mirror of
https://github.com/BobTheBlinker/android_kernel_motorola_sm6375.git
synced 2026-10-10 22:40:54 -04:00
qcacld-3.0: Fix use after free during RX thread enqueue
Currently nbuf is being used to get gso segments after enqueue to DP RX thread, this will lead to use after free issue because RX thread may process and even free the buffer by the time nbuf is accessed for getting gso segments in enqueue/softirq context. Fix this by updating gso segments before nbuf enqueue to DP RX thread. Change-Id: I2cc93bf9a44e2d487c1a6d474349cf5c0c5db76a CRs-Fixed: 2958132
This commit is contained in:
parent
1f90252fae
commit
92cb9fa130
1 changed files with 2 additions and 2 deletions
|
|
@ -276,10 +276,10 @@ static QDF_STATUS dp_rx_tm_thread_enqueue(struct dp_rx_thread *rx_thread,
|
|||
num_elements_in_nbuf--;
|
||||
next_ptr_list = head_ptr->next;
|
||||
qdf_nbuf_set_next(head_ptr, NULL);
|
||||
qdf_nbuf_queue_head_enqueue_tail(&rx_thread->nbuf_queue,
|
||||
head_ptr);
|
||||
/* count aggregated RX frame into enqueued stats */
|
||||
nbuf_queued += qdf_nbuf_get_gso_segs(head_ptr);
|
||||
qdf_nbuf_queue_head_enqueue_tail(&rx_thread->nbuf_queue,
|
||||
head_ptr);
|
||||
head_ptr = next_ptr_list;
|
||||
}
|
||||
|
||||
|
|
|
|||
Loading…
Reference in a new issue