[PATCH 3/3] station: fix NULL deref in ap_directed_roam

Suchir Kavi <[email protected]> Wed, 15 Jul 2026 19:34:44 -0700
Newsgroups dev.linux.lists.iwd
Message-ID <[email protected]>
station_ap_directed_roam() initialized ignore_candidates from
station->connected_bss->vendor_quirks before the state != CONNECTED
guard. station_disconnect() clears connected_bss before entering
DISCONNECTING and the WNM frame watch outlives the connection, so a BSS
Transition Management frame arriving in that window crashes on the
dereference the guard was meant to prevent.

Assign it after the state check, which guarantees connected_bss is set
(the frame-sanitize memcmp below already relies on the same invariant).

Assisted-by: Claude:claude-fable-5
---
 src/station.c | 6 ++++--
 1 file changed, 4 insertions(+), 2 deletions(-)

diff --git a/src/station.c b/src/station.c
index 0b2d7dc6..e3aeb3fd 100644
--- a/src/station.c
+++ b/src/station.c
@@ -3273,8 +3273,7 @@ static void station_ap_directed_roam(struct station *station,
 	uint16_t dtimer;
 	uint8_t valid_interval;
 	bool can_roam = !station_cannot_roam(station);
-	bool ignore_candidates =
-		station->connected_bss->vendor_quirks.ignore_bss_tm_candidates;
+	bool ignore_candidates;
 
 	l_debug("ifindex: %u", netdev_get_ifindex(station->netdev));
 
@@ -3283,6 +3282,9 @@ static void station_ap_directed_roam(struct station *station,
 		return;
 	}
 
+	ignore_candidates =
+		station->connected_bss->vendor_quirks.ignore_bss_tm_candidates;
+
 	/*
 	 * Sanitize the frame to check that it is from our current AP.
 	 *
-- 
2.54.0