android_kernel_samsung_msm8226/net
Zhu Jianmin 79f4915845 cfg80211: Fix use after free when process wdev events
"bssid" is only initialized out of the while loop, in case of two
events with same type: EVENT_CONNECT_RESULT, but one has zero
ether addr, the other is non-zero, the bssid pointer will be
referenced twice, which lead to use-after-free issue.

Change-Id: Ie8a24275f7ec5c2f936ef0a802a42e5f63be9c71
CRs-Fixed: 2254305
Signed-off-by: Zhu Jianmin <jianminz@codeaurora.org>
CVE-2018-11939
Signed-off-by: Kevin F. Haggerty <haggertk@lineageos.org>
2020-03-07 14:01:45 +01:00
..
9p Merge tag 'v3.4.113' into lineage-16.0 2019-08-05 14:20:47 +02:00
802
8021q Merge tag 'v3.4.113' into lineage-16.0 2019-08-05 14:20:47 +02:00
appletalk Merge tag 'v3.4.113' into lineage-16.0 2019-08-05 14:20:47 +02:00
atm Merge tag 'v3.4.113' into lineage-16.0 2019-08-05 14:20:47 +02:00
ax25 Merge tag 'v3.4.113' into lineage-16.0 2019-08-05 14:20:47 +02:00
batman-adv Merge tag 'v3.4.113' into lineage-16.0 2019-08-05 14:20:47 +02:00
bluetooth Bluetooth: hidp: fix buffer overflow 2019-08-09 12:05:04 +02:00
bridge netfilter: ebtables: fix erroneous reject of last rule 2019-08-09 11:42:03 +02:00
caif caif: Add sockaddr length check before accessing sa_family in connect handler 2019-08-08 12:09:32 +02:00
can Merge tag 'v3.4.113' into lineage-16.0 2019-08-05 14:20:47 +02:00
ceph libceph: introduce ceph_crypt() for in-place en/decryption 2019-08-06 11:48:20 +02:00
core net: Set sk_prot_creator when cloning sockets to the right proto 2019-08-09 11:42:01 +02:00
dcb Merge tag 'v3.4.113' into lineage-16.0 2019-08-05 14:20:47 +02:00
dccp Merge remote-tracking branch 'google-common/deprecated/android-3.4' into lineage-16.0 2019-08-06 11:41:21 +02:00
decnet net: Loopback ifindex is constant now 2019-08-09 11:44:53 +02:00
dns_resolver Merge tag 'v3.4.113' into lineage-16.0 2019-08-05 14:20:47 +02:00
dsa
econet
ethernet
ieee802154 Merge tag 'v3.4.113' into lineage-16.0 2019-08-05 14:20:47 +02:00
ipv4 tcp: refine memory limit test in tcp_fragment() 2019-08-09 12:05:35 +02:00
ipv6 netfilter: xt_rpfilter: depend on raw or mangle table 2019-08-09 09:14:21 +02:00
ipx Merge tag 'v3.4.113' into lineage-16.0 2019-08-05 14:20:47 +02:00
irda irda: Fix lockdep annotations in hashbin_delete(). 2019-08-06 12:26:33 +02:00
iucv af_iucv: Move sockaddr length checks to before accessing sa_family in bind and connect handlers 2019-08-08 12:09:30 +02:00
key af_key: unconditionally clone on broadcast 2019-08-09 12:03:08 +02:00
l2tp l2tp: pass tunnel pointer to ->session_create() 2019-08-08 16:37:19 +02:00
lapb
llc net/llc: avoid BUG_ON() in skb_orphan() 2019-08-06 12:26:32 +02:00
mac80211 Merge tag 'v3.4.113' into lineage-16.0 2019-08-05 14:20:47 +02:00
netfilter netfilter: fix missing dependencies for NETFILTER_XT_MATCH_CONNLABEL 2019-08-09 09:14:20 +02:00
netlabel Merge tag 'v3.4.113' into lineage-16.0 2019-08-05 14:20:47 +02:00
netlink netlink: Fix dump skb leak/double free 2019-08-06 12:24:26 +02:00
netrom Merge tag 'v3.4.113' into lineage-16.0 2019-08-05 14:20:47 +02:00
nfc nfc: Fix the sockaddr length sanitization in llcp_sock_connect 2019-08-08 12:09:32 +02:00
openvswitch Merge tag 'v3.4.113' into lineage-16.0 2019-08-05 14:20:47 +02:00
packet BACKPORT: packet: in packet_do_bind, test fanout with bind_lock held 2019-08-08 16:33:38 +02:00
phonet Merge tag 'v3.4.113' into lineage-16.0 2019-08-05 14:20:47 +02:00
rds Merge tag 'v3.4.113' into lineage-16.0 2019-08-05 14:20:47 +02:00
rfkill Merge tag 'v3.4.113' into lineage-16.0 2019-08-05 14:20:47 +02:00
rose Merge tag 'v3.4.113' into lineage-16.0 2019-08-05 14:20:47 +02:00
rxrpc Merge tag 'v3.4.113' into lineage-16.0 2019-08-05 14:20:47 +02:00
sched Merge tag 'v3.4.113' into lineage-16.0 2019-08-05 14:20:47 +02:00
sctp sctp: verify size of a new chunk in _sctp_make_chunk() 2020-03-07 14:01:44 +01:00
sunrpc Merge remote-tracking branch 'google-common/deprecated/android-3.4' into lineage-16.0 2019-08-06 11:41:21 +02:00
tipc Merge tag 'v3.4.113' into lineage-16.0 2019-08-05 14:20:47 +02:00
unix af_unix: Add sockaddr length checks before accessing sa_family in bind and connect handlers 2019-08-08 12:10:17 +02:00
wanrouter Merge tag 'v3.4.113' into lineage-16.0 2019-08-05 14:20:47 +02:00
wimax
wireless cfg80211: Fix use after free when process wdev events 2020-03-07 14:01:45 +01:00
x25 Merge tag 'v3.4.113' into lineage-16.0 2019-08-05 14:20:47 +02:00
xfrm xfrm_user: validate XFRM_MSG_NEWAE incoming ESN size harder 2019-08-06 12:26:34 +02:00
Kconfig net: sockev: Initial Commit 2014-07-22 14:33:44 -06:00
Makefile
activity_stats.c
compat.c net/compat.c,linux/filter.h: share compat_sock_fprog 2019-08-05 14:21:58 +02:00
nonet.c
socket.c Merge tag 'v3.4.113' into lineage-16.0 2019-08-05 14:20:47 +02:00
sysctl_net.c