Message ID | 20250523110156.4017111-1-zilin@seu.edu.cn |
---|---|
State | New |
Headers | show |
Series | wifi: cfg80211: use kfree_sensitive() for connkeys cleanup | expand |
diff --git a/net/wireless/nl80211.c b/net/wireless/nl80211.c index f039a7d0d..aaaafde96 100644 --- a/net/wireless/nl80211.c +++ b/net/wireless/nl80211.c @@ -1580,7 +1580,7 @@ nl80211_parse_connkeys(struct cfg80211_registered_device *rdev, return result; error: - kfree(result); + kfree_sensitive(result); return ERR_PTR(err); }
The nl80211_parse_connkeys() function currently uses kfree() to release the 'result' structure in error handling paths. However, if an error occurs due to result->def being less than 0, the 'result' structure may contain sensitive information. To prevent potential leakage of sensitive data, replace kfree() with kfree_sensitive() when freeing 'result'. This change aligns with the approach used in its caller, nl80211_join_ibss(), enhancing the overall security of the wireless subsystem. Signed-off-by: Zilin Guan <zilin@seu.edu.cn> --- net/wireless/nl80211.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-)