From: Zhu Yi Date: Thu, 9 Jul 2009 08:59:49 +0000 (+0800) Subject: cfg80211: fix NULL dereference in IBSS SIOCGIWAP X-Git-Url: https://git.stricted.de/?a=commitdiff_plain;h=80e5b06a1b0d9a6aa88dc5c9e93ba49510c52b45;p=GitHub%2Fmt8127%2Fandroid_kernel_alcatel_ttab.git cfg80211: fix NULL dereference in IBSS SIOCGIWAP This patch avoids memcpy from wdev->wext.ibss.bssid if it is NULL. This could happen if we SIOCGIWAP before SIOCSIWAP. Signed-off-by: Zhu Yi Signed-off-by: John W. Linville --- diff --git a/net/wireless/ibss.c b/net/wireless/ibss.c index 9394e78cd11f..8b65e212ae49 100644 --- a/net/wireless/ibss.c +++ b/net/wireless/ibss.c @@ -487,8 +487,11 @@ int cfg80211_ibss_wext_giwap(struct net_device *dev, wdev_lock(wdev); if (wdev->current_bss) memcpy(ap_addr->sa_data, wdev->current_bss->pub.bssid, ETH_ALEN); - else + else if (wdev->wext.ibss.bssid) memcpy(ap_addr->sa_data, wdev->wext.ibss.bssid, ETH_ALEN); + else + memset(ap_addr->sa_data, 0, ETH_ALEN); + wdev_unlock(wdev); return 0;