mirror of
https://github.com/torvalds/linux.git
synced 2026-09-23 05:04:02 +02:00
wifi: p54: require a full exp_if record in PDR_INTERFACE_LIST
The PDR_INTERFACE_LIST loop only checks that the record start is within
the entry before reading an entire struct exp_if from it. A truncated
trailing record makes the if_id/variant reads cross the entry boundary
into the heap beyond the EEPROM buffer (verified with a KASAN
reproducer of the loop). The variant also feeds the synth front-end
selection, so this is not only a leak.
Advance only while a full record still fits in the entry.
Fixes: eff1a59c48 ("[P54]: add mac80211-based driver for prism54 softmac hardware")
Cc: stable@vger.kernel.org
Acked-by: Christian Lamparter <chunkeey@gmail.com>
Assisted-by: GLM:5.3
Signed-off-by: Shengzhuo Wei <me@cherr.cc>
Link: https://patch.msgid.link/20260831-p54-pda-validation-v2-2-dae566b388c8@cherr.cc
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
This commit is contained in:
parent
ce858fa6b8
commit
d8efd84f49
|
|
@ -812,7 +812,8 @@ int p54_parse_eeprom(struct ieee80211_hw *dev, void *eeprom, int len)
|
|||
break;
|
||||
case PDR_INTERFACE_LIST:
|
||||
tmp = entry->data;
|
||||
while ((u8 *)tmp < entry->data + data_len) {
|
||||
while ((u8 *)tmp + sizeof(struct exp_if) <=
|
||||
entry->data + data_len) {
|
||||
struct exp_if *exp_if = tmp;
|
||||
if (exp_if->if_id == cpu_to_le16(IF_ID_ISL39000))
|
||||
synth = le16_to_cpu(exp_if->variant);
|
||||
|
|
|
|||
Loading…
Reference in New Issue
Block a user