aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorJouni Malinen <j@w1.fi>2005-06-27 01:19:05 (GMT)
committerJouni Malinen <j@w1.fi>2005-06-27 01:19:05 (GMT)
commit7fbafa439d74dd4d0f7249226e17c943676dc060 (patch)
treebaf100c5883af18f84985d4f239306bea1312cab
parent2e92c172a7a8f8cf11be23ae1643a30406c0cd56 (diff)
downloadhostap-history-7fbafa439d74dd4d0f7249226e17c943676dc060.zip
hostap-history-7fbafa439d74dd4d0f7249226e17c943676dc060.tar.gz
hostap-history-7fbafa439d74dd4d0f7249226e17c943676dc060.tar.bz2
Complete rsn_preauth_finished() by running ap_free_sta() from
registered callback (rsn_preauth_finished_cb) in order to avoid removing STA entry while EAPOL state machine is still processing the STA. This fixes a segfault due to using freed memory after completion of pre-authentication.
-rw-r--r--hostapd/wpa.c17
1 files changed, 16 insertions, 1 deletions
diff --git a/hostapd/wpa.c b/hostapd/wpa.c
index 0ad6684..cf73d94 100644
--- a/hostapd/wpa.c
+++ b/hostapd/wpa.c
@@ -552,6 +552,16 @@ static int rsn_preauth_iface_init(struct hostapd_data *hapd)
}
+static void rsn_preauth_finished_cb(void *eloop_ctx, void *timeout_ctx)
+{
+ struct hostapd_data *hapd = eloop_ctx;
+ struct sta_info *sta = timeout_ctx;
+ wpa_printf(MSG_DEBUG, "RSN: Removing pre-authentication STA entry for "
+ MACSTR, MAC2STR(sta->addr));
+ ap_free_sta(hapd, sta);
+}
+
+
void rsn_preauth_finished(struct hostapd_data *hapd, struct sta_info *sta,
int success)
{
@@ -566,7 +576,11 @@ void rsn_preauth_finished(struct hostapd_data *hapd, struct sta_info *sta,
pmksa_cache_add(hapd, sta, key, dot11RSNAConfigPMKLifetime);
}
- ap_free_sta(hapd, sta);
+ /*
+ * Finish STA entry removal from timeout in order to avoid freeing
+ * STA data before the caller has finished processing.
+ */
+ eloop_register_timeout(0, 0, rsn_preauth_finished_cb, hapd, sta);
}
@@ -1432,6 +1446,7 @@ void wpa_free_station(struct sta_info *sta)
eloop_cancel_timeout(wpa_send_eapol_timeout, sm->hapd, sta);
eloop_cancel_timeout(wpa_sm_call_step, sm->hapd, sta->wpa_sm);
+ eloop_cancel_timeout(rsn_preauth_finished_cb, sm->hapd, sta);
free(sm->last_rx_eapol_key);
free(sm);
sta->wpa_sm = NULL;