Skip to content

Commit 240c8d2

Browse files
maoyixiejmberg-intel
authored andcommitted
wifi: brcmfmac: cyw: fix heap overflow on a short auth frame
brcmf_notify_auth_frame_rx() takes the frame length from the firmware event and copies the frame body with the management header offset subtracted: u32 mgmt_frame_len = e->datalen - sizeof(struct brcmf_rx_mgmt_data); ... memcpy(&mgmt_frame->u, frame, mgmt_frame_len - offsetof(struct ieee80211_mgmt, u)); The only length check is e->datalen >= sizeof(*rxframe), so mgmt_frame_len can be anything from 0 up. offsetof(struct ieee80211_mgmt, u) is 24. When mgmt_frame_len is below that, the subtraction wraps as an unsigned value to a huge length. The memcpy then runs far past the kzalloc'd buffer. A malicious or malfunctioning AP can make the frame short during the external SAE auth exchange, so this is a remotely triggered heap overflow. Reject frames shorter than the management header offset before the copy. Fixes: 66f9093 ("wifi: brcmfmac: cyw: support external SAE authentication in station mode") Link: https://lore.kernel.org/r/178214417708.2368577.16740907093694208834@maoyixie.com Cc: stable@vger.kernel.org Co-developed-by: Kaixuan Li <kaixuan.li@ntu.edu.sg> Signed-off-by: Kaixuan Li <kaixuan.li@ntu.edu.sg> Signed-off-by: Maoyi Xie <maoyixie.tju@gmail.com> Acked-by: Arend van Spriel <arend.vanspriel@broadcom.com> Link: https://patch.msgid.link/20260627131313.3878893-1-maoyixie.tju@gmail.com Signed-off-by: Johannes Berg <johannes.berg@intel.com>
1 parent 2a66594 commit 240c8d2

1 file changed

Lines changed: 6 additions & 0 deletions

File tree

  • drivers/net/wireless/broadcom/brcm80211/brcmfmac/cyw

drivers/net/wireless/broadcom/brcm80211/brcmfmac/cyw/core.c

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -293,6 +293,12 @@ brcmf_notify_auth_frame_rx(struct brcmf_if *ifp,
293293
return -EINVAL;
294294
}
295295

296+
if (mgmt_frame_len < offsetof(struct ieee80211_mgmt, u)) {
297+
bphy_err(drvr, "Event %s (%d) frame too small. Ignore\n",
298+
brcmf_fweh_event_name(e->event_code), e->event_code);
299+
return -EINVAL;
300+
}
301+
296302
wdev = &ifp->vif->wdev;
297303
WARN_ON(!wdev);
298304

0 commit comments

Comments
 (0)