From nobody Sat Jul 25 23:42:05 2026 Received: from mail-wr1-f52.google.com (mail-wr1-f52.google.com [209.85.221.52]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 62D29374E43 for ; Sat, 11 Jul 2026 07:13:40 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.221.52 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783754022; cv=none; b=VSMRKSlhkvZm3nkQYRI4Y+sc9TpvYJiT2CkP7aOjyZUz+20jLTKKlgF06Re5NQvfDdjzPmtfRAgbCFci6oalIyFQiAApMGYCNlfil69sfk7ArYN854UgdrYJ4hQltVkS+m04dGHmQ3mEQFmWm2/1jdTxXF/jw3WhNVNAF2iBU6o= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783754022; c=relaxed/simple; bh=nJ93PuRgfvyXeSbj+HoOEf3Bf82IWNnh7L9snO3pg2w=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=mQKvRyso72UeKnPGgCrWwkL1olI1lPIK6sh1xafOpVX95mOTUVcL85pgTCpo0+w/gj0H5TSrDgo7yd+1vNGdFhFaTtXtbvQ1K41VwGsNHZN8lf1D2EUY6lGa2//ALL+HYmEBqLn2VtR/K15JwJGQYc9MUjqnvzYzNV4m+3QNoO4= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=0sec.ai; spf=pass smtp.mailfrom=0sec.ai; dkim=temperror (0-bit key) header.d=0sec.ai header.i=@0sec.ai header.b=jR9qGL0c; arc=none smtp.client-ip=209.85.221.52 Authentication-Results: smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=0sec.ai Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=0sec.ai Authentication-Results: smtp.subspace.kernel.org; dkim=temperror (0-bit key) header.d=0sec.ai header.i=@0sec.ai header.b="jR9qGL0c" Received: by mail-wr1-f52.google.com with SMTP id ffacd0b85a97d-4720d22c94aso1394556f8f.1 for ; Sat, 11 Jul 2026 00:13:40 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=0sec.ai; s=google; t=1783754019; x=1784358819; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=SNHJSSzRo5FI9vf+enTbdejiXKeJlyuLQfvo17oWJAQ=; b=jR9qGL0cLL9OH8fZxX0l0ahGUrNlXFSzyPUN7DEBq2Tq42sRjZ+Ssf+tRy4SoxE09I 1lipBfJEfCizwGIOQCdXBfCGWtg2x2NX4iGCgFsxYj1eqnDl3/kPqHqSG26Vlzi2AjFc PVKQJ7JUULXgOWxcBlix09KC/BQ3zTX1ww5x9fmdWQEXmfC1XvghCyOJlADQbJx3x2P0 4FIILW8gLT6Bl5vFpwEukXZlCZzGzQ8LGT1R8A7R5LUXRF+eouCL7ykzNHUN8lfLyesm 2VGPTDsk/v7YTyK0vlEi1XQ6UKVG13o9d88YEpxsEZUXuMfHqxIbmAv0ItaN8u2+6RGF K4tw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1783754019; x=1784358819; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=SNHJSSzRo5FI9vf+enTbdejiXKeJlyuLQfvo17oWJAQ=; b=FtHtB1WUBhneuuCGwziL/fwo2YQOcS6rUt9/pQSp4DADplz34XV5xcpcTQ9AXofdrP oRESHCnj31pY+PReJOJuwaKrboVePxrO9YhQrYeD2k0OArsKQdgLEx7DUSftcRfNFdVy QLX/elpRgaT2aro+cXR/Cqh25ADDvoRS9MGj/JoE/cMBIo5ExjBd3iAV1cszKqoe4TRM AyH4Lh+UHVNSfvr8R5zSo6HqDPBeXXyq6gL9qm6guQ9br9xw9YPpmFP9zMx0gXVZ76rA 9nuXvKSYTWOFWZIqvKGMoKKGgyeyh8a8Tzb9HdntCmrFgiInSYpqtxSvX3wxzN2V/XrA UEOw== X-Forwarded-Encrypted: i=1; AHgh+Rr5TAW3nBrXhhZ1cHFPa5w+wm8UzWZSI18Y0eQTJnx6L53ZOv2GoeDsbVIpnd5prorkgs6I5bFCf38f5u0=@vger.kernel.org