From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id D489B53ECFC; Wed, 23 Sep 2026 14:51:55 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790175117; cv=none; b=qYgoiUDajVYiEGtKLA4KnN6wHwB7+9t17CzJDl/X8CmUfryL5xZz7VdNGtgerzri8WIJe7Yje+GpuBGHRETHK1MOmpAVL3sxzMjdA0PJHAUsTVQBXanLqOUAcMXNCZzcQTuSGeYtcqzHFCOIXrGkLidfgOC2itAJVhp4hv7Wjf4= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790175117; c=relaxed/simple; bh=MwSvzIJxYb57wHv+nlELhiGwQFvUDCrho/+ckXp/uSg=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=HNxhicAh9jQsNcz8rl+bMxTEl38iwREXNn/KINEsQ5g1yfNslROdsNNG8K+hdgciu8juhMY2VuzkMCBWHOey7pOdiC7L6V9LJSloEfi+Pn9h2IfEuCt77Rers2VMgSDhWyv8xD6d8CJ3cWFK474kAwO120EEYT4Zn6OxAO9Tujg= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=r6kwB/em; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="r6kwB/em" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 0292E1F000FF; Wed, 23 Sep 2026 14:51:54 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1790175115; bh=39nMrpfooJry8qYcZH3zflDKHDic+mmcNUmXr4ZMCbY=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=r6kwB/em1zCqL5WcfAfe2reCMUsBSpXbnRsWS09y30jPI85CoqNSuJo0LJ0Gt/Eoy hAyWN5ueIDyIRcCyDABUGyzm3B260POODXB44e7FrvA6awoEbVwi6hCF0x80569W4X pu4W/qgRsASwRETj+UGvWAELwRbDzbIleNgNlu9w= From: Greg Kroah-Hartman To: stable@vger.kernel.org Cc: Greg Kroah-Hartman , patches@lists.linux.dev, Tianchu Chen , Johannes Berg Subject: [PATCH 6.18 326/398] wifi: rsi: fix heap OOB write on key removal Date: Wed, 23 Sep 2026 16:06:40 +0200 Message-ID: <20260923140651.873208519@linuxfoundation.org> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260923140643.441954610@linuxfoundation.org> References: <20260923140643.441954610@linuxfoundation.org> User-Agent: quilt/0.69 X-stable: review X-Patchwork-Hint: ignore Precedence: bulk X-Mailing-List: patches@lists.linux.dev List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit 6.18-stable review patch. If anyone has any objections, please let me know. ------------------ From: Tianchu Chen commit e6c5ed7a98d7bc8b0f7918246f1c90ddb3f79dfa upstream. When a key is removed (data == NULL), rsi_hal_load_key() runs: memset(&set_key[FRAME_DESC_SZ], 0, frame_len - FRAME_DESC_SZ); set_key is a struct rsi_set_key *, so the subscript is scaled by sizeof(struct rsi_set_key) (160 bytes): &set_key[FRAME_DESC_SZ] is skb->data + 2560, and the memset writes 144 zero bytes starting 2.4KB past the end of the 160-byte skb data buffer, corrupting unrelated heap objects. The intended byte offset would have been (u8 *)set_key + FRAME_DESC_SZ. The write fires on every DISABLE_KEY callback, so plain disconnects, roams and interface teardowns trigger it on real networks. The memset is redundant: the whole buffer is zeroed right after allocation, so the frame sent to the device is byte-identical without it. Drop the else branch; normal operation is unaffected. Discovered by Atuin - Automated Vulnerability Discovery Engine. Fixes: dad0d04fa7ba ("rsi: Add RS9113 wireless driver") Cc: stable@vger.kernel.org Assisted-by: LLM Signed-off-by: Tianchu Chen Link: https://patch.msgid.link/90bb2b07007942064c04aa3729cedd9eb1e930b1@linux.dev Signed-off-by: Johannes Berg Signed-off-by: Greg Kroah-Hartman --- drivers/net/wireless/rsi/rsi_91x_mgmt.c | 2 -- 1 file changed, 2 deletions(-) --- a/drivers/net/wireless/rsi/rsi_91x_mgmt.c +++ b/drivers/net/wireless/rsi/rsi_91x_mgmt.c @@ -852,8 +852,6 @@ int rsi_hal_load_key(struct rsi_common * memcpy(set_key->tx_mic_key, &data[16], 8); memcpy(set_key->rx_mic_key, &data[24], 8); } - } else { - memset(&set_key[FRAME_DESC_SZ], 0, frame_len - FRAME_DESC_SZ); } skb_put(skb, frame_len);