2009-01-09 14:38:08 +02:00
|
|
|
From a6411f449091c272ca08146238b91a0835306179 Mon Sep 17 00:00:00 2001
|
2009-01-03 15:48:27 +02:00
|
|
|
From: Gabor Juhos <juhosg@openwrt.org>
|
2009-01-07 20:17:27 +02:00
|
|
|
Date: Mon, 5 Jan 2009 11:14:14 +0100
|
2009-01-09 14:38:08 +02:00
|
|
|
Subject: [PATCH v2 10/11] ath9k: fix null pointer dereference in ani monitor code
|
2009-01-03 15:48:27 +02:00
|
|
|
|
|
|
|
In 'ath9k_ani_reset' the 'ahp->ah_curani' will be initialized only
|
2009-01-07 20:17:27 +02:00
|
|
|
if 'DO_ANI(ah)' true. In 'ath9k_hw_ani_monitor' we are using
|
|
|
|
'ahp->ah_curani' unconditionally, and it will cause a NULL pointer
|
|
|
|
dereference on AR9100.
|
2009-01-03 15:48:27 +02:00
|
|
|
|
|
|
|
Signed-off-by: Gabor Juhos <juhosg@openwrt.org>
|
|
|
|
Signed-off-by: Imre Kaloz <kaloz@openwrt.org>
|
|
|
|
---
|
|
|
|
drivers/net/wireless/ath9k/ani.c | 6 +++---
|
|
|
|
1 files changed, 3 insertions(+), 3 deletions(-)
|
|
|
|
|
|
|
|
--- a/drivers/net/wireless/ath9k/ani.c
|
|
|
|
+++ b/drivers/net/wireless/ath9k/ani.c
|
2009-01-07 20:17:27 +02:00
|
|
|
@@ -551,6 +551,9 @@ void ath9k_hw_ani_monitor(struct ath_hal
|
2009-01-03 15:48:27 +02:00
|
|
|
struct ar5416AniState *aniState;
|
|
|
|
int32_t listenTime;
|
|
|
|
|
|
|
|
+ if (!DO_ANI(ah))
|
|
|
|
+ return;
|
|
|
|
+
|
|
|
|
aniState = ahp->ah_curani;
|
|
|
|
ahp->ah_stats.ast_nodestats = *stats;
|
|
|
|
|
2009-01-07 20:17:27 +02:00
|
|
|
@@ -610,9 +613,6 @@ void ath9k_hw_ani_monitor(struct ath_hal
|
2009-01-03 15:48:27 +02:00
|
|
|
aniState->cckPhyErrCount = cckPhyErrCnt;
|
|
|
|
}
|
|
|
|
|
|
|
|
- if (!DO_ANI(ah))
|
|
|
|
- return;
|
|
|
|
-
|
|
|
|
if (aniState->listenTime > 5 * ahp->ah_aniPeriod) {
|
|
|
|
if (aniState->ofdmPhyErrCount <= aniState->listenTime *
|
|
|
|
aniState->ofdmTrigLow / 1000 &&
|