From nobody Fri Jul 24 22:17:34 2026 Received: from mail-pg1-f175.google.com (mail-pg1-f175.google.com [209.85.215.175]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 326E9470E96 for ; Thu, 23 Jul 2026 01:10:09 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.215.175 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784769010; cv=none; b=FOxd/pgoXC45Ftg5LgGcJYc8MczJuvK6l+aqJrEBsjPSPZgpQGhmWN1o71J6fXUnOJNpXiqbhCAgaAAV8gtIGO4K4r+qjyOwC/frnAYGCa1kI5/vYPsL30glWn8n9Q9Ya0BtQsjclk4xluF4Tnl9TsrDR2ADwJIzsesKcbGO7+8= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784769010; c=relaxed/simple; bh=Sy16K24qDpp7PICHqfmOrd5cZptXz9xLQaMlgu6spd0=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=lD7WQ3riynFclE15SBBNojVcnrreaH3P2MPdwfz3cLwo/zCGVUu1V+J89l1NZnaL+N57PmU2s7tom04l3EWRykLyh2vUzzIqnDBAtYmOtP+1Z8JKtrGrKYJuOahTdQO5ykLm7Ejj2G2JgytaAvur/EezD2ORhrX3MhWpYwoiUJA= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=PP9Lhz8i; arc=none smtp.client-ip=209.85.215.175 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="PP9Lhz8i" Received: by mail-pg1-f175.google.com with SMTP id 41be03b00d2f7-ca766c1c9ccso78638a12.0 for ; Wed, 22 Jul 2026 18:10:09 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1784769008; x=1785373808; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=XV45lch4j6NlWc5z+lGZFxIZUMUzY2iGbKyDWLWuSmI=; b=PP9Lhz8ieXDxBG0omPHhG0fLIyjVKthZ/OFugjeUbiF38mzlVmYTVEwiWbZGcgRnvN /dNJkuRQ63qNp2NYG/ZyvZh8oGghLbxcYqINCKUYSSVdsb/4zKEsVRhHbQ+msQJ2DrsW nqblEg5rpcArJMxd00uvyIRQAYSa4V1VTXX1NqULVKL7qzPz0V6eK8ajfH+iSsK2v5P2 1BWFsJnspJX4l9wLtwhpojDgvyRs7A3te69Y96Ui4Y5zliLqdmkBD4KnosncYOAtBD1T N2pQCiPraO5gtLxdxgI88Dmxkikl+fpKiq93T1WCpfYj3Jgc1AiRl2tW/KxU36meuR+y TElA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784769008; x=1785373808; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=XV45lch4j6NlWc5z+lGZFxIZUMUzY2iGbKyDWLWuSmI=; b=rCbtrMCqI86T0jc93mKIQtHDscePVdkYq+ndEboYL5UJkNeRfrrMyJkTqQi7Ghr2II +uH8N9TNqUBUN1KTyu2d5RLdK9/mxyzNSq2YYv+I8bf1GfDhZ/Ain66HhSLAXg1dO0c6 2JRJWmkcxbptTq8agt3Il7OBxh429r0inRa9MBvL1CFaKFyvN4ry6lpG8ErjxZD2A0Uu Eq4J73Q2tWan8HFEwWuibvxOOt05ylLYiK5UV5dFfXM25+pFRJcnuEByEg3sKhc2TvJ3 5EfRtb20PweZl5Js0NpAF6vlB85NZD1ff+TiIU2ofYILigs9SNQlhxHv9HBLM+6aHleQ VHUw== X-Forwarded-Encrypted: i=1; AHgh+Rp4KD7mBJPbSCRgHGx/+Y4FqbJVM0v1vCFht1pekPj00eJOgXVnMZTA0GygmVqMsNmVSJDJdeRmUAGK98M=@vger.kernel.org X-Gm-Message-State: AOJu0Ywm4MJywQgk1UECr0Njx/zd+eVopJmzxQyyG1OYmFQNrPYn640b mHulpSJ1LFquhg0MSDwbYXvivX1+czL1MY+/9FkJlS1n31TY+qy3kgyh X-Gm-Gg: AR+sD12LxU5VtF1CCJV3wgKIcW12ySw9wvK6Bbtf/TL9sOUC7E/fnLzPkweSUOAvKen iMNm1aue7t4WiigokHl+iL2AXir4agaEPey7eU9HEoI61YaDYC9G5AOoq8sO68cMwHaw9raXt82 6WjTxBXiMlNeJKb6njgoXi3cSfxy1F7/SENGAjAd6lJ5Zm4bi1L7eHPOnczw1jasFanx6owE21H