Linux wireless drivers development
 help / color / mirror / Atom feed
From: Ping-Ke Shih <pkshih@realtek.com>
To: <linux-wireless@vger.kernel.org>
Cc: <gary.chang@realtek.com>, <kevin_yang@realtek.com>
Subject: [PATCH rtw-next 2/3] wifi: rtw89: wow: check AOAC report C2H event length
Date: Wed, 23 Sep 2026 15:27:40 +0800	[thread overview]
Message-ID: <20260923072741.54118-3-pkshih@realtek.com> (raw)
In-Reply-To: <20260923072741.54118-1-pkshih@realtek.com>

From: Chih-Kang Chang <gary.chang@realtek.com>

The AOAC report C2H event contains fixed-size fields including GTK
and IGTK. The received C2H skb may contain less data than the expected
AOAC report size.

Check the skb length before processing the AOAC report to ensure the
complete report is available.

Signed-off-by: Chih-Kang Chang <gary.chang@realtek.com>
Signed-off-by: Ping-Ke Shih <pkshih@realtek.com>
---
 drivers/net/wireless/realtek/rtw89/mac.c | 8 ++++++++
 1 file changed, 8 insertions(+)

diff --git a/drivers/net/wireless/realtek/rtw89/mac.c b/drivers/net/wireless/realtek/rtw89/mac.c
index 093291e8854d..ad849e4b4a50 100644
--- a/drivers/net/wireless/realtek/rtw89/mac.c
+++ b/drivers/net/wireless/realtek/rtw89/mac.c
@@ -5897,6 +5897,13 @@ rtw89_mac_c2h_wow_aoac_rpt(struct rtw89_dev *rtwdev, struct sk_buff *skb, u32 le
 		(const struct rtw89_c2h_wow_aoac_report *)skb->data;
 	struct rtw89_completion_data data = {};
 
+	if (skb->len < sizeof(*c2h)) {
+		rtw89_warn(rtwdev, "wow: aoac rpt skb len %u is too short\n",
+			   skb->len);
+		data.err = true;
+		goto out;
+	}
+
 	aoac_rpt->rpt_ver = c2h->rpt_ver;
 	aoac_rpt->sec_type = c2h->sec_type;
 	aoac_rpt->key_idx = c2h->key_idx;
@@ -5913,6 +5920,7 @@ rtw89_mac_c2h_wow_aoac_rpt(struct rtw89_dev *rtwdev, struct sk_buff *skb, u32 le
 	aoac_rpt->igtk_ipn = le64_to_cpu(c2h->igtk_ipn);
 	memcpy(aoac_rpt->igtk, c2h->igtk, sizeof(aoac_rpt->igtk));
 
+out:
 	rtw89_complete_cond(wait, RTW89_WOW_WAIT_COND_AOAC, &data);
 }
 
-- 
2.25.1


  parent reply	other threads:[~2026-09-23  7:28 UTC|newest]

Thread overview: 5+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-23  7:27 [PATCH rtw-next 0/3] wifi: rtw89: add out-of-bound checking and reset map for hw_reconfig flow Ping-Ke Shih
2026-09-23  7:27 ` [PATCH rtw-next 1/3] wifi: rtw89: ser: reset map of associated links when L2 SER Ping-Ke Shih
2026-09-30  2:17   ` Ping-Ke Shih
2026-09-23  7:27 ` Ping-Ke Shih [this message]
2026-09-23  7:27 ` [PATCH rtw-next 3/3] wifi: rtw89: wow: check AOAC report key index Ping-Ke Shih

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260923072741.54118-3-pkshih@realtek.com \
    --to=pkshih@realtek.com \
    --cc=gary.chang@realtek.com \
    --cc=kevin_yang@realtek.com \
    --cc=linux-wireless@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox