From nobody Tue Sep 29 05:34:24 2026 Received: from mail-pg1-f181.google.com (mail-pg1-f181.google.com [209.85.215.181]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 0BC0141834C for ; Tue, 11 Aug 2026 21:00:50 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.215.181 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786482052; cv=none; b=tCMzuuYZmSc7oLprqEnG0YlHEYLedA/bYzj4bN6AeoMnqm4NZui3XyfnesVV0Dlwwpnxb7WeXYdZJin1yw1wl5xhyqsxCkgnRfJ3I9P9yE4XJTG3L+3cK0PgisqGUUNvPV4RKEgWlrj08Migri76tUr9ksSLdGDPOdYWaaA5iT4= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786482052; c=relaxed/simple; bh=DHZeUSZTTSX7z32SiH+oih8p4TW3kYdEqSl1SPBOCc0=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=hNM6ElyyAxnlm6cXvBWtsKyWLJI/NJ0sQC5UyNjzMj3+OOiY1pHaEG8YIr3L5UaMXB2aFOvUk+CAFC1OYPc3p2fwARjbqW+H8PGE0QLk56tkO8hF9R+hKFYX/Gvm/92T65UkLZOB+9tV/oVNvtYOK/QLSai1f3sG6uypE6/UBSs= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=Av4x1dfq; arc=none smtp.client-ip=209.85.215.181 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="Av4x1dfq" Received: by mail-pg1-f181.google.com with SMTP id 41be03b00d2f7-cbedf433a99so202773a12.2 for ; Tue, 11 Aug 2026 14:00:50 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1786482050; x=1787086850; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=Zdl3WKJSZaIAl32/kPw7PkLAafvF1qJSXITcCb18upg=; b=Av4x1dfqVUu5MH7gQ38hcrBwbCm9ZrZl9ZQRFGyD9T+YbxPRSEtVUKrXUBIpfW0Jx9 U6O7wUZGi85JMy968/usBUrRrR8pji1elP1vqfnIPAxRRkMcVvxBE4Awj1P6e/JZmf5F JUZ3Ez92WgDPVhrSlWoP5dVQGi778Ich90I+LL6m7RpKGt3+uLdyq+C4tO8c5SC9cnqL Z+GrisGaztw6wPQaeTCCclEQFWPK6AnhlGUv9PYN6PpmdF3G6l8BCr6y8TuKj4JRkPN2 jdGuBOyUWQoJYyJ/b89RLCCHXrOxpJecnM4ZuiwMaVuI4C8hofc1z8XKVmIYPUCRbqPB t0Hg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786482050; x=1787086850; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=Zdl3WKJSZaIAl32/kPw7PkLAafvF1qJSXITcCb18upg=; b=HUP3iQCy/1T75jQz++rMZFoZcaJ64BWkgR5hO1uTAvMsHaetBM1d1LHUHXkpQgW4wO EIZR1PQ3IC6tZzCNjL+aCJtQ9WvIYsbzFkbFg/lCEtgFyPNTUfQEdRnfcJ8itM5ympdM aeYyR45J1spyVsvf8N8fGODMHcQRmIuZRDDl23XKXpz8DgtaIiUL1yYug3p3iISzuDyK jlMOOG+8Jy/6Q9YDnm23iaANjrTR/RVaVMIs0Gc/M9GSp7U0nxHwrdpy3NDekJTZnIIy eVMjlg9w9CCKixXVg93iTI7IGLMarSeCK25ICNCufc4rWptgBW2myopJuuc6FPDQqL1q BoWw== X-Forwarded-Encrypted: i=1; AHgh+Rq1/p40h6agCQXt0F+19UjKAIuSh9/rP2ClktXSa896kj2Rq8ACJ8SlC/V/rnjR464dRjpAJt8R7mPbp8g=@vger.kernel.org X-Gm-Message-State: AOJu0YxceYf8lOqPvy/z6II5N8Qj2zEtbMBXJ8b2xZ9Xrnc9AVk9XAaW HQ/zn8yXyg1KEzX0qBUn5+MBqGbfR8MuZygB3P5FnpBTClJfJ31UTSvI X-Gm-Gg: AR+sD10vpIrZktV0P5A2dyEk93mf9kIzn+H14CS95ZuGWclBFiYlfw5sAZ0e6MRDaiL z5/K7mzuU+kz4xb01OF2txhiHsZIIoH966w/HhWgPbWBdbkaXZ905BpLTI40EeVEgeOqGsZMybM EY95HQ6sWwLHHkL0f48qnrl4oDrBNXJn62MzhsoD03I7qGJDjLI/PRMkH9HI11gq/qk8NL8o0DJ Mxsgczj1513q883SrHfbBBt8OoAoVpokj2OipMy9si8WwY7GPcjJCqn775KxNmo//StfuvIWkM4 dJatx3+fvshKh78bdLXmqX+FbpAYEMOLLPeBMJk0T3dboHAs+taJRdEJQJ4xHxqgiTjyQqJZ5kF 3ZQToaY04p3ciFO3G/YHOMP7gwKefSjId1zzCeJv8ZY5k2ilRaPIjfEmq7x8j5+P9OS6StK5eqE /X+UV8iIY35UjINtlIvahxRGXHjD/s8cqYYsG91+fMlC33eUr5rHbBJ54mghD3NR6y2nVFCvbn8 djfi+eADUn+4sx/BSuLrPEo8FcKNXo/ExSYrL6t6H16JYTfJeJ8JsRAPgxZ/NetNrC1Ulpik5kp KCCQ X-Received: by 2002:a05:6a20:cf8d:b0:3c3:935a:af2c with SMTP id adf61e73a8af0-3cc2b77f0cemr8795497637.3.1786482050220; Tue, 11 Aug 2026 14:00:50 -0700 (PDT) Received: from nixos ([2405:201:c40d:9039:4f8b:4d:f8c2:8f50]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-31cf628e42asm3322246eec.15.2026.08.11.14.00.46 