Skip to content

Commit 346ece0

Browse files
bingzlinvjw
authored andcommitted
mwifiex: fix NULL pointer dereference in usb suspend handler
Bug 60815 - Interface hangs in mwifiex_usb https://bugzilla.kernel.org/show_bug.cgi?id=60815 [ 2.883807] BUG: unable to handle kernel NULL pointer dereference at 0000000000000048 [ 2.883813] IP: [<ffffffff815a65e0>] pfifo_fast_enqueue+0x90/0x90 [ 2.883834] CPU: 1 PID: 3220 Comm: kworker/u8:90 Not tainted 3.11.1-monotone-l0 coolya#6 [ 2.883834] Hardware name: Microsoft Corporation Surface with Windows 8 Pro/Surface with Windows 8 Pro, BIOS 1.03.0450 03/29/2013 On Surface Pro, suspend to ram gives a NULL pointer dereference in pfifo_fast_enqueue(). The stack trace reveals that the offending call is clearing carrier in mwifiex_usb suspend handler. Since commit 1499d9f "mwifiex: don't drop carrier flag over suspend" has removed the carrier flag handling over suspend/resume in SDIO and PCIe drivers, I'm removing it in USB driver too. This also fixes the bug for Surface Pro. Cc: <stable@vger.kernel.org> # 3.5+ Tested-by: Dmitry Khromov <icechrome@gmail.com> Signed-off-by: Bing Zhao <bzhao@marvell.com> Signed-off-by: John W. Linville <linville@tuxdriver.com>
1 parent bd1c614 commit 346ece0

1 file changed

Lines changed: 0 additions & 7 deletions

File tree

  • drivers/net/wireless/mwifiex

drivers/net/wireless/mwifiex/usb.c

Lines changed: 0 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -447,9 +447,6 @@ static int mwifiex_usb_suspend(struct usb_interface *intf, pm_message_t message)
447447
*/
448448
adapter->is_suspended = true;
449449

450-
for (i = 0; i < adapter->priv_num; i++)
451-
netif_carrier_off(adapter->priv[i]->netdev);
452-
453450
if (atomic_read(&card->rx_cmd_urb_pending) && card->rx_cmd.urb)
454451
usb_kill_urb(card->rx_cmd.urb);
455452

@@ -509,10 +506,6 @@ static int mwifiex_usb_resume(struct usb_interface *intf)
509506
MWIFIEX_RX_CMD_BUF_SIZE);
510507
}
511508

512-
for (i = 0; i < adapter->priv_num; i++)
513-
if (adapter->priv[i]->media_connected)
514-
netif_carrier_on(adapter->priv[i]->netdev);
515-
516509
/* Disable Host Sleep */
517510
if (adapter->hs_activated)
518511
mwifiex_cancel_hs(mwifiex_get_priv(adapter,

0 commit comments

Comments
 (0)