linux-wireless.vger.kernel.org archive mirror
 help / color / mirror / Atom feed
* [PATCH 0/3] wifi: cap a few SSID lengths
@ 2025-08-29 12:48 Dan Carpenter
  2025-08-29 12:48 ` [PATCH 1/3] wifi: cw1200: cap SSID length in cw1200_do_join() Dan Carpenter
                   ` (2 more replies)
  0 siblings, 3 replies; 4+ messages in thread
From: Dan Carpenter @ 2025-08-29 12:48 UTC (permalink / raw)
  To: Marc Bornand
  Cc: Bjorn Helgaas, Felix Fietkau, Johannes Berg, Johannes Berg,
	John W. Linville, libertas-dev, linux-kernel, linux-wireless,
	Roopni Devanathan, Solomon Peachy

These patches are based on static analysis and review.  The other places
which get the ssid from ieee80211_bss_get_ie() do bounds checking to
ensure that the ssid length isn't more than IEEE80211_MAX_SSID_LEN (32).

Dan Carpenter (3):
  wifi: cw1200: cap SSID length in cw1200_do_join()
  wifi: libertas: cap SSID len in lbs_associate()
  wifi: cfg80211: sme: capp SSID length in __cfg80211_connect_result()

 drivers/net/wireless/marvell/libertas/cfg.c | 9 ++++++---
 drivers/net/wireless/st/cw1200/sta.c        | 2 +-
 net/wireless/sme.c                          | 5 ++++-
 3 files changed, 11 insertions(+), 5 deletions(-)

-- 
2.47.2


^ permalink raw reply	[flat|nested] 4+ messages in thread

* [PATCH 1/3] wifi: cw1200: cap SSID length in cw1200_do_join()
  2025-08-29 12:48 [PATCH 0/3] wifi: cap a few SSID lengths Dan Carpenter
@ 2025-08-29 12:48 ` Dan Carpenter
  2025-08-29 12:48 ` [PATCH 2/3] wifi: libertas: cap SSID len in lbs_associate() Dan Carpenter
  2025-08-29 12:48 ` [PATCH 3/3] wifi: cfg80211: sme: capp SSID length in __cfg80211_connect_result() Dan Carpenter
  2 siblings, 0 replies; 4+ messages in thread
From: Dan Carpenter @ 2025-08-29 12:48 UTC (permalink / raw)
  To: Solomon Peachy
  Cc: Thomas Gleixner, Ingo Molnar, Johannes Berg, Roopni Devanathan,
	John W. Linville, linux-wireless, linux-kernel

If the ssidie[1] length is more that 32 it leads to memory corruption.

Fixes: a910e4a94f69 ("cw1200: add driver for the ST-E CW1100 & CW1200 WLAN chipsets")
Signed-off-by: Dan Carpenter <dan.carpenter@linaro.org>
---
 drivers/net/wireless/st/cw1200/sta.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/net/wireless/st/cw1200/sta.c b/drivers/net/wireless/st/cw1200/sta.c
index b1dd76e8aecb..5d8eaa700779 100644
--- a/drivers/net/wireless/st/cw1200/sta.c
+++ b/drivers/net/wireless/st/cw1200/sta.c
@@ -1291,7 +1291,7 @@ static void cw1200_do_join(struct cw1200_common *priv)
 		rcu_read_lock();
 		ssidie = ieee80211_bss_get_ie(bss, WLAN_EID_SSID);
 		if (ssidie) {
-			join.ssid_len = ssidie[1];
+			join.ssid_len = min(ssidie[1], IEEE80211_MAX_SSID_LEN);
 			memcpy(join.ssid, &ssidie[2], join.ssid_len);
 		}
 		rcu_read_unlock();
-- 
2.47.2


^ permalink raw reply related	[flat|nested] 4+ messages in thread

* [PATCH 2/3] wifi: libertas: cap SSID len in lbs_associate()
  2025-08-29 12:48 [PATCH 0/3] wifi: cap a few SSID lengths Dan Carpenter
  2025-08-29 12:48 ` [PATCH 1/3] wifi: cw1200: cap SSID length in cw1200_do_join() Dan Carpenter
@ 2025-08-29 12:48 ` Dan Carpenter
  2025-08-29 12:48 ` [PATCH 3/3] wifi: cfg80211: sme: capp SSID length in __cfg80211_connect_result() Dan Carpenter
  2 siblings, 0 replies; 4+ messages in thread
From: Dan Carpenter @ 2025-08-29 12:48 UTC (permalink / raw)
  To: Solomon Peachy
  Cc: Johannes Berg, Felix Fietkau, Bjorn Helgaas, Al Viro,
	John W. Linville, linux-wireless, libertas-dev, linux-kernel

If the ssid_eid[1] length is more that 32 it leads to memory corruption.