IzOU83eyaG9R4Jdkci4TxJC3Ta1zcX6dLx7lmyKdwsS7rKYCoww+mnh+5gEMCqC9yoTeV0+3T2y 8B2Wx47bj2yzHVDRm/kOPk21h6MVeVX+zhR4Lba1I0Wwsl3DSw0pukD0x829V1KMaAACucp1DN7 uWrwtv7dcrRMjT9EcwZSEwPAZwYRqrJz1rMgPyQuR5efIEfL6P/0QOZyzDgJeYA+IfxPm+osQjv NYdo6g6LWgee6vzGyBzWWlyBDG+IF4IVNPnJgzKzkY X-Received: by 2002:a05:6a00:2ea6:b0:84c:4b58:2cec with SMTP id d2e1a72fcca58-84e2b7e3879mr1357215b3a.15.1784769008136; Wed, 22 Jul 2026 18:10:08 -0700 (PDT) Received: from KRHW1CJW23.bytedance.net ([203.208.189.11]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-84e17262d82sm2148975b3a.15.2026.07.22.18.10.05 (version=TLS1_3 cipher=TLS_CHACHA20_POLY1305_SHA256 bits=256/256); Wed, 22 Jul 2026 18:10:07 -0700 (PDT) From: Zhao Li To: johannes@sipsolutions.net Cc: linux-wireless@vger.kernel.org, linux-kernel@vger.kernel.org, michal.kazior@tieto.com, Zhao Li Subject: [PATCH v2] wifi: mac80211: skip unused probe response countdown offsets Date: Thu, 23 Jul 2026 09:10:01 +0800 Message-ID: <20260723011001.76851-1-enderaoelyther@gmail.com> X-Mailer: git-send-email 2.50.1 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" mac80211 copies cfg80211's variable-length countdown offset list into a zero-initialized fixed-size array, leaving unused entries at zero. The beacon branch already skips those zero entries, but the AP probe-response branch writes through them unconditionally. When a probe-response template has no countdown offset, the write through an unused zero entry overwrites resp->data[0], corrupting the first byte of the template. cfg80211 already bounds explicitly supplied non-zero offsets in nl80211_parse_counter_offsets(), so this is a zero-sentinel bug, not an out-of-bounds write. Skip zero probe-response offsets, matching the beacon path. Fixes: af296bdb8da4 ("mac80211: move csa counters from sdata to beacon/pres= p") Link: https://lore.kernel.org/all/20260708195911.84365-6-enderaoelyther@gma= il.com/ Assisted-by: Codex:gpt-5 Assisted-by: Claude:opus-4.8 Signed-off-by: Zhao Li --- Changes in v2: - Describe offset zero as the unused-entry sentinel; do not claim an out-of-bounds access. net/mac80211/tx.c | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/net/mac80211/tx.c b/net/mac80211/tx.c index 91b14112e24f0..fd4c379b3f201 100644 --- a/net/mac80211/tx.c +++ b/net/mac80211/tx.c @@ -5249,7 +5249,8 @@ static void ieee80211_set_beacon_cntdwn(struct ieee80= 211_sub_if_data *sdata, if (sdata->vif.type =3D=3D NL80211_IFTYPE_AP && resp) { u16 *resp_offsets =3D resp->cntdwn_counter_offsets; =20 - resp->data[resp_offsets[i]] =3D count; + if (resp_offsets[i]) + resp->data[resp_offsets[i]] =3D count; } } } --=20 2.50.1 (Apple Git-155)