https://github.com/torvalds/linux
Revision 6c80c39d9a6986a566c30d797aae37bfb697eea3 authored by Johannes Berg on 22 September 2011, 21:59:04 UTC, committed by John W. Linville on 26 September 2011, 18:55:50 UTC
If iwl_scan_initiate() fails for any reason,
priv->scan_request and priv->scan_vif are left
dangling. This can lead to a crash later when
iwl_bg_scan_completed() tries to run a pending
scan request.

In practice, this seems to be very rare due to
the STATUS_SCANNING check earlier. That check,
however, is wrong -- it should allow a scan to
be queued when a reset/roc scan is going on.
When a normal scan is already going on, a new
one can't be issued by mac80211, so that code
can be removed completely. I introduced this
bug when adding off-channel support in commit
266af4c745952e9bebf687dd68af58df553cb59d.

Cc: stable@kernel.org [3.0]
Reported-by: Peng Yan <peng.yan@intel.com>
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Wey-Yi Guy <wey-yi.w.guy@intel.com>
Signed-off-by: John W. Linville <linville@tuxdriver.com>
1 parent 1b9ca02
History
Tip revision: 6c80c39d9a6986a566c30d797aae37bfb697eea3 authored by Johannes Berg on 22 September 2011, 21:59:04 UTC
iwlagn: fix dangling scan request
Tip revision: 6c80c39

back to top