From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-1.web.codeaurora.org [10.30.226.201]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 93067145FE4 for ; Sat, 17 Aug 2024 09:23:45 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=10.30.226.201 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1723886625; cv=none; b=bW9mERwkKVr0JPW/EVLHWCfCsWjuYkpbCKknFayKxjqdHSPFPE/g6UaEd6kPho447hXJ1N98f451CGy5cx9f9NU5GohQhIu/6T7oIutJP1r+0mYtb1e6CI2KLueJmqcgkynDVXWAOXzVhx3Mnt9GHW5wF28vsS41uQ7u3Nv+3Mc= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1723886625; c=relaxed/simple; bh=BGH2RC52W3bn9Ptsw3Rvvtl7H/SZRnUNjZPyrqTWj88=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=houFvmD+ab76jN1HP9/QYXmmdahEf9ImkTDEqwO/m5s9IT3xnbh9tzuyTOaar6mNxKE1Qx5bUR1rkyEhtMcyI8/wWuZnB6ILiqES8LnnKGQZ4txmw9YnYOFpTY6bx/HJxi6zbQDK0uqjmHyWasZBQkzuBV5jCBKucLmoWu+ii2E= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=EjZs2YIg; arc=none smtp.client-ip=10.30.226.201 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="EjZs2YIg" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 11F01C116B1; Sat, 17 Aug 2024 09:23:44 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=linuxfoundation.org; s=korg; t=1723886625; bh=BGH2RC52W3bn9Ptsw3Rvvtl7H/SZRnUNjZPyrqTWj88=; h=From:To:Cc:Subject:Date:Reply-to:From; b=EjZs2YIgq1FInfzSxbgy0RaQNg0OHNcpGsxyHtHhcrdLoZ0s77dfjqZXLDtOs8G4H D3V9Jz5QrKO+q/wzIATh50psrPns2aIag0iimy51abGwsF9yjzWdOSalQmz/fKLjPV w4Cudl9m1y6u6o1x91m3INS/mZDkzoUexltJQm6A= From: Greg Kroah-Hartman To: linux-cve-announce@vger.kernel.org Cc: Greg Kroah-Hartman Subject: CVE-2024-43844: wifi: rtw89: wow: fix GTK offload H2C skbuff issue Date: Sat, 17 Aug 2024 11:22:48 +0200 Message-ID: <2024081731-CVE-2024-43844-97ea@gregkh> X-Mailer: git-send-email 2.46.0 Precedence: bulk X-Mailing-List: linux-cve-announce@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Reply-to: , X-Developer-Signature: v=1; a=openpgp-sha256; l=5636; i=gregkh@linuxfoundation.org; h=from:subject:message-id; bh=w9cLaQSBXuQxF0CpKMrAkiQd5iUJoxvJf3M5yfXN1Yc=; b=owGbwMvMwCRo6H6F97bub03G02pJDGkHsq9rcszSPrdna7uZ2FH97k976uR1TrjtvusvPTPxc HUyD/vBjlgWBkEmBlkxRZYv23iO7q84pOhlaHsaZg4rE8gQBi5OAZjI1EkMs5hm1t/lPbN2zz6P ++zd2jP7Ug+m7meYK3RTc/qmr7PkMmztC/gmyOqtSPyoDAA= X-Developer-Key: i=gregkh@linuxfoundation.org; a=openpgp; fpr=F4B60CC5BF78C2214A313DCB3147D40DDB2DFB29 Content-Transfer-Encoding: quoted-printable Description =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D In the Linux kernel, the following vulnerability has been resolved: wifi: rtw89: wow: fix GTK offload H2C skbuff issue We mistakenly put skb too large and that may exceed skb->end. Therefore, we fix it. skbuff: skb_over_panic: text:ffffffffc09e9a9d len:416 put:204 head:ffff8fba= 04eca780 data:ffff8fba04eca7e0 tail:0x200 end:0x140 dev: ------------[ cut here ]------------ kernel BUG at net/core/skbuff.c:192! invalid opcode: 0000 [#1] PREEMPT SMP PTI CPU: 1 PID: 4747 Comm: kworker/u4:44 Tainted: G O 6.6.30-02= 659-gc18865c4dfbd #1 86547039b47e46935493f615ee31d0b2d711d35e Hardware name: HP Meep/Meep, BIOS Google_Meep.11297.262.0 03/18/2021 Workqueue: events_unbound async_run_entry_fn RIP: 0010:skb_panic+0x5d/0x60 Code: c6 63 8b 8f bb 4c 0f 45 f6 48 c7 c7 4d 89 8b bb 48 89 ce 44 89 d1 41 = 56 53 41 53 ff b0 c8 00 00 00 e8 27 5f 23 00 48 83 c4 20 <0f> 0b 90 90 90 9= 0 90 90 90 90 90 90 90 90 90 90 90 90 90 0f 1f 44 RSP: 0018:ffffaa700144bad0 EFLAGS: 00010282 RAX: 0000000000000089 RBX: 0000000000000140 RCX: 14432c5aad26c900 RDX: 0000000000000000 RSI: 00000000ffffdfff RDI: 0000000000000001 RBP: ffffaa700144bae0 