All of lore.kernel.org
 help / color / mirror / Atom feed
From: "Tianchu Chen" <tianchu.chen@linux.dev>
To: gregkh@linuxfoundation.org, hansg@kernel.org
Cc: linux-staging@lists.linux.dev
Subject: [PATCH] staging: rtl8723bs: fix RX buffer OOB write from device-reported length
Date: Fri, 11 Sep 2026 11:10:42 +0000	[thread overview]
Message-ID: <8114c3adc1acaea78523cc0fb4d4b25f7665cee9@linux.dev> (raw)

From: Tianchu Chen <flynnnchen@tencent.com>

sd_recv_rxfifo() trusts the device-reported RX0_REQ_LEN value
(hal->SdioRxFIFOSize, a u16 read from the card via CMD52) as the
size of the next RX packet and passes it to sdio_read_port(), which
copies that many bytes into the recvbuf skb whose data area is only
MAX_RECVBUF_SZ (10240) bytes. A bogus device on SDIO can report up to
65535 bytes, causing a heap overflow of up to ~55KB past the skb
buffer.

Bail out when the RX0_REQ_LEN exceeds MAX_RECVBUF_SZ. This is expected
to keep behavior unchanged on normal devices.

Discovered by Atuin - Automated Vulnerability Discovery Engine.

Fixes: 554c0a3abf216 ("staging: Add rtl8723bs sdio wifi driver")
Cc: stable@vger.kernel.org
Assisted-by: LLM
Signed-off-by: Tianchu Chen <flynnnchen@tencent.com>
---

Test Report
=============================================================
Device: Wintel CX-W8

Cmdline: nokaslr no_hash_pointers randomize_kstack_offset=0 norandmaps
mitigations=off slub_debug=FZP 

Method: An oversized OOB RX packet filled with "RTL8723B-RXOVF" pattern has
been sent via sdio bus.

Result: Kernel reports object corruption on an unrelated RCU-reclaim path:
redzone and object-padding overwritten with the test pattern.