X-Gm-Message-State: AOJu0YwhKYtMiiSyIYz62u3IbvH9eKSqEZZdo6ZQkqQvkH1FpvbBq/r7 2xwjEo9Tj6b0Nfsw+XSbeo7FpvhrUxzgFkTMCeiWJB7fN0rte6Gs0gwmdrY9Q7uUtULs X-Gm-Gg: AfdE7cnec/4CieR1MrTiT2/9WVNaiwqUZi47E10vY8MzSe5mCRL6dMB2lv3BwXTKgVQ LW3QTygLAG13mC8kvjEyFaq55DunygJbxEvCxHsdsYXRW6dj8i5uhTABOwgasJL44AmgP4D7U6T DxgI/WJM8iBT6ti1EfB3RLn+q6ZnoZrnl366ckudbjCXNgx1iwqbTOnkVdbHylyer9KzEV9iygI OjGMbomEEeqPkrYfH8PaHJg0KJcxLij8LJe6aDz9gb19WqVc0dtWiLP8K3pPUSyB1NX9AhnoP7e 5/9Q8w/1Evd5YnDqON63ckV/ddvsUbmW0EeYt+SVg2XUpDbLMLa899Sp9AcHF7mhpyoXU6YdBka YFjKdC4mCfAdqvvP6H4oXUkUU0xIwGhvHoInYoqeUPC5HD3i+LVRJ6pvzIA9vJWEiplcCsvrTgQ 5lsTb0I+g9yinVOmZmiRxz9cu2R+YNhs44GHSCif1Ez6g9ou8yE8fx0eQZslwVbf6xXO2mSwrDF f3duyatcCZaAAOw+NgMc56XNOnUU4QOhMg= X-Received: by 2002:a5d:5c84:0:b0:474:9991:60d0 with SMTP id ffacd0b85a97d-47f2dcb60d3mr1985178f8f.12.1783754018793; Sat, 11 Jul 2026 00:13:38 -0700 (PDT) Received: from PeakBook-Mini.tail8e484.ts.net ([178.197.218.188]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-47aa0f21543sm61990120f8f.35.2026.07.11.00.13.37 (version=TLS1_3 cipher=TLS_CHACHA20_POLY1305_SHA256 bits=256/256); Sat, 11 Jul 2026 00:13:38 -0700 (PDT) From: Doruk Tan Ozturk To: linux-wireless@vger.kernel.org Cc: Johannes Berg , Peddolla Harshavardhan Reddy , linux-kernel@vger.kernel.org, stable@vger.kernel.org Subject: [PATCH] wifi: ath6kl: validate assoc info lengths in the WMI connect event Date: Sat, 11 Jul 2026 09:13:36 +0200 Message-ID: <20260711071336.58324-1-doruk@0sec.ai> X-Mailer: git-send-email 2.53.0 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" ath6kl_wmi_connect_event_rx() only checks that the received event is at least sizeof(struct wmi_connect_event); it never checks that the trailing beacon_ie_len + assoc_req_len + assoc_resp_len fields fit within the received buffer. Those attacker/AP-influenced lengths then drive two out-of-bounds accesses: - The WMM information-element scan builds peie =3D assoc_info + beacon_ie_len + assoc_req_len + assoc_resp_len and walks up to it, reading past the end of the event buffer when the declared lengths exceed the buffer. The walk also dereferences pie[1..6] and pie[1] (for the advance) without checking they stay within peie. - ath6kl_cfg80211_connect_event() subtracts fixed offsets from assoc_req_len (-=3D 4) and assoc_resp_len (-=3D 6), both u8, with no lo= wer bound. A short assoc request/response underflows the length to ~250, which cfg80211_connect_result() / cfg80211_roamed() then treat as the IE length and copy out of bounds from the small assoc_info buffer, disclosing adjacent slab memory to user space via nl80211. Bound