All of lore.kernel.org
 help / color / mirror / Atom feed
From: "Nicolas Escande" <nico.escande@gmail.com>
To: "Moon Hee Lee" <moonhee.lee.ca@gmail.com>,
	<johannes@sipsolutions.net>, <linux-wireless@vger.kernel.org>
Cc: <linux-kernel@vger.kernel.org>,
	<linux-kernel-mentees@lists.linux.dev>,
	<syzbot+ededba317ddeca8b3f08@syzkaller.appspotmail.com>
Subject: Re: [PATCH wireless-next] wifi: mac80211: reject VHT opmode for unsupported channel widths
Date: Thu, 03 Jul 2025 10:12:12 +0200	[thread overview]
Message-ID: <DB29OMQH4W9Z.1GPKEZBBIRSTS@gmail.com> (raw)
In-Reply-To: <20250702065908.430229-2-moonhee.lee.ca@gmail.com>

On Wed Jul 2, 2025 at 8:59 AM CEST, Moon Hee Lee wrote:
> VHT operating mode notifications must not be processed when the channel
> width is 5 MHz or 10 MHz, as the VHT specification does not support these
> narrow widths.

Hello,
Is this really specific for VHT ? or for HE /EHT as well ?

>
> Without validation, a malformed notification using 10 MHz can reach
> ieee80211_chan_width_to_rx_bw(), triggering a WARN_ON due to the invalid
> width. This issue was reported by syzbot.
>
> Reject these widths early in sta_link_apply_parameters() when
> opmode_notif is used.
>
> Reported-by: syzbot+ededba317ddeca8b3f08@syzkaller.appspotmail.com
> Closes: https://syzkaller.appspot.com/bug?extid=ededba317ddeca8b3f08
> Fixes: 751e7489c1d7 ("wifi: mac80211: expose ieee80211_chan_width_to_rx_bw() to drivers")
> Tested-by: syzbot+ededba317ddeca8b3f08@syzkaller.appspotmail.com
> Signed-off-by: Moon Hee Lee <moonhee.lee.ca@gmail.com>
> ---
>  net/mac80211/cfg.c | 15 +++++++++++++++
>  1 file changed, 15 insertions(+)
>
> diff --git a/net/mac80211/cfg.c b/net/mac80211/cfg.c
> index 56540c3701ed..5a6ae093a8bd 100644
> --- a/net/mac80211/cfg.c
> +++ b/net/mac80211/cfg.c
> @@ -1981,6 +1981,21 @@ static int sta_link_apply_parameters(struct ieee80211_local *local,
>  	ieee80211_sta_init_nss(link_sta);
>  
>  	if (params->opmode_notif_used) {
> +		enum nl80211_chan_width width = link->conf->chanreq.oper.width;
> +
> +		switch (width) {
> +		case NL80211_CHAN_WIDTH_20_NOHT:
Because this seems weird for VHT
> +		case NL80211_CHAN_WIDTH_20:
> +		case NL80211_CHAN_WIDTH_40:
> +		case NL80211_CHAN_WIDTH_80:
> +		case NL80211_CHAN_WIDTH_160:
> +		case NL80211_CHAN_WIDTH_80P80:
> +		case NL80211_CHAN_WIDTH_320:
And this did not exist for VHT either
> +			break;
> +		default:
> +			return -EINVAL;
> +		}
> +
>  		/* returned value is only needed for rc update, but the
>  		 * rc isn't initialized here yet, so ignore it
>  		 */


  reply	other threads:[~2025-07-03  8:12 UTC|newest]

Thread overview: 8+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2025-07-02  6:59 [PATCH wireless-next] wifi: mac80211: reject VHT opmode for unsupported channel widths Moon Hee Lee
2025-07-03  8:12 ` Nicolas Escande [this message]
2025-07-03  9:02   ` Moonhee Lee
2025-07-03 15:09     ` Johannes Berg
2025-07-03 15:11       ` Johannes Berg
2025-07-03 16:35         ` Moonhee Lee
2025-07-03 16:54           ` Johannes Berg
2025-07-03 18:45             ` Moonhee Lee

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=DB29OMQH4W9Z.1GPKEZBBIRSTS@gmail.com \
    --to=nico.escande@gmail.com \
    --cc=johannes@sipsolutions.net \
    --cc=linux-kernel-mentees@lists.linux.dev \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-wireless@vger.kernel.org \
    --cc=moonhee.lee.ca@gmail.com \
    --cc=syzbot+ededba317ddeca8b3f08@syzkaller.appspotmail.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.