From: Slawomir Stepien <sst@poczta.fm>
To: syzbot <syzbot@kernel.org>
Cc: syzkaller-upstream-moderation@googlegroups.com, syzbot@lists.linux.dev
Subject: Re: [PATCH RFC v3] wifi: cfg80211: fix BSS RB tree collision during channel switch
Date: Wed, 5 Aug 2026 22:31:09 +0200 [thread overview]
Message-ID: <anOdjR9mr7DumC6y@nr200> (raw)
In-Reply-To: <986597e1-174a-4bd0-9de5-dde9cb474df9@mail.kernel.org>
#syz upstream
On sie 05, 2026 09:26, syzbot wrote:
> When a station processes a Channel Switch Announcement (CSA),
> cfg80211_update_assoc_bss_entry() is called to update the channel of the
> associated BSS. Because the channel is part of the BSS Red-Black (RB) tree
> key, changing the channel requires removing the BSS from the tree and
> re-inserting it.
>
> Before re-inserting, cfg80211_update_assoc_bss_entry() searches for any
> existing BSS on the new channel that matches the associated BSS so it can
> be unlinked to prevent an RB tree collision. However, the search loop
> incorrectly uses cfg80211_bss_type_match() to filter candidates based on
> their capabilities. If an existing BSS matches perfectly in cmp_bss() (same
> channel, BSSID, and SSID) but has different capabilities (e.g., due to a
> malicious or misconfigured beacon setting both ESS and IBSS bits),
> cfg80211_bss_type_match() skips it.
>
> This leaves the colliding BSS in the tree. When cfg80211_rehash_bss()
> attempts to re-insert the associated BSS, rb_insert_bss() compares them
> using cmp_bss(), which ignores capabilities. It finds them identical,
> resulting in an RB tree collision and triggering a warning:
>
> WARNING: net/wireless/scan.c:1675 at rb_insert_bss net/wireless/scan.c:1675
> [inline]
> WARNING: net/wireless/scan.c:1675 at cfg80211_rehash_bss+0x1e6/0x540
> net/wireless/scan.c:1732
> Call Trace:
> <TASK>
> cfg80211_update_assoc_bss_entry+0x3cd/0x660 net/wireless/scan.c:3478
> cfg80211_ch_switch_notify+0x3b1/0x780 net/wireless/nl80211.c:22366
> ieee80211_sta_process_chanswitch+0xbd1/0x29e0 net/mac80211/mlme.c:-1
> ieee80211_rx_mgmt_beacon+0x1dc6/0x32a0 net/mac80211/mlme.c:8309
> ieee80211_sta_rx_queued_frame+0x6ac/0x4e40 net/mac80211/mlme.c:11793
> ieee80211_iface_process_skb net/mac80211/iface.c:1766 [inline]
> ieee80211_iface_work+0x552/0x1010 net/mac80211/iface.c:1823
> cfg80211_wiphy_work+0x29e/0x420 net/wireless/core.c:538
> </TASK>
>
> Fix this by removing the cfg80211_bss_type_match() check from the collision
> search loop. The RB tree uniqueness is defined solely by cmp_bss(), so any
> BSS that evaluates to cmp == 0 must be unlinked to prevent a collision,
> regardless of whether its capability matches the connection type. If the
> AP's capabilities legitimately changed, cfg80211_update_known_bss() will
> safely update the capability later.
>
> Fixes: 0afd425b1b64 ("cfg80211: fix duplicated scan entries after channel switch")
> Assisted-by: Gemini:gemini-3.5-flash Gemini:gemini-3.1-pro-preview syzbot
> Reported-by: syzbot+dc6f4dce0d707900cdea@syzkaller.appspotmail.com
> Closes: https://syzkaller.appspot.com/bug?extid=dc6f4dce0d707900cdea
> Link: https://syzkaller.appspot.com/ai_job?id=3e1a2f1d-82c9-492d-8063-7fb21356c013
> To: "Johannes Berg" <johannes@sipsolutions.net>
> To: <linux-wireless@vger.kernel.org>
> To: "Sergey Matyukevich" <sergey.matyukevich.os@quantenna.com>
> Cc: <linux-kernel@vger.kernel.org>
>
> ---
> v3:
> - Do not wrap log lines in the commit message.
>
> v2:
> - Removed the '------------[ cut here ]------------' line from the commit message to prevent checkpatch.pl from interpreting it as a commit separator.
> https://lore.kernel.org/all/4119b372-fffd-487d-b08f-f9cc0825ba05@mail.kernel.org/T/
>
> v1:
> https://lore.kernel.org/all/a8455fef-711a-4293-89ce-248c5f3428e7@mail.kernel.org/T/
> ---
> diff --git a/net/wireless/scan.c b/net/wireless/scan.c
> index 071083cc3..97bf7ab8c 100644
> --- a/net/wireless/scan.c
> +++ b/net/wireless/scan.c
> @@ -3443,11 +3443,6 @@ void cfg80211_update_assoc_bss_entry(struct wireless_dev *wdev,
> cbss->pub.channel = chan;
>
> list_for_each_entry(bss, &rdev->bss_list, list) {
> - if (!cfg80211_bss_type_match(bss->pub.capability,
> - bss->pub.channel->band,
> - wdev->conn_bss_type))
> - continue;
> -
> if (bss == cbss)
> continue;
>
>
>
> base-commit: f5098b6bae761e346ebcd9da7f95622c04733cff
--
Slawomir Stepien
prev parent reply other threads:[~2026-08-05 20:31 UTC|newest]
Thread overview: 2+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-05 9:26 [PATCH RFC v3] wifi: cfg80211: fix BSS RB tree collision during channel switch syzbot
2026-08-05 20:31 ` Slawomir Stepien [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=anOdjR9mr7DumC6y@nr200 \
--to=sst@poczta.fm \
--cc=syzbot@kernel.org \
--cc=syzbot@lists.linux.dev \
--cc=syzkaller-upstream-moderation@googlegroups.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.