Description
In the Linux kernel, the following vulnerability has been resolved: iw_cxgb4: Fix potential NULL dereference in c4iw_fill_res_cm_id_entry() This condition needs to match the previous "if (epcp->state == LISTEN) {" exactly to avoid a NULL dereference of either "listen_ep" or "ep". The problem is that "epcp" has been re-assigned so just testing "if (epcp->state == LISTEN) {" a second time is not sufficient.
Product status
116aeb8873712ea559d26b0d9d88147af5c88db5 (git) before 76e0396313c79ecd0df44ee3c18745cfac52b3e6
116aeb8873712ea559d26b0d9d88147af5c88db5 (git) before 24278dc380aab6a1aef0a75317f57ad4c2453cf6
116aeb8873712ea559d26b0d9d88147af5c88db5 (git) before dd55240e4364d64befcc575b0d33091881524f42
116aeb8873712ea559d26b0d9d88147af5c88db5 (git) before 4ca446b127c568b59cb8d9748b6f70499624bb18
4.18
Any version before 4.18
5.15.99 (semver)
6.1.16 (semver)
6.2.3 (semver)
6.3 (original_commit_for_fix)
References
git.kernel.org/...c/76e0396313c79ecd0df44ee3c18745cfac52b3e6
git.kernel.org/...c/24278dc380aab6a1aef0a75317f57ad4c2453cf6
git.kernel.org/...c/dd55240e4364d64befcc575b0d33091881524f42
git.kernel.org/...c/4ca446b127c568b59cb8d9748b6f70499624bb18