From nobody Sat Jul 25 20:47:01 2026 Received: from mail-wr1-f47.google.com (mail-wr1-f47.google.com [209.85.221.47]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id E6F2C1E5714 for ; Mon, 13 Jul 2026 21:32:56 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.221.47 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783978378; cv=none; b=BgDvUrIoS2QwvRprpVIovWWR6exxkZqdmb+52BIoUAb8Hx4F5IFRVyKUDfUVQBlT4+Ae7cbwa+eErY2HaebzwozrDXDYKV7t7Mxo5yfhw6toPFocuDX1MsilAgSGG3DjA/5ksqWFwMGVfKBsrNjDuAo/3qwJHChPxLzO9Ydx+dQ= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783978378; c=relaxed/simple; bh=KPNRNFZEJ2UjwZa0agq4MDAlQLgIYnxwb+Izb8tPesk=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=pALvwMoY+WHq36P7qod3TQeIjWSHmEdNujMXboMyKeNLKGpY/2oKwApcVZRTedSFPLYfPInj77ZGbXvWW6NipY/TdRUHIjjCp6tNZdAYi+LWTQfEvp81VLvdx+CWB4lKgnvyfEqrp0V+Dz3S0RJhH8sh7NOidBxY888E3+RPlk4= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=0sec.ai; spf=pass smtp.mailfrom=0sec.ai; dkim=temperror (0-bit key) header.d=0sec.ai header.i=@0sec.ai header.b=eJdfJXem; arc=none smtp.client-ip=209.85.221.47 Authentication-Results: smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=0sec.ai Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=0sec.ai Authentication-Results: smtp.subspace.kernel.org; dkim=temperror (0-bit key) header.d=0sec.ai header.i=@0sec.ai header.b="eJdfJXem" Received: by mail-wr1-f47.google.com with SMTP id ffacd0b85a97d-476a130c138so317730f8f.0 for ; Mon, 13 Jul 2026 14:32:56 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=0sec.ai; s=google; t=1783978375; x=1784583175; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=6rdaRIl05xXqbdOzxCjD1XxZpsLBKNtHk20piNYF/bM=; b=eJdfJXemqur2+0Qxv/hz86ypC/5EG3h/kqqYdFbL78/YQyiq65aglMOSDx/GWIV+z9 GtNnROs5lLDY7ILbVCB47eedcrvVVYlQhinW+D42JULJiITszOIe3XYhOAVASaHN2YOg b35PQNXloY4ik8KMSqwS4jgw6HEZdoIdStw9WaOzPcFPC1yRop7A6MEcjPYp0F3IFw1S X6kZMI/cLjNA2hQQOKVmVw5Mq7FiJijGvZpm8+PVhfEWjtZNIlCBE6/XnGgF9gamoE2j m0vOImNdSyc75gjCUPD+E/2Vw7kmAiiJ7P/80dUGFlwnRBvyq7cHgDTAzQEFcS62QihA inlw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1783978375; x=1784583175; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=6rdaRIl05xXqbdOzxCjD1XxZpsLBKNtHk20piNYF/bM=; b=rpvffz38LFfhTuQRxKEnTmX0aLcbB2Bxu7WjE+v1M0XD/GUMj/rMe4fq70crt9yWzv z2j2+1pGIg7y/HmaT17Sr2IPdRA0nO6mW3S9cq+QAYp1B+ryFlfOuKcYEGn9DO1p9wdP V1nLm+yckFC1iXSy0bMkUY7YW2mb+xUcEjGZfgQHvOTnbevpeC2MCoPOE0NcSIvPT4qg +gJzP7w3olbO49SzyTFx0q6hOwrSQy/zQ6mbvkInOW7KpZO3qyY01baBsDbeUBJvWkde 6UR0Uqme8twgk1CsD7HdPbosUY7n55SJDdt2T82czXO0xHF14bh21fiuX1Mc5wJVw1y4 IW3A== X-Forwarded-Encrypted: i=1; AHgh+Rpwceojmo4EWayh8K1uuBsn9YPOduE4N2Xg+Ub49mKENyWb4+m68wD9q1JuGVHK3FkYPoaYDxhK60WpztM=@vger.kernel.org X-Gm-Message-State: AOJu0Yx9Nzrw4j0o6XSaZ3hQEFvVG2ILRfiU0Al097pp3L9rcBwkU7oY MFUb8fNjy3AODXub6Gohj+4fFricev0GF5uHIpuo3ndhlsZ27JiC7QMVnRKdNa8YDG7xc+xVT3l S2O0vSuc9 X-Gm-Gg: AfdE7cnZ/2zSBJCubUBCl0IK3AIgy9O5X/ktsfDse8gNZM8UKR3nkzNozRxnyFfsfb/ NpEgaXessc1bM7WdQbxM/8CV1QncvEOU+m0ked4WYVM/6xe9YHYd/q6McIv/A/qP0qC4udfx7mi