[PATCH 3/3] station: fix NULL deref in ap_directed_roam
Suchir Kavi <[email protected]> Wed, 15 Jul 2026 19:34:44 -0700
| Newsgroups | dev.linux.lists.iwd |
|---|---|
| Message-ID | <[email protected]> |
station_ap_directed_roam() initialized ignore_candidates from
station->connected_bss->vendor_quirks before the state != CONNECTED
guard. station_disconnect() clears connected_bss before entering
DISCONNECTING and the WNM frame watch outlives the connection, so a BSS
Transition Management frame arriving in that window crashes on the
dereference the guard was meant to prevent.
Assign it after the state check, which guarantees connected_bss is set
(the frame-sanitize memcmp below already relies on the same invariant).
Assisted-by: Claude:claude-fable-5
---
src/station.c | 6 ++++--
1 file changed, 4 insertions(+), 2 deletions(-)
diff --git a/src/station.c b/src/station.c
index 0b2d7dc6..e3aeb3fd 100644
--- a/src/station.c
+++ b/src/station.c
@@ -3273,8 +3273,7 @@ static void station_ap_directed_roam(struct station *station,
uint16_t dtimer;
uint8_t valid_interval;
bool can_roam = !station_cannot_roam(station);
- bool ignore_candidates =
- station->connected_bss->vendor_quirks.ignore_bss_tm_candidates;
+ bool ignore_candidates;
l_debug("ifindex: %u", netdev_get_ifindex(station->netdev));
@@ -3283,6 +3282,9 @@ static void station_ap_directed_roam(struct station *station,
return;
}
+ ignore_candidates =
+ station->connected_bss->vendor_quirks.ignore_bss_tm_candidates;
+
/*
* Sanitize the frame to check that it is from our current AP.
*
--
2.54.0