mirror of
https://github.com/torvalds/linux.git
synced 2026-10-08 03:26:02 +02:00
wifi: mac80211: avoid out-of-bounds read for empty PREQ elements
ieee80211_mesh_preq_size_ok() derives the location of the PREQ bottom
fields before checking whether the element contains even the fixed
header. ieee80211_mesh_hwmp_preq_get_bottom() reads the flags byte to
account for the optional Address Extension field. Consequently, an
empty PREQ element causes a one-byte read beyond its declared payload.
Move the helper call after both size checks, so the bottom fields are
only accessed when they are present.
Fixes: 8b40b1d24a ("wifi: mac80211: Fix overread in PREQ frame processing")
Cc: stable@vger.kernel.org
Signed-off-by: Ivan Pustogarov <ivan@ipust.net>
Link: https://patch.msgid.link/20260903152616.1646637-1-ivan@ipust.net
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
This commit is contained in:
parent
af72b5946d
commit
e6031f0226
|
|
@ -361,8 +361,7 @@ ieee80211_mesh_hwmp_perr_get_rcode(const u8 *ie, u8 dst_idx)
|
|||
/* IEEE Std 802.11-2016 9.4.2.113 PREQ element */
|
||||
static inline bool ieee80211_mesh_preq_size_ok(const u8 *pos, u8 elen)
|
||||
{
|
||||
struct ieee80211_mesh_hwmp_preq_bottom *preq_elem_bottom =
|
||||
ieee80211_mesh_hwmp_preq_get_bottom(pos);
|
||||
struct ieee80211_mesh_hwmp_preq_bottom *preq_elem_bottom;
|
||||
u8 target_count;
|
||||
int needed;
|
||||
|
||||
|
|
@ -378,6 +377,7 @@ static inline bool ieee80211_mesh_preq_size_ok(const u8 *pos, u8 elen)
|
|||
if (elen < needed)
|
||||
return false;
|
||||
|
||||
preq_elem_bottom = ieee80211_mesh_hwmp_preq_get_bottom(pos);
|
||||
target_count = preq_elem_bottom->target_count;
|
||||
/* IEEE Std 802.11-2016 Table 14-10 to 14-16 */
|
||||
if (target_count < 1)
|
||||
|
|
|
|||
Loading…
Reference in New Issue
Block a user