mirror of
https://github.com/torvalds/linux.git
synced 2026-07-27 01:32:21 +02:00
wifi: at76c50x-usb: avoid length underflow in at76_guess_freq()
at76_guess_freq() checks only that the received frame is at least a bare
802.11 header (24 bytes) before subtracting the fixed management-body
offset:
len -= el_off;
For both beacon and probe response frames, el_off is 36. If the frame is
shorter than el_off, subtracting it causes the calculated IE length to
wrap. The length is eventually passed to cfg80211_find_elem_match() as a
very large unsigned value, so the element walk runs beyond the RX skb.
This path is reached from at76_rx_tasklet() while scanning. If the device
delivers a truncated beacon or probe response, the oversized IE length
causes an out-of-bounds read during scanning.
Skip the IE lookup if the frame does not reach the variable elements,
before subtracting el_off.
Fixes: 1264b95146 ("at76c50x-usb: add driver")
Cc: stable@vger.kernel.org
Assisted-by: Claude:claude-opus-4-8
Signed-off-by: Huihui Huang <hhhuang@smu.edu.sg>
Link: https://patch.msgid.link/20260715140815.1242033-1-hhhuang@smu.edu.sg
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
This commit is contained in:
parent
f0858bfc7d
commit
61a799ffd1
|
|
@ -1521,13 +1521,16 @@ static inline int at76_guess_freq(struct at76_priv *priv)
|
|||
|
||||
if (ieee80211_is_probe_resp(hdr->frame_control)) {
|
||||
el_off = offsetof(struct ieee80211_mgmt, u.probe_resp.variable);
|
||||
el = ((struct ieee80211_mgmt *)hdr)->u.probe_resp.variable;
|
||||
} else if (ieee80211_is_beacon(hdr->frame_control)) {
|
||||
el_off = offsetof(struct ieee80211_mgmt, u.beacon.variable);
|
||||
el = ((struct ieee80211_mgmt *)hdr)->u.beacon.variable;
|
||||
} else {
|
||||
goto exit;
|
||||
}
|
||||
|
||||
if (len < el_off)
|
||||
goto exit;
|
||||
|
||||
el = priv->rx_skb->data + el_off;
|
||||
len -= el_off;
|
||||
|
||||
el = cfg80211_find_ie(WLAN_EID_DS_PARAMS, el, len);
|
||||
|
|
|
|||
Loading…
Reference in New Issue
Block a user