mirror of
https://github.com/torvalds/linux.git
synced 2026-07-27 17:47:41 +02:00
hwsim_tx_info_frame_received_nl() casts the HWSIM_ATTR_TX_INFO payload to a struct hwsim_tx_rate * and unconditionally reads IEEE80211_TX_MAX_RATES entries (8 bytes) from it. The policy only bounds the attribute from above (NLA_BINARY .len is a maximum) and the op sets GENL_DONT_VALIDATE_STRICT, so a short or zero-length attribute is accepted and the loop reads past the payload. Require the exact length in the policy, so a malformed attribute is rejected before the handler runs. Signed-off-by: Ibrahim Hashimov <security@auditcode.ai> Assisted-by: AuditCode-AI:2026.07 Link: https://patch.msgid.link/20260721115346.17236-1-security@auditcode.ai Signed-off-by: Johannes Berg <johannes.berg@intel.com> |
||
|---|---|---|
| .. | ||
| Kconfig | ||
| mac80211_hwsim_i.h | ||
| mac80211_hwsim_main.c | ||
| mac80211_hwsim_nan.c | ||
| mac80211_hwsim_nan.h | ||
| mac80211_hwsim.h | ||
| Makefile | ||
| virt_wifi.c | ||