wifi: mac80211: avoid out-of-bounds read for empty PREQ elements

ieee80211_mesh_preq_size_ok() derives the location of the PREQ bottom
fields before checking whether the element contains even the fixed
header. ieee80211_mesh_hwmp_preq_get_bottom() reads the flags byte to
account for the optional Address Extension field. Consequently, an
empty PREQ element causes a one-byte read beyond its declared payload.

Move the helper call after both size checks, so the bottom fields are
only accessed when they are present.

Fixes: 8b40b1d24a ("wifi: mac80211: Fix overread in PREQ frame processing")
Cc: stable@vger.kernel.org
Signed-off-by: Ivan Pustogarov <ivan@ipust.net>
Link: https://patch.msgid.link/20260903152616.1646637-1-ivan@ipust.net
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
This commit is contained in:
Ivan Pustogarov 2026-09-03 17:26:16 +02:00 committed by Johannes Berg
parent af72b5946d
commit e6031f0226

View File

@ -361,8 +361,7 @@ ieee80211_mesh_hwmp_perr_get_rcode(const u8 *ie, u8 dst_idx)
/* IEEE Std 802.11-2016 9.4.2.113 PREQ element */
static inline bool ieee80211_mesh_preq_size_ok(const u8 *pos, u8 elen)
{
struct ieee80211_mesh_hwmp_preq_bottom *preq_elem_bottom =
ieee80211_mesh_hwmp_preq_get_bottom(pos);
struct ieee80211_mesh_hwmp_preq_bottom *preq_elem_bottom;
u8 target_count;
int needed;
@ -378,6 +377,7 @@ static inline bool ieee80211_mesh_preq_size_ok(const u8 *pos, u8 elen)
if (elen < needed)
return false;
preq_elem_bottom = ieee80211_mesh_hwmp_preq_get_bottom(pos);
target_count = preq_elem_bottom->target_count;
/* IEEE Std 802.11-2016 Table 14-10 to 14-16 */
if (target_count < 1)