[PATCH v2 1/2] It fixes a SEGV in eapol_rx_packets at receipt of EAPOL M1 msg at legacy roaming following a failed FT-handover due to a preceding ft_auth-/ft_reassoc-timeout. The issue only arises when using mwifiex / NXP 88W9098 driver for the client's WLAN module. We have seen the issue with SIEMENS SCALANCE W700 AX APs, but it may also occur with other AP brands supporting FT-handover.

Dierk Modrow <[email protected]> Wed, 8 Jul 2026 21:55:49 +0200
Newsgroups dev.linux.lists.iwd
Message-ID <[email protected]>
From: Dierk Modrow <[email protected]>

---
 src/eapol.c | 4 ++++
 1 file changed, 4 insertions(+)

diff --git a/src/eapol.c b/src/eapol.c
index 372549c6..c2dc4e4c 100644
--- a/src/eapol.c
+++ b/src/eapol.c
@@ -2824,6 +2824,10 @@ void eapol_register(struct eapol_sm *sm)
 
 	l_queue_push_head(state_machines, sm);
 
+	/* workaround against SEGV on fct. eapol_rx_packet by avoiding for two different eapol_frame_watches with different ids, but same eapol_sm ptr */
+	if ((sm->watch_id > 0) && eapol_frame_watch_remove(sm->watch_id)) {
+		l_debug("existing frame_watch for sm=%p with id=%u successfully removed", sm, sm->watch_id);
+	}
 	sm->watch_id = eapol_frame_watch_add(sm->handshake->ifindex,
 						rx_handler, sm);
 	sm->protocol_version = sm->handshake->proto_version;
-- 
2.49.0.windows.1