]> git.ipfire.org Git - thirdparty/kernel/stable.git/commitdiff
wifi: rtw88: always wait for both firmware loading attempts
authorDmitry Antipov <dmantipov@yandex.ru>
Fri, 26 Jul 2024 11:46:57 +0000 (14:46 +0300)
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Thu, 17 Oct 2024 13:07:38 +0000 (15:07 +0200)
[ Upstream commit 0e735a4c6137262bcefe45bb52fde7b1f5fc6c4d ]

In 'rtw_wait_firmware_completion()', always wait for both (regular and
wowlan) firmware loading attempts. Otherwise if 'rtw_usb_intf_init()'
has failed in 'rtw_usb_probe()', 'rtw_usb_disconnect()' may issue
'ieee80211_free_hw()' when one of 'rtw_load_firmware_cb()' (usually
the wowlan one) is still in progress, causing UAF detected by KASAN.

Fixes: c8e5695eae99 ("rtw88: load wowlan firmware if wowlan is supported")
Reported-by: syzbot+6c6c08700f9480c41fe3@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=6c6c08700f9480c41fe3
Signed-off-by: Dmitry Antipov <dmantipov@yandex.ru>
Signed-off-by: Ping-Ke Shih <pkshih@realtek.com>
Link: https://patch.msgid.link/20240726114657.25396-1-dmantipov@yandex.ru
Signed-off-by: Sasha Levin <sashal@kernel.org>
drivers/net/wireless/realtek/rtw88/main.c

index 2ef1416899f03858b38ea838052c999cb65352d2..91eea38f62cd38cb05b4249dbe41e17e138862d3 100644 (file)
@@ -1007,20 +1007,21 @@ static int rtw_wait_firmware_completion(struct rtw_dev *rtwdev)
 {
        struct rtw_chip_info *chip = rtwdev->chip;
        struct rtw_fw_state *fw;
+       int ret = 0;
 
        fw = &rtwdev->fw;
        wait_for_completion(&fw->completion);
        if (!fw->firmware)
-               return -EINVAL;
+               ret = -EINVAL;
 
        if (chip->wow_fw_name) {
                fw = &rtwdev->wow_fw;
                wait_for_completion(&fw->completion);
                if (!fw->firmware)
-                       return -EINVAL;
+                       ret = -EINVAL;
        }
 
-       return 0;
+       return ret;
 }
 
 static int rtw_power_on(struct rtw_dev *rtwdev)