All of lore.kernel.org
 help / color / mirror / Atom feed
* [PATCH wireless 1/2] wifi: rtw89: fix OOB read in rtw89_core_cancel_6ghz_probe_tx()
@ 2026-08-30 14:31 Tristan Madani
  2026-08-30 14:31 ` [PATCH wireless 2/2] wifi: rtw89: fix OOB read in __rtw89_wow_parse_akm() Tristan Madani
  2026-09-07  2:31 ` [PATCH wireless 1/2] wifi: rtw89: fix OOB read in rtw89_core_cancel_6ghz_probe_tx() Ping-Ke Shih
  0 siblings, 2 replies; 5+ messages in thread
From: Tristan Madani @ 2026-08-30 14:31 UTC (permalink / raw)
  To: Ping-Ke Shih
  Cc: Kalle Valo, Po-Hao Huang, Chin-Yen Lee, linux-wireless, stable,
	Tristan Madani

From: Tristan Madani <tristan@talencesecurity.com>

rtw89_core_cancel_6ghz_probe_tx() computes a pointer to the IE area
with

    ies = mgmt->u.beacon.variable;

and then passes skb->len as the IE data length to cfg80211_find_ie():

    ssid_ie = cfg80211_find_ie(WLAN_EID_SSID, ies, skb->len);

skb->len is the total frame length, not the length of the IE portion.
The IEs start at offset 36 (24-byte header + 12-byte fixed fields), so
the correct IE length is skb->len minus that offset.  Passing the full
frame length causes cfg80211_find_ie() to walk up to 36 bytes past the
end of the skb data buffer, triggering a slab-out-of-bounds read.

Additionally, the function does not verify that the frame is long enough
to contain the fixed beacon/probe-response fields before computing the
IE pointer.

Fix by returning early when skb->len is shorter than the variable-IE
offset, and pass the correct IE data length to cfg80211_find_ie().

Fixes: c6aa9a9c4725 ("wifi: rtw89: add RNR support for 6 GHz scan")
Cc: stable@vger.kernel.org
Signed-off-by: Tristan Madani <tristan@talencesecurity.com>
---
 drivers/net/wireless/realtek/rtw89/core.c | 9 ++++++++-
 1 file changed, 8 insertions(+), 1 deletion(-)

diff --git a/drivers/net/wireless/realtek/rtw89/core.c b/drivers/net/wireless/realtek/rtw89/core.c
index 68dad6090f87e..7b46715ea12db 100644
--- a/drivers/net/wireless/realtek/rtw89/core.c
+++ b/drivers/net/wireless/realtek/rtw89/core.c
@@ -2532,9 +2532,11 @@ static void rtw89_core_cancel_6ghz_probe_tx(struct rtw89_dev *rtwdev,
 {
 	struct ieee80211_rx_status *rx_status = IEEE80211_SKB_RXCB(skb);
 	struct ieee80211_mgmt *mgmt = (struct ieee80211_mgmt *)skb->data;
+	size_t hdr_len = offsetof(struct ieee80211_mgmt, u.beacon.variable);
 	struct list_head *pkt_list = rtwdev->scan_info.pkt_list;
 	struct rtw89_pktofld_info *info;
 	const u8 *ies = mgmt->u.beacon.variable, *ssid_ie;
+	size_t ie_len;
 	bool queue_work = false;
 
 	if (rx_status->band != NL80211_BAND_6GHZ)
@@ -2545,7 +2547,12 @@ static void rtw89_core_cancel_6ghz_probe_tx(struct rtw89_dev *rtwdev,
 		return;
 	}
 
-	ssid_ie = cfg80211_find_ie(WLAN_EID_SSID, ies, skb->len);
+	if (skb->len < hdr_len)
+		return;
+
+	ie_len = skb->len - hdr_len;
+
+	ssid_ie = cfg80211_find_ie(WLAN_EID_SSID, ies, ie_len);
 
 	list_for_each_entry(info, &pkt_list[NL80211_BAND_6GHZ], list) {
 		if (ether_addr_equal(info->bssid, mgmt->bssid)) {
-- 
2.47.3


^ permalink raw reply related	[flat|nested] 5+ messages in thread

end of thread, other threads:[~2026-09-07  2:40 UTC | newest]

Thread overview: 5+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-08-30 14:31 [PATCH wireless 1/2] wifi: rtw89: fix OOB read in rtw89_core_cancel_6ghz_probe_tx() Tristan Madani
2026-08-30 14:31 ` [PATCH wireless 2/2] wifi: rtw89: fix OOB read in __rtw89_wow_parse_akm() Tristan Madani
2026-09-05 23:43   ` [PATCH " Maxim Skokov
2026-09-07  2:40   ` [PATCH wireless " Ping-Ke Shih
2026-09-07  2:31 ` [PATCH wireless 1/2] wifi: rtw89: fix OOB read in rtw89_core_cancel_6ghz_probe_tx() Ping-Ke Shih

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.