Re: use-after-free in ieee80211_defrag() [from NetBSD]

2018-06-24 Thread Stefan Sperling
On Thu, Jun 21, 2018 at 07:46:12PM +0200, Sebastien Marie wrote: > Hi, > > m...@netbsd.org has corrected an use-after-free on NetBSD on similar > code we have. > > Fix use-after-free, m_cat can free m. > >

Re: use-after-free in ieee80211_defrag() [from NetBSD]

2018-06-24 Thread Sebastien Marie
On Thu, Jun 21, 2018 at 07:46:12PM +0200, Sebastien Marie wrote: > Hi, > > m...@netbsd.org has corrected an use-after-free on NetBSD on similar > code we have. > > Fix use-after-free, m_cat can free m. > >

use-after-free in ieee80211_defrag() [from NetBSD]

2018-06-21 Thread Sebastien Marie
Hi, m...@netbsd.org has corrected an use-after-free on NetBSD on similar code we have. Fix use-after-free, m_cat can free m. http://cvsweb.netbsd.org/bsdweb.cgi/src/sys/net80211/ieee80211_input.c.diff?r1=1.111=1.112 >From code reading on us side, I think the same problem is