AwyZwEkWSfIOTz7tRaUBt2YFX38fVjaCg502gxQ7CuIiIZ0iyCdmIS5kgcUtHVx0haf3MZQlfRV qcVSw2o3mohfonS5sr/vXwdUH+4OG4RY3RcaqnG09GMKs9zzL+wpxPvECprYSvyIvEn+okUMxNA 3tc6JER+pbw4bwaAW3byLwFBL5X8uco6Y8Ajk1xKg6jEmSM86q5kTChkD4QYqE0o9AMm4350+3z j3sX803gZ6UQKz9EwbLRAlvvaKnQS1TgMHTN1b4iqDecLhldB++jtvveVenU0Lb0SxDBcmW6G2B bUB1pYyWAxaa2rqdabXyudf64g9hqavUHthZzl59p2fAruXFsCAwu0Gwlj9OvDd9uKHx9MjL8AJ sBpT0rAlVcLg4OeFucfhYhoWsTfw+rpcK0= X-Received: by 2002:a05:600c:3acf:b0:493:f176:dc69 with SMTP id 5b1f17b1804b1-493f884f5f2mr104527375e9.37.1783978375216; Mon, 13 Jul 2026 14:32:55 -0700 (PDT) Received: from PeakBook-Mini.tail8e484.ts.net ([178.197.218.188]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49508724786sm25938115e9.3.2026.07.13.14.32.53 (version=TLS1_3 cipher=TLS_CHACHA20_POLY1305_SHA256 bits=256/256); Mon, 13 Jul 2026 14:32:54 -0700 (PDT) From: Doruk Tan Ozturk To: Jeff Johnson , linux-wireless@vger.kernel.org Cc: Johannes Berg , Peddolla Harshavardhan Reddy , linux-kernel@vger.kernel.org, stable@vger.kernel.org Subject: [PATCH] wifi: ath6kl: clamp assoc request/response lengths before subtracting IE offsets Date: Mon, 13 Jul 2026 23:32:51 +0200 Message-ID: <20260713213251.21161-1-doruk@0sec.ai> X-Mailer: git-send-email 2.53.0 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" ath6kl_cfg80211_connect_event() subtracts fixed IE offsets from assoc_req_len (-=3D 4) and assoc_resp_len (-=3D 6), both u8, with no lower bound. The aggregate check recently added to ath6kl_wmi_connect_event_rx() bounds the declared lengths from above (their sum must fit the received event), but an assoc request/response shorter than its fixed offset still underflows here: the u8 wraps to ~250, and cfg80211_connect_result() / cfg80211_roamed() then treat that wrapped value as the IE length and copy that many bytes out of the small assoc_info buffer to user space via nl80211, disclosing adjacent slab memory. Clamp both lengths to their offsets before subtracting. Found by 0sec (https://0sec.ai) using automated source analysis; the missing lower bound is evident from source. Compile-tested. Fixes: bdcd81707973 ("Add ath6kl cleaned up driver") Cc: stable@vger.kernel.org Assisted-by: 0sec:claude-opus-4-8 Signed-off-by: Doruk Tan Ozturk --- drivers/net/wireless/ath/ath6kl/cfg80211.c | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/drivers/net/wireless/ath/ath6kl/cfg80211.c b/drivers/net/wirel= ess/ath/ath6kl/cfg80211.c index cc0f2c45fc3a..62f663c0daa2 100644 --- a/drivers/net/wireless/ath/ath6kl/cfg80211.c +++ b/drivers/net/wireless/ath/ath6kl/cfg80211.c @@ -754,6 +754,11 @@ void ath6kl_cfg80211_connect_event(struct ath6kl_vif *= vif, u16 channel, u8 *assoc_resp_ie =3D assoc_info + beacon_ie_len + assoc_req_len + assoc_resp_ie_offset; =20 + if (assoc_req_len < assoc_req_ie_offset) + assoc_req_len =3D assoc_req_ie_offset; + if (assoc_resp_len < assoc_resp_ie_offset) + assoc_resp_len =3D assoc_resp_ie_offset; + assoc_req_len -=3D assoc_req_ie_offset; assoc_resp_len -=3D assoc_resp_ie_offset; =20 --=20 2.43.0