Nicolai Stange <nstange@xxxxxxx> wrote: > Commit e5e884b42639 ("libertas: Fix two buffer overflows at parsing bss > descriptor") introduced a bounds check on the number of supplied rates to > lbs_ibss_join_existing(). > > Unfortunately, it introduced a return path from within a RCU read side > critical section without a corresponding rcu_read_unlock(). Fix this. > > Fixes: e5e884b42639 ("libertas: Fix two buffer overflows at parsing bss > descriptor") > Signed-off-by: Nicolai Stange <nstange@xxxxxxx> I'll queue these to v5.5, unless Linus releases the final today and then they will go to v5.6. -- https://patchwork.kernel.org/patch/11331869/ https://wireless.wiki.kernel.org/en/developers/documentation/submittingpatches