mirror of
https://github.com/torvalds/linux.git
synced 2026-09-14 16:10:02 +02:00
wifi: cfg80211: validate IEs in cfg80211_wext_siwgenie()
The KASAN allocation trace shows that a malformed IE buffer is stored via SIOCSIWGENIE (cfg80211_wext_siwgenie()) without any validation. The crash trace shows that a subsequent SIOCSIWESSID triggers a connection attempt which calls cfg80211_sme_get_conn_ies() to process the stored IE buffer, causing: - An out-of-bounds read in skip_ie() which reads ies[pos+1] (the length byte) past the end of the 1-byte buffer. - An integer underflow in the memcpy size argument when offs returned by ieee80211_ie_split() exceeds ies_len, causing unsigned subtraction to wrap to SIZE_MAX and triggering a fortify panic. Fix this by validating the IE buffer in cfg80211_wext_siwgenie() before storing it. Reported-by: syzbot+cc867e537e4bd36f69bb@syzkaller.appspotmail.com Closes: https://syzkaller.appspot.com/bug?extid=cc867e537e4bd36f69bb Signed-off-by: Deepanshu Kartikey <kartikey406@gmail.com> Link: https://patch.msgid.link/20260725142028.32560-1-kartikey406@gmail.com [drop unnecessary ie_len check, update commit message] Signed-off-by: Johannes Berg <johannes.berg@intel.com>
This commit is contained in:
parent
650a21e0bf
commit
a2f5286ca4
|
|
@ -319,6 +319,15 @@ int cfg80211_wext_siwgenie(struct net_device *dev,
|
|||
return 0;
|
||||
|
||||
if (ie_len) {
|
||||
const struct element *elem;
|
||||
|
||||
for_each_element(elem, extra, ie_len) {
|
||||
/* nothing */
|
||||
}
|
||||
|
||||
if (!for_each_element_completed(elem, extra, ie_len))
|
||||
return -EINVAL;
|
||||
|
||||
ie = kmemdup(extra, ie_len, GFP_KERNEL);
|
||||
if (!ie)
|
||||
return -ENOMEM;
|
||||
|
|
|
|||
Loading…
Reference in New Issue
Block a user