From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 6359B5187C2; Wed, 30 Sep 2026 17:22:34 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790788955; cv=none; b=lsRhzL8g7xFmQg4qTAn+zXKjjPGJSkgG5TIYwLeY+zlp2KNSKUn9w9hkMZIG/b8KVDusRjYnAfRAVgxNBFuawNmJrhtwJd6URVkkU7NT/vrA35ztoOJ8Q97PRoUbBjRJM9Zte3iEzGlKoycBHfzxoxUkFMim+Bd3Augo5TVHWm8= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790788955; c=relaxed/simple; bh=jYg6IGODlgVYcGSx6cA6qMbiiUEAH4GdQNA1M40CWNE=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=bmE9IcjMmXUxTtG8nnb67/sYmZOmxczaxxOfW371heM6Fwe5HkaPgvfbap3o7C9gYyJBRRSV4Q2Z03+OP80E04ax/32gngr6Tm9D3n+VFOflDuYFxGJyBWVtb41/+aRdZi1+t6q3c8zq1POAnEjXwrdYbT9DBxTNRrNoB2qn+CI= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=Z+jBhbii; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="Z+jBhbii" Received: by smtp.kernel.org (Postfix) with ESMTPSA id BCF881F000FF; Wed, 30 Sep 2026 17:22:33 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1790788954; bh=BN5an/PA5np1ZQ8c6Pn3hBvusam5qKeWr0VWMGz5wj0=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=Z+jBhbiiOQn7JxcLpxaj020FqvZOtrX3FYmVN5K4h1cwq1I2f6bJvEeyNZ1wge3bZ FPMfHfSX2ieyEi/OG5F7JXUxj2vzFw/w0pRayqFXTC3ehsoFkgcjphUbMoXraFNRFy 169imQtw2QAILBDpU8IS1sYNRbZFh1b8kNrrV1sw= From: Greg Kroah-Hartman To: stable@vger.kernel.org Cc: Greg Kroah-Hartman , patches@lists.linux.dev, Tianchu Chen , Johannes Berg Subject: [PATCH 6.12 262/877] wifi: rsi: fix heap OOB write on key removal Date: Wed, 30 Sep 2026 17:19:33 +0200 Message-ID: <20260930152420.376543460@linuxfoundation.org> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260930152414.738996857@linuxfoundation.org> References: <20260930152414.738996857@linuxfoundation.org> User-Agent: quilt/0.69 X-stable: review X-Patchwork-Hint: ignore Precedence: bulk X-Mailing-List: patches@lists.linux.dev List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit 6.12-stable review patch. If anyone has any objections, please let me know. ------------------ From: Tianchu Chen commit e6c5ed7a98d7bc8b0f7918246f1c90ddb3f79dfa upstream. When a key is removed (data == NULL), rsi_hal_load_key() runs: memset(&set_key[FRAME_DESC_SZ], 0, frame_len - FRAME_DESC_SZ); set_key is a struct rsi_set_key *, so the subscript is scaled by sizeof(struct rsi_set_key) (160 bytes): &set_key[FRAME_DESC_SZ] is skb->data + 2560, and the memset writes 144 zero bytes starting 2.4KB past the end of the 160-byte skb data buffer, corrupting unrelated heap objects. The intended byte offset would have been (u8 *)set_key + FRAME_DESC_SZ. The write fires on every DISABLE_KEY callback, so plain disconnects, roams and interface teardowns trigger it on real networks. The memset is redundant: the whole buffer is zeroed right after allocation, so the frame sent to the device is byte-identical without it. Drop the else branch; normal operation is unaffected. Discovered by Atuin - Automated Vulnerability Discovery Engine. Fixes: dad0d04fa7ba ("rsi: Add RS9113 wireless driver") Cc: stable@vger.kernel.org Assisted-by: LLM Signed-off-by: Tianchu Chen Link: https://patch.msgid.link/90bb2b07007942064c04aa3729cedd9eb1e930b1@linux.dev Signed-off-by: Johannes Berg Signed-off-by: Greg Kroah-Hartman --- drivers/net/wireless/rsi/rsi_91x_mgmt.c | 2 -- 1 file changed, 2 deletions(-) --- a/drivers/net/wireless/rsi/rsi_91x_mgmt.c +++ b/drivers/net/wireless/rsi/rsi_91x_mgmt.c @@ -852,8 +852,6 @@ int rsi_hal_load_key(struct rsi_common * memcpy(set_key->tx_mic_key, &data[16], 8); memcpy(set_key->rx_mic_key, &data[24], 8); } - } else { - memset(&set_key[FRAME_DESC_SZ], 0, frame_len - FRAME_DESC_SZ); } skb_put(skb, frame_len);