mirror of
https://github.com/torvalds/linux.git
synced 2026-06-09 15:12:59 +02:00
ath10k: drop fragments with multicast DA for PCIe
commit 65c415a144 upstream.
Fragmentation is not used with multicast frames. Discard unexpected
fragments with multicast DA. This fixes CVE-2020-26145.
Tested-on: QCA6174 hw3.2 PCI WLAN.RM.4.4.1-00110-QCARMSWP-1
Cc: stable@vger.kernel.org
Signed-off-by: Wen Gong <wgong@codeaurora.org>
Signed-off-by: Jouni Malinen <jouni@codeaurora.org>
Link: https://lore.kernel.org/r/20210511200110.5a0bd289bda8.Idd6ebea20038fb1cfee6de924aa595e5647c9eae@changeid
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
This commit is contained in:
parent
c17b3e1ffc
commit
b1b3dcd653
|
|
@ -1768,6 +1768,16 @@ static u64 ath10k_htt_rx_h_get_pn(struct ath10k *ar, struct sk_buff *skb,
|
||||||
return pn;
|
return pn;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
static bool ath10k_htt_rx_h_frag_multicast_check(struct ath10k *ar,
|
||||||
|
struct sk_buff *skb,
|
||||||
|
u16 offset)
|
||||||
|
{
|
||||||
|
struct ieee80211_hdr *hdr;
|
||||||
|
|
||||||
|
hdr = (struct ieee80211_hdr *)(skb->data + offset);
|
||||||
|
return !is_multicast_ether_addr(hdr->addr1);
|
||||||
|
}
|
||||||
|
|
||||||
static bool ath10k_htt_rx_h_frag_pn_check(struct ath10k *ar,
|
static bool ath10k_htt_rx_h_frag_pn_check(struct ath10k *ar,
|
||||||
struct sk_buff *skb,
|
struct sk_buff *skb,
|
||||||
u16 peer_id,
|
u16 peer_id,
|
||||||
|
|
@ -1839,7 +1849,7 @@ static void ath10k_htt_rx_h_mpdu(struct ath10k *ar,
|
||||||
bool is_decrypted;
|
bool is_decrypted;
|
||||||
bool is_mgmt;
|
bool is_mgmt;
|
||||||
u32 attention;
|
u32 attention;
|
||||||
bool frag_pn_check = true;
|
bool frag_pn_check = true, multicast_check = true;
|
||||||
|
|
||||||
if (skb_queue_empty(amsdu))
|
if (skb_queue_empty(amsdu))
|
||||||
return;
|
return;
|
||||||
|
|
@ -1946,13 +1956,20 @@ static void ath10k_htt_rx_h_mpdu(struct ath10k *ar,
|
||||||
0,
|
0,
|
||||||
enctype);
|
enctype);
|
||||||
|
|
||||||
if (!frag_pn_check) {
|
if (frag)
|
||||||
/* Discard the fragment with invalid PN */
|
multicast_check = ath10k_htt_rx_h_frag_multicast_check(ar,
|
||||||
|
msdu,
|
||||||
|
0);
|
||||||
|
|
||||||
|
if (!frag_pn_check || !multicast_check) {
|
||||||
|
/* Discard the fragment with invalid PN or multicast DA
|
||||||
|
*/
|
||||||
temp = msdu->prev;
|
temp = msdu->prev;
|
||||||
__skb_unlink(msdu, amsdu);
|
__skb_unlink(msdu, amsdu);
|
||||||
dev_kfree_skb_any(msdu);
|
dev_kfree_skb_any(msdu);
|
||||||
msdu = temp;
|
msdu = temp;
|
||||||
frag_pn_check = true;
|
frag_pn_check = true;
|
||||||
|
multicast_check = true;
|
||||||
continue;
|
continue;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|
|
||||||
Loading…
Reference in New Issue
Block a user