Fixes: a910e4a94f69 ("cw1200: add driver for the ST-E CW1100 & CW1200 WLAN chipsets")
Signed-off-by: Dan Carpenter <dan.carpenter@linaro.org>
---
 drivers/net/wireless/marvell/libertas/cfg.c | 9 ++++++---
 1 file changed, 6 insertions(+), 3 deletions(-)

diff --git a/drivers/net/wireless/marvell/libertas/cfg.c b/drivers/net/wireless/marvell/libertas/cfg.c
index 94dd488becaf..caba7491cd5a 100644
--- a/drivers/net/wireless/marvell/libertas/cfg.c
+++ b/drivers/net/wireless/marvell/libertas/cfg.c
@@ -1151,10 +1151,13 @@ static int lbs_associate(struct lbs_private *priv,
 	/* add SSID TLV */
 	rcu_read_lock();
 	ssid_eid = ieee80211_bss_get_ie(bss, WLAN_EID_SSID);
-	if (ssid_eid)
-		pos += lbs_add_ssid_tlv(pos, ssid_eid + 2, ssid_eid[1]);
-	else
+	if (ssid_eid) {
+		u32 ssid_len = min(ssid_eid[1], IEEE80211_MAX_SSID_LEN);
+
+		pos += lbs_add_ssid_tlv(pos, ssid_eid + 2, ssid_len);
+	} else {
 		lbs_deb_assoc("no SSID\n");
+	}
 	rcu_read_unlock();
 
 	/* add DS param TLV */
-- 
2.47.2


^ permalink raw reply related	[flat|nested] 4+ messages in thread

* [PATCH 3/3] wifi: cfg80211: sme: capp SSID length in __cfg80211_connect_result()
  2025-08-29 12:48 [PATCH 0/3] wifi: cap a few SSID lengths Dan Carpenter
  2025-08-29 12:48 ` [PATCH 1/3] wifi: cw1200: cap SSID length in cw1200_do_join() Dan Carpenter
  2025-08-29 12:48 ` [PATCH 2/3] wifi: libertas: cap SSID len in lbs_associate() Dan Carpenter
@ 2025-08-29 12:48 ` Dan Carpenter
  2 siblings, 0 replies; 4+ messages in thread
From: Dan Carpenter @ 2025-08-29 12:48 UTC (permalink / raw)
  To: Marc Bornand; +Cc: Johannes Berg, linux-wireless, linux-kernel

If the ssid->datalen is more than IEEE80211_MAX_SSID_LEN (32) it would
lead to memory corruption so add some bounds checking.

Fixes: c38c70185101 ("wifi: cfg80211: Set SSID if it is not already set")
Signed-off-by: Dan Carpenter <dan.carpenter@linaro.org>
---
 net/wireless/sme.c | 5 ++++-
 1 file changed, 4 insertions(+), 1 deletion(-)

diff --git a/net/wireless/sme.c b/net/wireless/sme.c
index 826ec0a6355f..3a028ff287fb 100644
--- a/net/wireless/sme.c
+++ b/net/wireless/sme.c
@@ -900,13 +900,16 @@ void __cfg80211_connect_result(struct net_device *dev,
 	if (!wdev->u.client.ssid_len) {
 		rcu_read_lock();
 		for_each_valid_link(cr, link) {
+			u32 ssid_len;
+
 			ssid = ieee80211_bss_get_elem(cr->links[link].bss,
 						      WLAN_EID_SSID);
 
 			if (!ssid || !ssid->datalen)
 				continue;
 
-			memcpy(wdev->u.client.ssid, ssid->data, ssid->datalen);
+			ssid_len = min(ssid->datalen, IEEE80211_MAX_SSID_LEN);
+			memcpy(wdev->u.client.ssid, ssid->data, ssid_len);
 			wdev->u.client.ssid_len = ssid->datalen;
 			break;
 		}
-- 
2.47.2


^ permalink raw reply related	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2025-08-29 12:48 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2025-08-29 12:48 [PATCH 0/3] wifi: cap a few SSID lengths Dan Carpenter
2025-08-29 12:48 ` [PATCH 1/3] wifi: cw1200: cap SSID length in cw1200_do_join() Dan Carpenter
2025-08-29 12:48 ` [PATCH 2/3] wifi: libertas: cap SSID len in lbs_associate() Dan Carpenter
2025-08-29 12:48 ` [PATCH 3/3] wifi: cfg80211: sme: capp SSID length in __cfg80211_connect_result() Dan Carpenter

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).