Re: [PATCH] ath9k: release allocated buffer if timed out

From: Brian Norris
Date: Wed May 20 2020 - 16:59:40 EST


On Wed, May 13, 2020 at 12:02 PM Brian Norris <briannorris@xxxxxxxxxxxx> wrote:
>
> On Wed, May 13, 2020 at 12:05 AM Kalle Valo <kvalo@xxxxxxxxxxxxxx> wrote:
> > Actually it's already reverted in -next, nobody just realised that it's
> > a regression from commit 728c1e2a05e4:
> >
> > ced21a4c726b ath9k: Fix use-after-free Read in htc_connect_service
>
> Nice.
>
> > v5.8-rc1 should be the first release having the fix.
>
> So I guess we have to wait until 5.8-rc1 (when this lands in mainline)
> to send this manually to stable@xxxxxxxxxxxxxxx?

For the record, there are more reports of this, if I'm reading them right:

https://bugzilla.kernel.org/show_bug.cgi?id=207797