mac80211: fix duplicate retransmission detection
authorJohannes Berg <johannes.berg@intel.com>
Thu, 11 Jul 2013 20:33:26 +0000 (22:33 +0200)
committerBen Hutchings <ben@decadent.org.uk>
Tue, 10 Sep 2013 00:57:11 +0000 (01:57 +0100)
commit517c62b4ca84901872c82a94ed10162111e4be97
treecf75bc4a66bfaf5f1662c55997d911199c017abc
parent0b06991f5cbcc15b8457b5c53e3d1e0c6d245f08
mac80211: fix duplicate retransmission detection

commit 6b0f32745dcfba01d7be33acd1b40306c7a914c6 upstream.

The duplicate retransmission detection code in mac80211
erroneously attempts to do the check for every frame,
even frames that don't have a sequence control field or
that don't use it (QoS-Null frames.)

This is problematic because it causes the code to access
data beyond the end of the SKB and depending on the data
there will drop packets erroneously.

Correct the code to not do duplicate detection for such
frames.

I found this error while testing AP powersave, it lead
to retransmitted PS-Poll frames being dropped entirely
as the data beyond the end of the SKB was always zero.

Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
net/mac80211/rx.c