From 81cb5b74bae9b0ebf2ae96391be8b37065b74330 Mon Sep 17 00:00:00 2001 From: Dierk Modrow Date: Wed, 8 Jul 2026 17:22:27 +0200 Subject: [PATCH 1/2] src/eapol.c: fix of SEGV in eapol_rx_packets at receipt of EAPOL M1 msg at legacy roaming after ft_auth-/ft_reassoc-timeout when using mwifiex / NXP 88W9098 driver --- src/eapol.c | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/src/eapol.c b/src/eapol.c index 372549c6..c2dc4e4c 100644 --- a/src/eapol.c +++ b/src/eapol.c @@ -2824,6 +2824,10 @@ void eapol_register(struct eapol_sm *sm) l_queue_push_head(state_machines, sm); + /* workaround against SEGV on fct. eapol_rx_packet by avoiding for two different eapol_frame_watches with different ids, but same eapol_sm ptr */ + if ((sm->watch_id > 0) && eapol_frame_watch_remove(sm->watch_id)) { + l_debug("existing frame_watch for sm=%p with id=%u successfully removed", sm, sm->watch_id); + } sm->watch_id = eapol_frame_watch_add(sm->handshake->ifindex, rx_handler, sm); sm->protocol_version = sm->handshake->proto_version; From 70d190be987434563d24815c1699580bcc507a3c Mon Sep 17 00:00:00 2001 From: Dierk Modrow Date: Wed, 8 Jul 2026 17:22:28 +0200 Subject: [PATCH 2/2] src/station.c: fix of SEGV in station_roam_scan_notify when performing repeated roam scan at legacy roaming after ft_auth-/ft_reassoc-timeout when using mwifiex / NXP 88W9098 driver --- src/station.c | 12 ++++++------ 1 file changed, 6 insertions(+), 6 deletions(-) diff --git a/src/station.c b/src/station.c index 8fcf8c70..077e510e 100644 --- a/src/station.c +++ b/src/station.c @@ -2253,7 +2253,7 @@ static bool station_can_fast_transition(struct station *station, { uint16_t mdid; - if (!hs->mde) + if (!hs || !hs->mde) return false; if (ie_parse_mobility_domain_from_data(hs->mde, hs->mde[1] + 2, @@ -2917,7 +2917,7 @@ static bool station_roam_scan_notify(int err, struct l_queue *bss_list, orig_security = network_get_security(network); - if (hs->mde) + if (hs && hs->mde) ie_parse_mobility_domain_from_data(hs->mde, hs->mde[1] + 2, &mdid, NULL, NULL); @@ -2930,7 +2930,7 @@ static bool station_roam_scan_notify(int err, struct l_queue *bss_list, if (bss && !station->ap_directed_roaming) { double cur_bss_rank = bss->rank; - if (hs->mde && bss->mde_present && l_get_le16(bss->mde) == mdid) + if (hs && hs->mde && bss->mde_present && l_get_le16(bss->mde) == mdid) cur_bss_rank *= RANK_FT_FACTOR; cur_bss_group_rank = evaluate_bss_group_rank(bss->addr, @@ -2967,8 +2967,8 @@ static bool station_roam_scan_notify(int err, struct l_queue *bss_list, goto next; /* Skip result if it is not part of the ESS */ - if (bss->ssid_len != hs->ssid_len || - memcmp(bss->ssid, hs->ssid, hs->ssid_len)) + if (hs && (bss->ssid_len != hs->ssid_len || + memcmp(bss->ssid, hs->ssid, hs->ssid_len))) goto next; if (scan_bss_get_security(bss, &security) < 0) @@ -2986,7 +2986,7 @@ static bool station_roam_scan_notify(int err, struct l_queue *bss_list, rank = bss->rank; - if (hs->mde && bss->mde_present && l_get_le16(bss->mde) == mdid) + if (hs && hs->mde && bss->mde_present && l_get_le16(bss->mde) == mdid) rank *= RANK_FT_FACTOR; group_rank = evaluate_bss_group_rank(bss->addr, bss->frequency,