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 11 Aug 2026 14:00:49 -0700 (PDT) From: Ayushman Rout To: syzbot+f1ba58d6b55abd13239e@syzkaller.appspotmail.com Cc: johannes@sipsolutions.net, linux-kernel@vger.kernel.org, linux-wireless@vger.kernel.org, netdev@vger.kernel.org, syzkaller-bugs@googlegroups.com, Ayushman Rout Subject: [PATCH] wifi: mac80211: guard drv_net_setup_tc() against unbound AP_VLAN sdata Date: Wed, 12 Aug 2026 02:29:27 +0530 Message-ID: <20260811205927.11228-1-ayushmanrout27@gmail.com> X-Mailer: git-send-email 2.54.0 In-Reply-To: <6a6d39e6.f794c993.27aeb.0008.GAE@google.com> References: <6a6d39e6.f794c993.27aeb.0008.GAE@google.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" #syz test: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.g= it master syzbot reports a NULL/invalid pointer dereference in trace_event_raw_event_drv_net_setup_tc(), reached via ieee80211_netdev_setup_tc() -> drv_net_setup_tc(). drv_net_setup_tc() calls get_bss_sdata(sdata) unconditionally. For an NL80211_IFTYPE_AP_VLAN interface this does container_of(sdata->bss, ...), but sdata->bss is only linked opportunistically at interface-add time when a matching same-address AP interface exists - it is not enforced, so an AP_VLAN interface can be fully created and registered with sdata->bss left NULL. container_of() on NULL yields a small invalid pointer rather than NULL, which the trace_drv_net_setup_tc tracepoint then dereferences to read the interface name. Guard against an unbound AP_VLAN sdata before calling get_bss_sdata(), matching the WARN_ON_ONCE(!bss) precondition already used for this same relationship in sta_info.c. Also add check_sdata_in_driver(), used by the neighboring drv_net_fill_forward_path() but missing here. The underlying gap in ieee80211_if_add() - AP_VLAN creation not requiring a bound bss - is not fixed here; other get_bss_sdata() callers may share the exposure. Fixes: 61587f1556fe ("wifi: mac80211: add support for letting drivers regis= ter tc offload support") Reported-by: syzbot+f1ba58d6b55abd13239e@syzkaller.appspotmail.com Closes: https://syzkaller.appspot.com/bug?extid=3Df1ba58d6b55abd13239e Signed-off-by: Ayushman Rout --- net/mac80211/driver-ops.h | 16 ++++++++++++++++ 1 file changed, 16 insertions(+) diff --git a/net/mac80211/driver-ops.h b/net/mac80211/driver-ops.h index f1c0b87fddd5..ecfdb51152f4 100644 --- a/net/mac80211/driver-ops.h +++ b/net/mac80211/driver-ops.h @@ -1702,7 +1702,23 @@ static inline int drv_net_setup_tc(struct ieee80211_= local *local, =20 might_sleep(); =20 + /* + * An AP_VLAN interface created without a matching, same-address + * AP interface present never gets sdata->bss populated (see the + * interface-add validation in iface.c, which links bss only + * opportunistically and does not require it). Such an sdata is + * not safe to pass through get_bss_sdata(): container_of() on a + * NULL sdata->bss yields a small invalid pointer, which the + * tracepoint below then dereferences to read the interface name, + * causing a crash. + */ + if (sdata->vif.type =3D=3D NL80211_IFTYPE_AP_VLAN && !sdata->bss) + return -EIO; + sdata =3D get_bss_sdata(sdata); + if (!check_sdata_in_driver(sdata)) + return -EIO; + trace_drv_net_setup_tc(local, sdata, type); if (local->ops->net_setup_tc) ret =3D local->ops->net_setup_tc(&local->hw, &sdata->vif, dev, --=20 2.54.0