mirror of
				git://git.openwrt.org/openwrt/openwrt.git
				synced 2025-11-03 22:44:27 -05:00 
			
		
		
		
	mac80211: fix A-MSDU packet handling with TCP retransmission
Improves local TCP throughput and fixes use-after-free bugs that could lead to crashes. Signed-off-by: Felix Fietkau <nbd@nbd.name>
This commit is contained in:
		
							parent
							
								
									f00cb94f7c
								
							
						
					
					
						commit
						e220ffb533
					
				@ -0,0 +1,31 @@
 | 
			
		||||
From: Sara Sharon <sara.sharon@intel.com>
 | 
			
		||||
Date: Thu, 11 Oct 2018 14:21:21 +0200
 | 
			
		||||
Subject: [PATCH] mac80211: free skb fraglist before freeing the skb
 | 
			
		||||
 | 
			
		||||
mac80211 uses the frag list to build AMSDU. When freeing
 | 
			
		||||
the skb, it may not be really freed, since someone is still
 | 
			
		||||
holding a reference to it.
 | 
			
		||||
In that case, when TCP skb is being retransmitted, the
 | 
			
		||||
pointer to the frag list is being reused, while the data
 | 
			
		||||
in there is no longer valid.
 | 
			
		||||
Since we will never get frag list from the network stack,
 | 
			
		||||
as mac80211 doesn't advertise the capability, we can safely
 | 
			
		||||
free and nullify it before releasing the SKB.
 | 
			
		||||
 | 
			
		||||
Signed-off-by: Sara Sharon <sara.sharon@intel.com>
 | 
			
		||||
---
 | 
			
		||||
 | 
			
		||||
--- a/net/mac80211/status.c
 | 
			
		||||
+++ b/net/mac80211/status.c
 | 
			
		||||
@@ -561,6 +561,11 @@ static void ieee80211_report_used_skb(st
 | 
			
		||||
 	}
 | 
			
		||||
 
 | 
			
		||||
 	ieee80211_led_tx(local);
 | 
			
		||||
+
 | 
			
		||||
+	if (skb_has_frag_list(skb)) {
 | 
			
		||||
+		kfree_skb_list(skb_shinfo(skb)->frag_list);
 | 
			
		||||
+		skb_shinfo(skb)->frag_list = NULL;
 | 
			
		||||
+	}
 | 
			
		||||
 }
 | 
			
		||||
 
 | 
			
		||||
 /*
 | 
			
		||||
@ -96,7 +96,7 @@ Signed-off-by: Janusz Dziedzic <janusz.dziedzic@tieto.com>
 | 
			
		||||
 	struct rcu_head rcu_head;
 | 
			
		||||
--- a/net/mac80211/status.c
 | 
			
		||||
+++ b/net/mac80211/status.c
 | 
			
		||||
@@ -653,9 +653,22 @@ void ieee80211_tx_monitor(struct ieee802
 | 
			
		||||
@@ -658,9 +658,22 @@ void ieee80211_tx_monitor(struct ieee802
 | 
			
		||||
 	struct sk_buff *skb2;
 | 
			
		||||
 	struct ieee80211_tx_info *info = IEEE80211_SKB_CB(skb);
 | 
			
		||||
 	struct ieee80211_sub_if_data *sdata;
 | 
			
		||||
 | 
			
		||||
		Loading…
	
		Reference in New Issue
	
	Block a user