[  973.253606] CPU: 1 UID: 0 PID: 54 Comm: kworker/u17:2 Tainted: G    B   WC         6.12.94+deb13-amd64 #1  Debian 6.12.94-1
[  973.253635] Tainted: [B]=BAD_PAGE, [W]=WARN, [C]=CRAP
[  973.253651] Hardware name: Insyde Intel CX-W8/Intel CX-W8, BIOS M.W8RAAA01 04/17/2015
[  973.253668] Workqueue: kvfree_rcu_reclaim kfree_rcu_work
[  973.253698] RIP: 0010:object_err+0x1d2/0x1df
[  973.253722] Code: 1a 29 c1 48 8d 54 05 00 48 c7 c6 13 ba 4f 82 48 c7 c7 fc 5f 4e 82 e8 6d fb ff ff be 01 00 00 00 bf 05 00 00 00 e8 de 60 40 ff <0f> 0b 5b 5d 41 5c 41 5d c3 cc cc cc cc 49 89 d7 48 8b 0c 24 4c 89
[  973.253744] RSP: 0018:ffffc90000217be0 EFLAGS: 00010046
[  973.253765] RAX: 0000000000000000 RBX: ffff888001045580 RCX: 0000000000000027
[  973.253783] RDX: 0000000000000000 RSI: 0000000000000001 RDI: ffff88807b8a1780
[  973.253800] RBP: ffff8880191c8040 R08: 0000000000000000 R09: ffffc90000217a60
[  973.253816] R10: ffffffff82cb43c8 R11: 0000000000000003 R12: ffff8880191c8000
[  973.253832] R13: ffffea0000647200 R14: ffffea0000647200 R15: ffff8880191c8040
[  973.253849] FS:  0000000000000000(0000) GS:ffff88807b880000(0000) knlGS:0000000000000000
[  973.253867] CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
[  973.253884] CR2: 00007ffff7dfe350 CR3: 0000000005622000 CR4: 00000000001026f0
[  973.253901] Call Trace:
[  973.253918]  <TASK>
[  973.253939]  check_bytes_and_report.cold+0x66/0x84
[  973.253967]  check_object+0x17c/0x310
[  973.253994]  free_to_partial_list+0x1cd/0x490
[  973.254017]  ? kvfree_rcu_bulk+0x16a/0x1a0
[  973.254040]  kmem_cache_free_bulk.part.0+0x3b1/0x3d0
[  973.254064]  ? kvfree_rcu_bulk+0x16a/0x1a0
[  973.254086]  ? update_entity_lag+0x1b/0x90
[  973.254113]  kvfree_rcu_bulk+0x16a/0x1a0
[  973.254137]  kfree_rcu_work+0x100/0x1b0
[  973.254160]  ? __schedule+0x50d/0xc00
[  973.254184]  process_one_work+0x174/0x330
[  973.254210]  worker_thread+0x191/0x2f0
[  973.254234]  ? __pfx_worker_thread+0x10/0x10
[  973.254257]  kthread+0xcf/0x100
[  973.254279]  ? __pfx_kthread+0x10/0x10
[  973.254299]  ret_from_fork+0x31/0x50
[  973.254322]  ? __pfx_kthread+0x10/0x10
[  973.254343]  ret_from_fork_asm+0x1a/0x30
[  973.254369]  </TASK>
[  973.254385] ---[ end trace 0000000000000000 ]---
[  973.254404] FIX kmalloc-cg-192: Restoring Left Redzone 0xffff8880191c8000-0xffff8880191c803f=0xcc
[  973.254426] [Right Redzone overwritten] 0xffff8880191c8100-0xffff8880191c8107 @offset=256. First byte 0x2d instead of 0xcc
[  973.254447] FIX kmalloc-cg-192: Restoring Right Redzone 0xffff8880191c8100-0xffff8880191c8107=0xcc
[  973.254465] [Object padding overwritten] 0xffff8880191c8110-0xffff8880191c813f @offset=272. First byte 0x52 instead of 0x5a
[  973.254485] =============================================================================
[  973.254500] BUG kmalloc-cg-192 (Tainted: G    B   WC        ): Object corrupt
[  973.254517] -----------------------------------------------------------------------------
[  973.254517] 
[  973.254560] Slab 0xffffea0000647200 objects=25 used=12 fp=0xffff8880191c9e40 flags=0xfffffc0000240(workingset|head|node=0|zone=1|lastcpupid=0x1fffff)
[  973.254587] Object 0xffff8880191c8040 @offset=64 fp=0xffff8880191c8400
[  973.254587] 
[  973.254606] Redzone  ffff8880191c8000: cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc  ................
[  973.254624] Redzone  ffff8880191c8010: cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc  ................
[  973.254641] Redzone  ffff8880191c8020: cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc  ................
[  973.254659] Redzone  ffff8880191c8030: cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc  ................
[  973.254694] Object   ffff8880191c8050: 56 46 21 52 54 4c 38 37 32 33 42 2d 52 58 4f 56  VF!RTL8723B-RXOV
[  973.254711] Object   ffff8880191c8060: 46 21 52 54 4c 38 37 32 33 42 2d 52 58 4f 56 46  F!RTL8723B-RXOVF
[  973.254728] Object   ffff8880191c8070: 21 52 54 4c 38 37 32 33 42 2d 52 58 4f 56 46 21  !RTL8723B-RXOVF!
[  973.254745] Object   ffff8880191c8080: 52 54 4c 38 37 32 33 42 2d 52 58 4f 56 46 21 52  RTL8723B-RXOVF!R
[  973.254762] Object   ffff8880191c8090: 54 4c 38 37 32 33 42 2d 52 58 4f 56 46 21 52 54  TL8723B-RXOVF!RT
[  973.254779] Object   ffff8880191c80a0: 4c 38 37 32 33 42 2d 52 58 4f 56 46 21 52 54 4c  L8723B-RXOVF!RTL
[  973.254796] Object   ffff8880191c80b0: 38 37 32 33 42 2d 52 58 4f 56 46 21 52 54 4c 38  8723B-RXOVF!RTL8
[  973.254812] Object   ffff8880191c80c0: 37 32 33 42 2d 52 58 4f 56 46 21 52 54 4c 38 37  723B-RXOVF!RTL87
[  973.254829] Object   ffff8880191c80d0: 32 33 42 2d 52 58 4f 56 46 21 52 54 4c 38 37 32  23B-RXOVF!RTL872
[  973.254846] Object   ffff8880191c80e0: 33 42 2d 52 58 4f 56 46 21 52 54 4c 38 37 32 33  3B-RXOVF!RTL8723
[  973.254863] Object   ffff8880191c80f0: 42 2d 52 58 4f 56 46 21 52 54 4c 38 37 32 33 42  B-RXOVF!RTL8723B
[  973.254880] Redzone  ffff8880191c8100: cc cc cc cc cc cc cc cc                          ........
[  973.254917] Padding  ffff8880191c8110: 52 58 4f 56 46 21 52 54 4c 38 37 32 33 42 2d 52  RXOVF!RTL8723B-R
[  973.254953] Padding  ffff8880191c8130: 4f 56 46 21 52 54 4c 38 37 32 33 42 2d 52 58 4f  OVF!RTL8723B-RXO


 drivers/staging/rtl8723bs/hal/sdio_ops.c | 7 +++++++
 1 file changed, 7 insertions(+)

diff --git a/drivers/staging/rtl8723bs/hal/sdio_ops.c b/drivers/staging/rtl8723bs/hal/sdio_ops.c
index da2d9088ab5ac..b7a4ab0bedc90 100644
--- a/drivers/staging/rtl8723bs/hal/sdio_ops.c
+++ b/drivers/staging/rtl8723bs/hal/sdio_ops.c
@@ -644,6 +644,13 @@ static struct recv_buf *sd_recv_rxfifo(struct adapter *adapter, u32 size)
 	struct recv_priv *recv_priv;
 	struct recv_buf	*recvbuf;
 
+	/* RX0_REQ_LEN is device-reported; the skb buffer is only
+	 * MAX_RECVBUF_SZ bytes, reject bogus lengths instead of
+	 * overflowing past it.
+	 */
+	if (size > MAX_RECVBUF_SZ)
+		return NULL;
+
 	/*  Patch for some SDIO Host 4 bytes issue */
 	/*  ex. RK3188 */
 	readsize = round_up(size, 4);
-- 
2.51.0

                 reply	other threads:[~2026-09-11 11:10 UTC|newest]

Thread overview: [no followups] expand[flat|nested]  mbox.gz  Atom feed

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=8114c3adc1acaea78523cc0fb4d4b25f7665cee9@linux.dev \
    --to=tianchu.chen@linux.dev \
    --cc=gregkh@linuxfoundation.org \
    --cc=hansg@kernel.org \
    --cc=linux-staging@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.