wifi: libertas: reject short monitor TX frames

In monitor mode, lbs_hard_start_xmit() casts skb->data to a
radiotap TX header, skips that header, and then copies the 802.11
destination address from offset 4 in the remaining frame.  The
generic length check only rejects zero-length and oversized skbs, so
a short monitor frame can be read past the end of the skb data.

Require enough bytes for the radiotap TX header and the destination
address field before using the monitor-mode header layout.

Signed-off-by: Pengpeng Hou <pengpeng@iscas.ac.cn>
Link: https://patch.msgid.link/20260704011140.37639-1-pengpeng@iscas.ac.cn
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
This commit is contained in:
Pengpeng Hou 2026-07-04 09:11:40 +08:00 committed by Johannes Berg
parent 0a2581cbae
commit 13ff543e0b

View File

@ -117,6 +117,13 @@ netdev_tx_t lbs_hard_start_xmit(struct sk_buff *skb, struct net_device *dev)
if (priv->wdev->iftype == NL80211_IFTYPE_MONITOR) {
struct tx_radiotap_hdr *rtap_hdr = (void *)skb->data;
if (skb->len < sizeof(*rtap_hdr) + 4 + ETH_ALEN) {
lbs_deb_tx("tx err: short monitor frame %u\n", skb->len);
dev->stats.tx_dropped++;
dev->stats.tx_errors++;
goto free;
}
/* set txpd fields from the radiotap header */
txpd->tx_control = cpu_to_le32(convert_radiotap_rate_to_mv(rtap_hdr->rate));