mirror of
https://github.com/espressif/esp-idf.git
synced 2026-09-22 13:01:16 +03:00
When a WPS handshake is already in progress and the enrollee sends another EAPOL-Start (e.g., due to missed packets or timeout), the registrar resets its state by calling 'eap_wsc_reset()'. This function frees 'sm->eap_method_priv' and then calls 'esp_wifi_ap_wps_disable()', which internally triggers another call to 'eap_wsc_reset()'. This results in a double reset where the second invocation accesses the already freed 'sm->eap_method_priv', leading to a crash. This fix sets 'sm->eap_method_priv' to NULL immediately after freeing it to ensure any subsequent calls to eap_wsc_reset() do not access an invalid pointer.