mirror of
https://github.com/torvalds/linux.git
synced 2026-07-27 01:32:21 +02:00
wifi: mac80211_hwsim: reject undersized HWSIM_ATTR_TX_INFO
hwsim_tx_info_frame_received_nl() casts the HWSIM_ATTR_TX_INFO payload to a struct hwsim_tx_rate * and unconditionally reads IEEE80211_TX_MAX_RATES entries (8 bytes) from it. The policy only bounds the attribute from above (NLA_BINARY .len is a maximum) and the op sets GENL_DONT_VALIDATE_STRICT, so a short or zero-length attribute is accepted and the loop reads past the payload. Require the exact length in the policy, so a malformed attribute is rejected before the handler runs. Signed-off-by: Ibrahim Hashimov <security@auditcode.ai> Assisted-by: AuditCode-AI:2026.07 Link: https://patch.msgid.link/20260721115346.17236-1-security@auditcode.ai Signed-off-by: Johannes Berg <johannes.berg@intel.com>
This commit is contained in:
parent
43b25879f0
commit
3dc723ac78
|
|
@ -870,9 +870,9 @@ static const struct nla_policy hwsim_genl_policy[HWSIM_ATTR_MAX + 1] = {
|
|||
[HWSIM_ATTR_FLAGS] = { .type = NLA_U32 },
|
||||
[HWSIM_ATTR_RX_RATE] = { .type = NLA_U32 },
|
||||
[HWSIM_ATTR_SIGNAL] = { .type = NLA_U32 },
|
||||
[HWSIM_ATTR_TX_INFO] = { .type = NLA_BINARY,
|
||||
.len = IEEE80211_TX_MAX_RATES *
|
||||
sizeof(struct hwsim_tx_rate)},
|
||||
[HWSIM_ATTR_TX_INFO] =
|
||||
NLA_POLICY_EXACT_LEN(IEEE80211_TX_MAX_RATES *
|
||||
sizeof(struct hwsim_tx_rate)),
|
||||
[HWSIM_ATTR_COOKIE] = { .type = NLA_U64 },
|
||||
[HWSIM_ATTR_CHANNELS] = { .type = NLA_U32 },
|
||||
[HWSIM_ATTR_RADIO_ID] = { .type = NLA_U32 },
|
||||
|
|
|
|||
Loading…
Reference in New Issue
Block a user