the declared IE lengths against the received buffer, bound the WMM element reads against peie, and clamp the assoc request/response lengths before the subtraction. The sibling wil6210 driver already performs the equivalent length check for the same WMI connect event. Found by 0sec (https://0sec.ai) using automated source analysis; the missing bounds are evident from source and cross-checked against the sibling wil6210 driver. Compile-tested. Fixes: bdcd81707973 ("Add ath6kl cleaned up driver") Cc: stable@vger.kernel.org Assisted-by: 0sec:claude-opus-4-8 Signed-off-by: Doruk Tan Ozturk --- drivers/net/wireless/ath/ath6kl/cfg80211.c | 5 +++++ drivers/net/wireless/ath/ath6kl/wmi.c | 10 +++++++++- 2 files changed, 14 insertions(+), 1 deletion(-) diff --git a/drivers/net/wireless/ath/ath6kl/cfg80211.c b/drivers/net/wirel= ess/ath/ath6kl/cfg80211.c index cc0f2c45fc3a..62f663c0daa2 100644 --- a/drivers/net/wireless/ath/ath6kl/cfg80211.c +++ b/drivers/net/wireless/ath/ath6kl/cfg80211.c @@ -754,6 +754,11 @@ void ath6kl_cfg80211_connect_event(struct ath6kl_vif *= vif, u16 channel, u8 *assoc_resp_ie =3D assoc_info + beacon_ie_len + assoc_req_len + assoc_resp_ie_offset; =20 + if (assoc_req_len < assoc_req_ie_offset) + assoc_req_len =3D assoc_req_ie_offset; + if (assoc_resp_len < assoc_resp_ie_offset) + assoc_resp_len =3D assoc_resp_ie_offset; + assoc_req_len -=3D assoc_req_ie_offset; assoc_resp_len -=3D assoc_resp_ie_offset; =20 diff --git a/drivers/net/wireless/ath/ath6kl/wmi.c b/drivers/net/wireless/a= th/ath6kl/wmi.c index 72611a2ceb9d..fbfd74154d12 100644 --- a/drivers/net/wireless/ath/ath6kl/wmi.c +++ b/drivers/net/wireless/ath/ath6kl/wmi.c @@ -862,6 +862,10 @@ static int ath6kl_wmi_connect_event_rx(struct wmi *wmi= , u8 *datap, int len, =20 ev =3D (struct wmi_connect_event *) datap; =20 + if (len < sizeof(*ev) + ev->beacon_ie_len + ev->assoc_req_len + + ev->assoc_resp_len) + return -EINVAL; + if (vif->nw_type =3D=3D AP_NETWORK) { /* AP mode start/STA connected event */ struct net_device *dev =3D vif->ndev; @@ -913,7 +917,8 @@ static int ath6kl_wmi_connect_event_rx(struct wmi *wmi,= u8 *datap, int len, while (pie < peie) { switch (*pie) { case WLAN_EID_VENDOR_SPECIFIC: - if (pie[1] > 3 && pie[2] =3D=3D 0x00 && pie[3] =3D=3D 0x50 && + if (pie + 7 <=3D peie && pie[1] > 3 && + pie[2] =3D=3D 0x00 && pie[3] =3D=3D 0x50 && pie[4] =3D=3D 0xf2 && pie[5] =3D=3D WMM_OUI_TYPE) { /* WMM OUT (00:50:F2) */ if (pie[1] > 5 && @@ -926,6 +931,9 @@ static int ath6kl_wmi_connect_event_rx(struct wmi *wmi,= u8 *datap, int len, if (wmi->is_wmm_enabled) break; =20 + if (pie + 1 >=3D peie) + break; + pie +=3D pie[1] + 2; } =20 --=20 2.43.0