Received: by 2002:a05:6358:11c7:b0:104:8066:f915 with SMTP id i7csp6675622rwl; Wed, 22 Mar 2023 13:59:58 -0700 (PDT) X-Google-Smtp-Source: AK7set/UQYEDzoqMd2+F3ONvvsf7weM4x4LWb28CeHzKYcySU+0hoJAJEDvyaU21jU8nKphJKkf4 X-Received: by 2002:aa7:c9ce:0:b0:4af:81fb:4c72 with SMTP id i14-20020aa7c9ce000000b004af81fb4c72mr7424010edt.34.1679518797735; Wed, 22 Mar 2023 13:59:57 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1679518797; cv=none; d=google.com; s=arc-20160816; b=vzl1w4ahrnnLdLz322bfLNVOMhol0xPwglF2UZbB/Xz6cwzUQZhVzuW3BeH6ne4W5o yHoRjkN/3bSIVqtOGAiM63tPPTfEDMKgOReUG/RdVpQH5tynNqWSoM8j/GRUqmluK56Z wVZq1+kcLb17O2ZVMEpc+6290m2W6020LgiAI4CYOovWdz4gTn3QuPyUMTWrE15sJR46 Be+NLsW0ouZ5EPkQKMvOKhOE3e6TutOSJ4TAYbLhUFy3anRfEh+lJBZHUo2mpPp3uJR2 GM8To2YVMX7btq1snfnZwav+DiVbo8F7HbuYVJe64XTZ4sEtp9/kGDNc0uWtY2CO2AiL fu2Q== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:content-transfer-encoding:in-reply-to:from :references:cc:to:content-language:subject:user-agent:mime-version :date:message-id:dkim-signature; bh=tnVlQbQ+Osf80GEtD2/XmWosAEX59luwGzbhDTMc2sg=; b=bD8XENzKHiRo/egrP28sk9+UgdEicx0zXioU0AndSzRmek3p2eKPrxAsl5KxL/Y0mj dKbOWn2SFWjuEsVyrPKOFvW9adzNcuR65X+2Jbm4DI2LiQfLuR/rwtoranEAD3v1Mhvp IHXuw3KcyaYA8EvlKDousvC+sFISgAcp4mafCyspD+3akhSP+L+twpY26w9V4PHkHTQv fHZAaV4bbIbKxdzbS7yK0JC9AzBMeyT67YXnSJau6uryLZMwlTCqom7+7HVONaIjmA1u +2Lv7c+g26dEY5sew9A+47QIatqQCld5fzCMH2IBvrWLSJVj8WBZSi2QzjXG4coV/aLJ UdxA== ARC-Authentication-Results: i=1; mx.google.com; dkim=fail header.i=@nbd.name header.s=20160729 header.b=ZC4hYHr5; spf=pass (google.com: domain of linux-wireless-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) smtp.mailfrom=linux-wireless-owner@vger.kernel.org; dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=nbd.name Return-Path: Received: from out1.vger.email (out1.vger.email. [2620:137:e000::1:20]) by mx.google.com with ESMTP id a20-20020aa7cf14000000b00501db3adafasi6372396edy.510.2023.03.22.13.59.41; Wed, 22 Mar 2023 13:59:57 -0700 (PDT) Received-SPF: pass (google.com: domain of linux-wireless-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) client-ip=2620:137:e000::1:20; Authentication-Results: mx.google.com; dkim=fail header.i=@nbd.name header.s=20160729 header.b=ZC4hYHr5; spf=pass (google.com: domain of linux-wireless-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) smtp.mailfrom=linux-wireless-owner@vger.kernel.org; dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=nbd.name Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S231229AbjCVU6k (ORCPT + 60 others); Wed, 22 Mar 2023 16:58:40 -0400 Received: from lindbergh.monkeyblade.net ([23.128.96.19]:60688 "EHLO lindbergh.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S230478AbjCVU6j (ORCPT ); Wed, 22 Mar 2023 16:58:39 -0400 Received: from nbd.name (nbd.name [46.4.11.11]) by lindbergh.monkeyblade.net (Postfix) with ESMTPS id A5B25131 for ; Wed, 22 Mar 2023 13:58:38 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=nbd.name; s=20160729; h=Content-Transfer-Encoding:Content-Type:In-Reply-To:From: References:Cc:To:Subject:MIME-Version:Date:Message-ID:Sender:Reply-To: Content-ID:Content-Description:Resent-Date:Resent-From:Resent-Sender: Resent-To:Resent-Cc:Resent-Message-ID:List-Id:List-Help:List-Unsubscribe: List-Subscribe:List-Post:List-Owner:List-Archive; bh=tnVlQbQ+Osf80GEtD2/XmWosAEX59luwGzbhDTMc2sg=; b=ZC4hYHr5ViNYDmSF4u/gSOnnYk b0MS6sUS0hS4NJ74MKwTS59XCv9q+eUQVc9nkmpOvJoYGDJo2hgFXgigCVSoQIfFs5t7p1GtVUUpo DOycUVikLSGgx+7f8iBDB17GdeEWfPlhxDUwtxZw0ng3ilxzAGF8rqg5n1gpQegdSjBI=; Received: from p54ae9730.dip0.t-ipconnect.de ([84.174.151.48] helo=nf.local) by ds12 with esmtpsa (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 (Exim 4.94.2) (envelope-from ) id 1pf5XY-005lzv-H1; Wed, 22 Mar 2023 21:58:36 +0100 Message-ID: Date: Wed, 22 Mar 2023 21:58:36 +0100 MIME-Version: 1.0 User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:102.0) Gecko/20100101 Thunderbird/102.9.0 Subject: Re: [PATCH v3] wireless: mt76: mt7921: Fix use-after-free in fw features query. Content-Language: en-US To: Lorenzo Bianconi Cc: linux-wireless@vger.kernel.org, lorenzo.bianconi@redhat.com, Ben Greear , Kalle Valo References: <51fd8f76494348aa9ecbf0abc471ebe47a983dfd.1679502607.git.lorenzo@kernel.org> From: Felix Fietkau In-Reply-To: <51fd8f76494348aa9ecbf0abc471ebe47a983dfd.1679502607.git.lorenzo@kernel.org> Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: 7bit X-Spam-Status: No, score=-0.2 required=5.0 tests=DKIM_SIGNED,DKIM_VALID, DKIM_VALID_AU,DKIM_VALID_EF,NICE_REPLY_A,SPF_HELO_NONE,SPF_NONE, URIBL_BLOCKED autolearn=unavailable autolearn_force=no version=3.4.6 X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on lindbergh.monkeyblade.net Precedence: bulk List-ID: X-Mailing-List: linux-wireless@vger.kernel.org On 22.03.23 17:37, Lorenzo Bianconi wrote: > From: Ben Greear > > Stop referencing 'features' memory after release_firmware is called. > > Fixes this crash: > > RIP: 0010:mt7921_check_offload_capability+0x17d > mt7921_pci_probe+0xca/0x4b0 > ... > > Signed-off-by: Ben Greear > Signed-off-by: Lorenzo Bianconi Acked-by: Felix Fietkau - Felix