From: Jiale Yao <yaojiale02@163.com>
To: Jeff Johnson <jjohnson@kernel.org>,
Baochen Qiang <quic_bqiang@quicinc.com>,
Vasanthakumar Thiagarajan
<vasanthakumar.thiagarajan@oss.qualcomm.com>,
linux-wireless@vger.kernel.org, ath12k@lists.infradead.org,
linux-kernel@vger.kernel.org
Cc: Jiale Yao <yaojiale02@163.com>, stable@vger.kernel.org
Subject: [PATCH] wifi: ath12k: validate MAC/PHY capability count before saving
Date: Fri, 25 Sep 2026 20:17:39 +0800 [thread overview]
Message-ID: <20260925121739.2061979-1-yaojiale02@163.com> (raw)
Firmware supplies the hardware mode count and the PHY bitmap for each
mode in the service-ready event. ath12k_wmi_save_all_mac_phy_info()
uses those bitmaps to advance through svc_ext_info->mac_phy_info, but the
destination is a fixed array of ATH12K_MAX_MAC_PHY_CAP elements.
If the total number of advertised PHY entries exceeds that limit, the
loop writes beyond mac_phy_info and corrupts adjacent memory. A mismatch
between the advertised total and the number of parsed capability TLVs can
also make the source pointer advance beyond its allocation.
Validate both counts before writing any entries and propagate the error to
the service-ready parser.
Fixes: 062ade23991e ("wifi: ath12k: parse and save hardware mode info from WMI_SERVICE_READY_EXT_EVENTID event for later use")
Cc: stable@vger.kernel.org
Signed-off-by: Jiale Yao <yaojiale02@163.com>
---
drivers/net/wireless/ath/ath12k/wmi.c | 22 ++++++++++++++++++++--
1 file changed, 20 insertions(+), 2 deletions(-)
diff --git a/drivers/net/wireless/ath/ath12k/wmi.c b/drivers/net/wireless/ath/ath12k/wmi.c
index d5160af60e00..59ac17f0d48d 100644
--- a/drivers/net/wireless/ath/ath12k/wmi.c
+++ b/drivers/net/wireless/ath/ath12k/wmi.c
@@ -5004,7 +5004,7 @@ ath12k_wmi_save_mac_phy_info(struct ath12k_base *ab,
__le32_to_cpu(mac_phy_cap->high_5ghz_chan_freq);
}
-static void
+static int
ath12k_wmi_save_all_mac_phy_info(struct ath12k_base *ab,
struct ath12k_wmi_svc_rdy_ext_parse *svc_rdy_ext)
{
@@ -5015,6 +5015,20 @@ ath12k_wmi_save_all_mac_phy_info(struct ath12k_base *ab,
u32 hw_mode_id, phy_bit_map;
u8 hw_idx;
+ if (svc_rdy_ext->tot_phy_id > ARRAY_SIZE(svc_ext_info->mac_phy_info)) {
+ ath12k_warn(ab, "too many PHY entries %u (max %zu)\n",
+ svc_rdy_ext->tot_phy_id,
+ ARRAY_SIZE(svc_ext_info->mac_phy_info));
+ return -EINVAL;
+ }
+
+ if (svc_rdy_ext->n_mac_phy_caps != svc_rdy_ext->tot_phy_id) {
+ ath12k_warn(ab, "invalid number of MAC/PHY caps %u, expected %u\n",
+ svc_rdy_ext->n_mac_phy_caps,
+ svc_rdy_ext->tot_phy_id);
+ return -EINVAL;
+ }
+
mac_phy_info = &svc_ext_info->mac_phy_info[0];
mac_phy_cap = svc_rdy_ext->mac_phy_caps;
@@ -5044,6 +5058,8 @@ ath12k_wmi_save_all_mac_phy_info(struct ath12k_base *ab,
phy_bit_map >>= 1;
}
}
+
+ return 0;
}
static int ath12k_wmi_svc_rdy_ext_parse(struct ath12k_base *ab,
@@ -5094,7 +5110,9 @@ static int ath12k_wmi_svc_rdy_ext_parse(struct ath12k_base *ab,
return ret;
}
- ath12k_wmi_save_all_mac_phy_info(ab, svc_rdy_ext);
+ ret = ath12k_wmi_save_all_mac_phy_info(ab, svc_rdy_ext);
+ if (ret)
+ return ret;
svc_rdy_ext->mac_phy_done = true;
} else if (!svc_rdy_ext->ext_hal_reg_done) {
--
2.34.1
next reply other threads:[~2026-09-25 12:18 UTC|newest]
Thread overview: 3+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-25 12:17 Jiale Yao [this message]
2026-09-29 3:32 ` [PATCH] wifi: ath12k: validate MAC/PHY capability count before saving Baochen Qiang
2026-10-03 10:22 ` jiale yao
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260925121739.2061979-1-yaojiale02@163.com \
--to=yaojiale02@163.com \
--cc=ath12k@lists.infradead.org \
--cc=jjohnson@kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-wireless@vger.kernel.org \
--cc=quic_bqiang@quicinc.com \
--cc=stable@vger.kernel.org \
--cc=vasanthakumar.thiagarajan@oss.qualcomm.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox