Re: [PATCH] wireless: wext: allocate space for NULL-terminationfor 32byte SSIDs

From: Daniel Mack
Date: Tue Dec 15 2009 - 05:37:28 EST


On Tue, Dec 15, 2009 at 11:31:23AM +0100, Johannes Berg wrote:
> On Tue, 2009-12-15 at 18:20 +0800, Daniel Mack wrote:
>
> > > drivers/net/wireless/libertas$ grep lbs_deb_ * | grep ssid|grep '%s'
> > > assoc.c: lbs_deb_join("current SSID '%s', ssid length %u\n",
> > > assoc.c: lbs_deb_join("requested ssid '%s', ssid length %u\n",
> > > assoc.c: lbs_deb_join("ADHOC_START: SSID '%s', ssid length %u\n",
> > > scan.c: lbs_deb_wext("set_scan, essid '%s'\n",
> >
> > Those macros are stubbed out as nops in my setup, so they can
> > unfortunately not be the reason. I'll dig deeper :)
>
> Well, the stack trace ought to help.

It unfortunately doesn't. The site that causes the problem does not
crash itself. It just corrupts some memory, and the actual crash happens
much later, which makes it so evil.

Daniel
--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/