aboutsummaryrefslogtreecommitdiff
path: root/drivers/net/wireless/nxp/nxpwifi/cfg80211.c
diff options
context:
space:
mode:
Diffstat (limited to 'drivers/net/wireless/nxp/nxpwifi/cfg80211.c')
-rw-r--r--drivers/net/wireless/nxp/nxpwifi/cfg80211.c31
1 files changed, 24 insertions, 7 deletions
diff --git a/drivers/net/wireless/nxp/nxpwifi/cfg80211.c b/drivers/net/wireless/nxp/nxpwifi/cfg80211.c
index 86304ea3331c..473e81304ca8 100644
--- a/drivers/net/wireless/nxp/nxpwifi/cfg80211.c
+++ b/drivers/net/wireless/nxp/nxpwifi/cfg80211.c
@@ -1539,9 +1539,11 @@ nxpwifi_cfg80211_del_station(struct wiphy *wiphy, struct wireless_dev *wdev,
eth_zero_addr(deauth_mac);
+ rcu_read_lock();
sta_node = nxpwifi_get_sta_entry(priv, params->mac);
if (sta_node)
ether_addr_copy(deauth_mac, params->mac);
+ rcu_read_unlock();
if (is_valid_ether_addr(deauth_mac)) {
ret = nxpwifi_uap_sta_deauth(priv, deauth_mac);
@@ -3323,6 +3325,7 @@ nxpwifi_cfg80211_authenticate(struct wiphy *wiphy,
struct nxpwifi_adapter *adapter = priv->adapter;
struct sk_buff *skb;
u16 pkt_len, auth_alg;
+ size_t frame_len;
int ret;
struct ieee80211_mgmt *mgmt;
struct nxpwifi_txinfo *tx_info;
@@ -3396,13 +3399,25 @@ nxpwifi_cfg80211_authenticate(struct wiphy *wiphy,
nxpwifi_cancel_scan(adapter);
- pkt_len = (u16)req->ie_len + req->auth_data_len +
- NXPWIFI_MGMT_HEADER_LEN + NXPWIFI_AUTH_BODY_LEN;
+ frame_len = req->ie_len + req->auth_data_len +
+ sizeof(struct ieee80211_hdr_3addr) + NXPWIFI_AUTH_BODY_LEN;
if (req->auth_data_len >= 4)
- pkt_len -= 4;
+ frame_len -= 4;
+
+ /* nxpwifi_form_mgmt_frame() inserts address4, so the frame handed to
+ * the firmware is ETH_ALEN longer than the one built here.
+ */
+ if (frame_len > U16_MAX - ETH_ALEN) {
+ nxpwifi_dbg(adapter, ERROR,
+ "auth frame too long: %zu bytes\n", frame_len);
+ return -EINVAL;
+ }
+ pkt_len = frame_len + ETH_ALEN;
- mgmt = kzalloc(pkt_len, GFP_KERNEL);
+ mgmt = kzalloc(frame_len, GFP_KERNEL);
+ if (!mgmt)
+ return -ENOMEM;
skb = dev_alloc_skb(NXPWIFI_MIN_DATA_HEADER_LEN +
NXPWIFI_MGMT_FRAME_HEADER_SIZE +
@@ -3410,6 +3425,7 @@ nxpwifi_cfg80211_authenticate(struct wiphy *wiphy,
if (!skb) {
nxpwifi_dbg(adapter, ERROR,
"allocate skb failed for management frame\n");
+ kfree(mgmt);
return -ENOMEM;
}
@@ -3448,7 +3464,7 @@ nxpwifi_cfg80211_authenticate(struct wiphy *wiphy,
memcpy((u8 *)varptr, req->ie, req->ie_len);
}
- nxpwifi_form_mgmt_frame(skb, (const u8 *)mgmt, pkt_len);
+ nxpwifi_form_mgmt_frame(skb, (const u8 *)mgmt, frame_len);
kfree(mgmt);
priv->auth_flag = HOST_MLME_AUTH_PENDING;
priv->auth_alg = auth_alg;
@@ -3729,8 +3745,9 @@ int nxpwifi_init_channel_scan_gap(struct nxpwifi_adapter *adapter)
* additional active scan request for hidden SSIDs on passive channels.
*/
adapter->num_in_chan_stats = 2 * (n_channels_bg + n_channels_a);
- adapter->chan_stats = vmalloc(array_size(sizeof(*adapter->chan_stats),
- adapter->num_in_chan_stats));
+ adapter->chan_stats = kcalloc(adapter->num_in_chan_stats,
+ sizeof(*adapter->chan_stats),
+ GFP_KERNEL);
if (!adapter->chan_stats)
return -ENOMEM;