From: Tristan Madani <tristmd@gmail.com>
To: Ping-Ke Shih <pkshih@realtek.com>
Cc: Kalle Valo <kvalo@kernel.org>, Po-Hao Huang <phhuang@realtek.com>,
Chin-Yen Lee <timlee@realtek.com>,
linux-wireless@vger.kernel.org, stable@vger.kernel.org,
Tristan Madani <tristan@talencesecurity.com>
Subject: [PATCH wireless 1/2] wifi: rtw89: fix OOB read in rtw89_core_cancel_6ghz_probe_tx()
Date: Sun, 30 Aug 2026 14:31:52 +0000 [thread overview]
Message-ID: <20260830143154.1751910-1-tristmd@gmail.com> (raw)
From: Tristan Madani <tristan@talencesecurity.com>
rtw89_core_cancel_6ghz_probe_tx() computes a pointer to the IE area
with
ies = mgmt->u.beacon.variable;
and then passes skb->len as the IE data length to cfg80211_find_ie():
ssid_ie = cfg80211_find_ie(WLAN_EID_SSID, ies, skb->len);
skb->len is the total frame length, not the length of the IE portion.
The IEs start at offset 36 (24-byte header + 12-byte fixed fields), so
the correct IE length is skb->len minus that offset. Passing the full
frame length causes cfg80211_find_ie() to walk up to 36 bytes past the
end of the skb data buffer, triggering a slab-out-of-bounds read.
Additionally, the function does not verify that the frame is long enough
to contain the fixed beacon/probe-response fields before computing the
IE pointer.
Fix by returning early when skb->len is shorter than the variable-IE
offset, and pass the correct IE data length to cfg80211_find_ie().
Fixes: c6aa9a9c4725 ("wifi: rtw89: add RNR support for 6 GHz scan")
Cc: stable@vger.kernel.org
Signed-off-by: Tristan Madani <tristan@talencesecurity.com>
---
drivers/net/wireless/realtek/rtw89/core.c | 9 ++++++++-
1 file changed, 8 insertions(+), 1 deletion(-)
diff --git a/drivers/net/wireless/realtek/rtw89/core.c b/drivers/net/wireless/realtek/rtw89/core.c
index 68dad6090f87e..7b46715ea12db 100644
--- a/drivers/net/wireless/realtek/rtw89/core.c
+++ b/drivers/net/wireless/realtek/rtw89/core.c
@@ -2532,9 +2532,11 @@ static void rtw89_core_cancel_6ghz_probe_tx(struct rtw89_dev *rtwdev,
{
struct ieee80211_rx_status *rx_status = IEEE80211_SKB_RXCB(skb);
struct ieee80211_mgmt *mgmt = (struct ieee80211_mgmt *)skb->data;
+ size_t hdr_len = offsetof(struct ieee80211_mgmt, u.beacon.variable);
struct list_head *pkt_list = rtwdev->scan_info.pkt_list;
struct rtw89_pktofld_info *info;
const u8 *ies = mgmt->u.beacon.variable, *ssid_ie;
+ size_t ie_len;
bool queue_work = false;
if (rx_status->band != NL80211_BAND_6GHZ)
@@ -2545,7 +2547,12 @@ static void rtw89_core_cancel_6ghz_probe_tx(struct rtw89_dev *rtwdev,
return;
}
- ssid_ie = cfg80211_find_ie(WLAN_EID_SSID, ies, skb->len);
+ if (skb->len < hdr_len)
+ return;
+
+ ie_len = skb->len - hdr_len;
+
+ ssid_ie = cfg80211_find_ie(WLAN_EID_SSID, ies, ie_len);
list_for_each_entry(info, &pkt_list[NL80211_BAND_6GHZ], list) {
if (ether_addr_equal(info->bssid, mgmt->bssid)) {
--
2.47.3
next reply other threads:[~2026-08-30 14:31 UTC|newest]
Thread overview: 5+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-30 14:31 Tristan Madani [this message]
2026-08-30 14:31 ` [PATCH wireless 2/2] wifi: rtw89: fix OOB read in __rtw89_wow_parse_akm() Tristan Madani
2026-09-05 23:43 ` [PATCH " Maxim Skokov
2026-09-07 2:40 ` [PATCH wireless " Ping-Ke Shih
2026-09-07 2:31 ` [PATCH wireless 1/2] wifi: rtw89: fix OOB read in rtw89_core_cancel_6ghz_probe_tx() Ping-Ke Shih
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260830143154.1751910-1-tristmd@gmail.com \
--to=tristmd@gmail.com \
--cc=kvalo@kernel.org \
--cc=linux-wireless@vger.kernel.org \
--cc=phhuang@realtek.com \
--cc=pkshih@realtek.com \
--cc=stable@vger.kernel.org \
--cc=timlee@realtek.com \
--cc=tristan@talencesecurity.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.