211/cfg.c

index 3b58af59f7e4295cad37fc61a0b14d63f9f712eb..932cf20785bc3b6f7f80d6b51c0db78d9898a6f6 100644 (file)
@@ -1179,8 +1179,6 @@ ieee80211_set_unsol_bcast_probe_resp(struct ieee80211_sub_if_data *sdata,
        link_conf->unsol_bcast_probe_resp_interval = params->interval;
 
        old = sdata_dereference(link->u.ap.unsol_bcast_probe_resp, sdata);
-       if (old)
-               kfree_rcu(old, rcu_head);
 
        if (params->tmpl && params->tmpl_len) {
                new = kzalloc(sizeof(*new) + params->tmpl_len, GFP_KERNEL);
@@ -1193,6 +1191,9 @@ ieee80211_set_unsol_bcast_probe_resp(struct ieee80211_sub_if_data *sdata,
                RCU_INIT_POINTER(link->u.ap.unsol_bcast_probe_resp, NULL);
        }
 
+       if (old)
+               kfree_rcu(old, rcu_head);
+
        *changed |= BSS_CHANGED_UNSOL_BCAST_PROBE_RESP;
        return 0;
 }