R08: 0000000000000000 R09: ffffaa700144b920 R10: 00000000ffffdfff R11: ffffffffbc28fbc0 R12: ffff8fba4e57a010 R13: 0000000000000000 R14: ffffffffbb8f8b63 R15: 0000000000000000 FS: 0000000000000000(0000) GS:ffff8fba7bd00000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 00007999c4ad1000 CR3: 000000015503a000 CR4: 0000000000350ee0 Call Trace: ? __die_body+0x1f/0x70 ? die+0x3d/0x60 ? do_trap+0xa4/0x110 ? skb_panic+0x5d/0x60 ? do_error_trap+0x6d/0x90 ? skb_panic+0x5d/0x60 ? handle_invalid_op+0x30/0x40 ? skb_panic+0x5d/0x60 ? exc_invalid_op+0x3c/0x50 ? asm_exc_invalid_op+0x16/0x20 ? skb_panic+0x5d/0x60 skb_put+0x49/0x50 rtw89_fw_h2c_wow_gtk_ofld+0xbd/0x220 [rtw89_core 778b32de31cd1f14df2d6721a= e99ba8a83636fa5] rtw89_wow_resume+0x31f/0x540 [rtw89_core 778b32de31cd1f14df2d6721ae99ba8a8= 3636fa5] rtw89_ops_resume+0x2b/0xa0 [rtw89_core 778b32de31cd1f14df2d6721ae99ba8a836= 36fa5] ieee80211_reconfig+0x84/0x13e0 [mac80211 818a894e3b77da6298269c59ed7cdff06= 5a4ed52] ? __pfx_wiphy_resume+0x10/0x10 [cfg80211 1a793119e2aeb157c4ca4091ff8e1d9ae= 233b59d] ? dev_printk_emit+0x51/0x70 ? _dev_info+0x6e/0x90 ? __pfx_wiphy_resume+0x10/0x10 [cfg80211 1a793119e2aeb157c4ca4091ff8e1d9ae= 233b59d] wiphy_resume+0x89/0x180 [cfg80211 1a793119e2aeb157c4ca4091ff8e1d9ae233b59d] ? __pfx_wiphy_resume+0x10/0x10 [cfg80211 1a793119e2aeb157c4ca4091ff8e1d9ae= 233b59d] dpm_run_callback+0x3c/0x140 device_resume+0x1f9/0x3c0 ? __pfx_dpm_watchdog_handler+0x10/0x10 async_resume+0x1d/0x30 async_run_entry_fn+0x29/0xd0 process_scheduled_works+0x1d8/0x3d0 worker_thread+0x1fc/0x2f0 kthread+0xed/0x110 ? __pfx_worker_thread+0x10/0x10 ? __pfx_kthread+0x10/0x10 ret_from_fork+0x38/0x50 ? __pfx_kthread+0x10/0x10 ret_from_fork_asm+0x1b/0x30 Modules linked in: ccm 8021q r8153_ecm cdc_ether usbnet r8152 mii dm_integr= ity async_xor xor async_tx lz4 lz4_compress zstd zstd_compress zram zsmallo= c uinput rfcomm cmac algif_hash rtw89_8922ae(O) algif_skcipher rtw89_8922a(= O) af_alg rtw89_pci(O) rtw89_core(O) btusb(O) snd_soc_sst_bxt_da7219_max983= 57a btbcm(O) snd_soc_hdac_hdmi btintel(O) snd_soc_intel_hda_dsp_common snd_= sof_probes btrtl(O) btmtk(O) snd_hda_codec_hdmi snd_soc_dmic uvcvideo video= buf2_vmalloc uvc videobuf2_memops videobuf2_v4l2 videobuf2_common snd_sof_p= ci_intel_apl snd_sof_intel_hda_common snd_soc_hdac_hda snd_sof_intel_hda so= undwire_intel soundwire_generic_allocation snd_sof_intel_hda_mlink soundwir= e_cadence snd_sof_pci snd_sof_xtensa_dsp mac80211 snd_soc_acpi_intel_match = snd_soc_acpi snd_sof snd_sof_utils soundwire_bus snd_soc_max98357a snd_soc_= avs snd_soc_hda_codec snd_hda_ext_core snd_intel_dspcfg snd_intel_sdw_acpi = snd_soc_da7219 snd_hda_codec snd_hwdep snd_hda_core veth ip6table_nat xt_MA= SQUERADE xt_cgroup fuse bluetooth ecdh_generic cfg80211 ecc gsmi: Log Shutdown Reason 0x03 ---[ end trace 0000000000000000 ]--- The Linux kernel CVE team has assigned CVE-2024-43844 to this issue. Affected and fixed versions =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D Issue introduced in 6.10 with commit ed9a3c0d4dd9 and fixed in 6.10.3 with= commit ef0d9d2f0dc1 Issue introduced in 6.10 with commit ed9a3c0d4dd9 and fixed in 6.11-rc1 wi= th commit dda364c34591 Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=3DCVE-2024-43844 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D The file(s) affected by this issue are: drivers/net/wireless/realtek/rtw89/fw.c Mitigation =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/ef0d9d2f0dc1133db3d3a1c5167190c6627146b2 https://git.kernel.org/stable/c/dda364c345913fe03ddbe4d5ae14a2754c100296