.../net/wireless/mediatek/mt76/mt7925/mcu.c | 32 ++++++++++++++----- 1 file changed, 24 insertions(+), 8 deletions(-)
The CLC region is supplied by firmware, but the loader trusts the region
count and each record length. A malformed image can make the region table
pointer precede the firmware buffer, make the record loop fail to advance,
or index phy->clc past its end. Validate the table and record bounds
before dereferencing or copying.
Fixes: c948b5da6bbe ("wifi: mt76: mt7925: add Mediatek Wi-Fi7 driver for mt7925 chips")
Cc: stable@vger.kernel.org
Signed-off-by: Laxman Acharya Padhya <acharyalaxman8848@gmail.com>
---
.../net/wireless/mediatek/mt76/mt7925/mcu.c | 32 ++++++++++++++-----
1 file changed, 24 insertions(+), 8 deletions(-)
diff --git a/drivers/net/wireless/mediatek/mt76/mt7925/mcu.c b/drivers/net/wireless/mediatek/mt76/mt7925/mcu.c
index e94fa544ff20..76e30bf4ce0f 100644
--- a/drivers/net/wireless/mediatek/mt76/mt7925/mcu.c
+++ b/drivers/net/wireless/mediatek/mt76/mt7925/mcu.c
@@ -803,8 +803,9 @@ static int mt7925_load_clc(struct mt792x_dev *dev, const char *fw_name)
struct mt76_dev *mdev = &dev->mt76;
struct mt792x_phy *phy = &dev->phy;
const struct firmware *fw;
+ size_t clc_len, fw_data_len, len, offset = 0;
u8 *clc_base = NULL, hw_encap = 0;
- int ret, i, len, offset = 0;
+ int ret, i;
dev->phy.clc_chan_conf = 0xff;
dev->regd_user = false;
@@ -829,13 +830,21 @@ static int mt7925_load_clc(struct mt792x_dev *dev, const char *fw_name)
}
hdr = (const void *)(fw->data + fw->size - sizeof(*hdr));
+ if (hdr->n_region > (fw->size - sizeof(*hdr)) / sizeof(*region)) {
+ dev_err(mdev->dev, "Invalid firmware region table\n");
+ ret = -EINVAL;
+ goto out;
+ }
+ fw_data_len = fw->size - sizeof(*hdr) -
+ hdr->n_region * sizeof(*region);
+
for (i = 0; i < hdr->n_region; i++) {
region = (const void *)((const u8 *)hdr -
(hdr->n_region - i) * sizeof(*region));
len = le32_to_cpu(region->len);
/* check if we have valid buffer size */
- if (offset + len > fw->size) {
+ if (len > fw_data_len - offset) {
dev_err(mdev->dev, "Invalid firmware region\n");
ret = -EINVAL;
goto out;
@@ -852,11 +861,19 @@ static int mt7925_load_clc(struct mt792x_dev *dev, const char *fw_name)
if (!clc_base)
goto out;
- for (offset = 0; offset < len; offset += le32_to_cpu(clc->len)) {
- clc = (const struct mt7925_clc *)(clc_base + offset);
+ for (offset = 0; offset < len; offset += clc_len) {
+ if (len - offset < sizeof(*clc)) {
+ ret = -EINVAL;
+ goto out;
+ }
- if (clc->idx >= ARRAY_SIZE(phy->clc))
- break;
+ clc = (const struct mt7925_clc *)(clc_base + offset);
+ clc_len = le32_to_cpu(clc->len);
+ if (clc_len < sizeof(*clc) || clc_len > len - offset ||
+ clc->idx >= ARRAY_SIZE(phy->clc)) {
+ ret = -EINVAL;
+ goto out;
+ }
/* do not init buf again if chip reset triggered */
if (phy->clc[clc->idx])
@@ -869,8 +886,7 @@ static int mt7925_load_clc(struct mt792x_dev *dev, const char *fw_name)
continue;
phy->clc[clc->idx] = devm_kmemdup(mdev->dev, clc,
- le32_to_cpu(clc->len),
- GFP_KERNEL);
+ clc_len, GFP_KERNEL);
if (!phy->clc[clc->idx]) {
ret = -ENOMEM;
--
2.51.2
© 2016 - 2026 Red Hat, Inc.