Linux wireless drivers development
 help / color / mirror / Atom feed
* [PATCH] wifi: mwifiex: fix NULL dereference when the AP has HT-cap but no HT-oper
@ 2026-07-16 10:30 Doruk Tan Ozturk
  2026-07-20  7:05 ` Francesco Dolcini
  0 siblings, 1 reply; 2+ messages in thread
From: Doruk Tan Ozturk @ 2026-07-16 10:30 UTC (permalink / raw)
  To: briannorris; +Cc: francesco, linux-wireless, linux-kernel, stable

mwifiex_tdls_add_ht_oper() gates its follow-the-AP-bandwidth path on
bss_desc->bcn_ht_cap being present, but then dereferences a different
pointer, bss_desc->bcn_ht_oper:

	if (ISSUPP_CHANWIDTH40(priv->adapter->hw_dot_11n_dev_cap) &&
	    bss_desc->bcn_ht_cap &&
	    ISALLOWED_CHANWIDTH40(bss_desc->bcn_ht_oper->ht_param))

bcn_ht_cap and bcn_ht_oper are populated independently while parsing the
associated AP's beacon in mwifiex_update_bss_desc_with_ie(): an AP that
advertises an HT Capabilities element but no HT Operation element leaves
bcn_ht_cap non-NULL and bcn_ht_oper NULL. Setting up a TDLS link to a
peer while associated to such an AP then dereferences the NULL
bcn_ht_oper and crashes the kernel. Every other bcn_ht_oper user in the
driver NULL-checks it first.

Guard on the pointer that is actually dereferenced.

Found by 0sec automated security-research tooling (https://0sec.ai).

Fixes: 396939f94084 ("mwifiex: add HT operation IE in TDLS setup confirm")
Cc: stable@vger.kernel.org
Assisted-by: 0sec:multi-model
Signed-off-by: Doruk Tan Ozturk <doruk@0sec.ai>
---
 drivers/net/wireless/marvell/mwifiex/tdls.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/net/wireless/marvell/mwifiex/tdls.c b/drivers/net/wireless/marvell/mwifiex/tdls.c
index 845f2a22e071..c71ffe8399e4 100644
--- a/drivers/net/wireless/marvell/mwifiex/tdls.c
+++ b/drivers/net/wireless/marvell/mwifiex/tdls.c
@@ -215,7 +215,7 @@ mwifiex_tdls_add_ht_oper(struct mwifiex_private *priv, const u8 *mac,
 
 	/* follow AP's channel bandwidth */
 	if (ISSUPP_CHANWIDTH40(priv->adapter->hw_dot_11n_dev_cap) &&
-	    bss_desc->bcn_ht_cap &&
+	    bss_desc->bcn_ht_oper &&
 	    ISALLOWED_CHANWIDTH40(bss_desc->bcn_ht_oper->ht_param))
 		ht_oper->ht_param = bss_desc->bcn_ht_oper->ht_param;
 
-- 
2.43.0


^ permalink raw reply related	[flat|nested] 2+ messages in thread

* Re: [PATCH] wifi: mwifiex: fix NULL dereference when the AP has HT-cap but no HT-oper
  2026-07-16 10:30 [PATCH] wifi: mwifiex: fix NULL dereference when the AP has HT-cap but no HT-oper Doruk Tan Ozturk
@ 2026-07-20  7:05 ` Francesco Dolcini
  0 siblings, 0 replies; 2+ messages in thread
From: Francesco Dolcini @ 2026-07-20  7:05 UTC (permalink / raw)
  To: Doruk Tan Ozturk
  Cc: briannorris, francesco, linux-wireless, linux-kernel, stable

On Thu, Jul 16, 2026 at 12:30:42PM +0200, Doruk Tan Ozturk wrote:
> mwifiex_tdls_add_ht_oper() gates its follow-the-AP-bandwidth path on
> bss_desc->bcn_ht_cap being present, but then dereferences a different
> pointer, bss_desc->bcn_ht_oper:
> 
> 	if (ISSUPP_CHANWIDTH40(priv->adapter->hw_dot_11n_dev_cap) &&
> 	    bss_desc->bcn_ht_cap &&
> 	    ISALLOWED_CHANWIDTH40(bss_desc->bcn_ht_oper->ht_param))
> 
> bcn_ht_cap and bcn_ht_oper are populated independently while parsing the
> associated AP's beacon in mwifiex_update_bss_desc_with_ie(): an AP that
> advertises an HT Capabilities element but no HT Operation element leaves
> bcn_ht_cap non-NULL and bcn_ht_oper NULL. Setting up a TDLS link to a
> peer while associated to such an AP then dereferences the NULL
> bcn_ht_oper and crashes the kernel. Every other bcn_ht_oper user in the
> driver NULL-checks it first.
> 
> Guard on the pointer that is actually dereferenced.
> 
> Found by 0sec automated security-research tooling (https://0sec.ai).
> 
> Fixes: 396939f94084 ("mwifiex: add HT operation IE in TDLS setup confirm")
> Cc: stable@vger.kernel.org
> Assisted-by: 0sec:multi-model
> Signed-off-by: Doruk Tan Ozturk <doruk@0sec.ai>

Reviewed-by: Francesco Dolcini <francesco.dolcini@toradex.com>


^ permalink raw reply	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2026-07-20  7:05 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-07-16 10:30 [PATCH] wifi: mwifiex: fix NULL dereference when the AP has HT-cap but no HT-oper Doruk Tan Ozturk
2026-07-20  7:05 ` Francesco Dolcini

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox