From nobody Tue Sep 29 05:35:25 2026 Received: from mailgw.kylinos.cn (mailgw.kylinos.cn [124.126.103.232]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id B6BBB3264F4; Wed, 12 Aug 2026 06:07:59 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=124.126.103.232 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786514885; cv=none; b=dNCsUO5FgcDYsom9S9t5hqLZMpo7Vx3H79RNNp7ikgDdYqpWLRecerrWS+ArMs3x4euSNLQFDO616NQ6XmU610pgQa9J2pB1Ha/PttsAs9TiQ3s6jLdCoaQJEwZnIdxZZGm6nMHqb9sI7LzRww9MkiDyAo1+4SDTcR1whNpMv2o= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786514885; c=relaxed/simple; bh=7K0F3pNxMJxMUv8nrmHJgg+DdGJ5S+hgkuvjQayL5lU=; h=From:To:Cc:Subject:Date:Message-Id:In-Reply-To:References: MIME-Version; b=YrrDKFEoDcoMP2FUjCzcJqH3O6Ye8MYvaKSxR+1ydNCF05ZfEZvopSdW/n4L5LipQxcCRDoh2jao2FvdI+Q9Kud5Q/G3X8sGzFifWPLLunYk5L8hhdBbnUlyrCIm4whLJc76Wiicw2o/FUNtdAU2oTTZJ6WWnWZq4swH/Xl4geE= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=kylinos.cn; spf=pass smtp.mailfrom=kylinos.cn; arc=none smtp.client-ip=124.126.103.232 Authentication-Results: smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=kylinos.cn Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=kylinos.cn X-UUID: 27836566961411f1aa26b74ffac11d73-20260812 X-CID-P-RULE: Release_Ham X-CID-O-INFO: VERSION:1.3.12,REQID:b7b2b4b5-a492-49f2-aafc-ca39b1af9aa9,IP:0,U RL:0,TC:0,Content:-25,EDM:25,RT:0,SF:0,FILE:0,BULK:0,RULE:Release_Ham,ACTI ON:release,TS:0 X-CID-META: VersionHash:e7bac3a,CLOUDID:4f6115090072d14b10440498c34e5d58,BulkI D:nil,BulkQuantity:0,Recheck:0,SF:81|82|102|850|865|898,TC:nil,Content:0|1 5|50,EDM:5,IP:nil,URL:0,File:nil,RT:nil,Bulk:nil,QS:nil,BEC:nil,COL:0,OSI: 0,OSA:0,AV:0,LES:1,SPR:NO,DKR:0,DKP:0,BRR:0,BRE:0,ARC:0 X-CID-BVR: 2,SSN|SDN X-CID-BAS: 2,SSN|SDN,0,_ X-CID-FACTOR: TF_CID_SPAM_SNR X-CID-RHF: D41D8CD98F00B204E9800998ECF8427E X-UUID: 27836566961411f1aa26b74ffac11d73-20260812 X-User: lilinmao@kylinos.cn Received: from localhost.localdomain [(10.44.16.150)] by mailgw.kylinos.cn (envelope-from ) (Generic MTA with TLSv1.3 TLS_AES_256_GCM_SHA384 256/256) with ESMTP id 1170945384; Wed, 12 Aug 2026 14:07:53 +0800 From: Linmao Li To: Lachlan Hodges Cc: Dan Callaghan , Arien Judge , Johannes Berg , linux-wireless@vger.kernel.org, linux-kernel@vger.kernel.org, Linmao Li Subject: [PATCH wireless-next 1/4] wifi: mm81x: free the firmware scratch buffer on parse failures Date: Wed, 12 Aug 2026 14:07:37 +0800 Message-Id: <20260812060740.1275280-2-lilinmao@kylinos.cn> X-Mailer: git-send-email 2.25.1 In-Reply-To: <20260812060740.1275280-1-lilinmao@kylinos.cn> References: <20260812060740.1275280-1-lilinmao@kylinos.cn> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" mm81x_fw_load_fw() allocates fw_buf before it inspects the image, but releases it only on the success path. The two early returns taken for a malformed image leave one firmware-sized allocation attached to the device, and mm81x_fw_flash() retries the load three times. Release it on those paths too, the way mm81x_fw_load_bcf() already does. Fixes: b1906cea00b0 ("wifi: mm81x: add mm81x Wi-Fi HaLow driver") Signed-off-by: Linmao Li --- drivers/net/wireless/morsemicro/mm81x/fw.c | 7 +++++-- 1 file changed, 5 insertions(+), 2 deletions(-) diff --git a/drivers/net/wireless/morsemicro/mm81x/fw.c b/drivers/net/wirel= ess/morsemicro/mm81x/fw.c index d6d2ad086c328..d407b57f4c9cb 100644 --- a/drivers/net/wireless/morsemicro/mm81x/fw.c +++ b/drivers/net/wireless/morsemicro/mm81x/fw.c @@ -117,13 +117,15 @@ static int mm81x_fw_load_fw(struct mm81x *mors, const= struct firmware *fw) =20 if (mm81x_fw_get_header(fw->data, &ehdr)) { dev_err(mors->dev, "Wrong file format"); - return -EINVAL; + ret =3D -EINVAL; + goto out_free; } =20 if (mm81x_fw_get_section_header(fw->data, &ehdr, &sh_strtab, ehdr.e_shstrndx)) { dev_err(mors->dev, "Invalid firmware. Missing string table"); - return -ENOENT; + ret =3D -ENOENT; + goto out_free; } =20 sh_strs =3D (const char *)fw->data + sh_strtab.sh_offset; @@ -179,6 +181,7 @@ static int mm81x_fw_load_fw(struct mm81x *mors, const s= truct firmware *fw) if (ehdr.e_entry) ret =3D mm81x_fw_set_boot_addr(mors, ehdr.e_entry); =20 +out_free: devm_kfree(mors->dev, fw_buf); return ret; } --=20 2.25.1 From nobody Tue Sep 29 05:35:25 2026 Received: from mailgw.kylinos.cn (mailgw.kylinos.cn [124.126.103.232]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id B3CA633D4FD; Wed, 12 Aug 2026 06:08:03 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=124.126.103.232 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786514890; cv=none; b=kj4qR5LA9H6jbL8D0UiP5H5o7SeFVve5Q44kL2olxoNCHHRt366mEBwCXP8PsHvCNCssqXPLtCdGwQviXRf/POx1ECUqHsx4fdCXAKJPC1VivRyqbDJ9oahVIKWN7p8GRS3sfMGaffUS7jTgC1Jpek/z2vUf4DaVBXuIuRY0Tpc= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786514890; c=relaxed/simple; bh=YmzKRhhX/lB/xv+JxthT8pLmBgVHp0dH6MwVhDfiqng=; h=From:To:Cc:Subject:Date:Message-Id:In-Reply-To:References: MIME-Version; b=jFaea/cJnr6BhFr0icu9+DMSpKnyYkaUiQf9QdTY9wKwSnuWf1NM/67Q7ggRXfYLpjDH1A5dWRzSt4sX5t+tHFSJ/rsbLr1ICjXvooRj/nhd0AUP9Caj6IzPXQKdEi4YMrwZpRsPqRJWDWgGy5VLVhpNAcSsq77BTbd8NC1GtbE= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=kylinos.cn; spf=pass smtp.mailfrom=kylinos.cn; arc=none smtp.client-ip=124.126.103.232 Authentication-Results: smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=kylinos.cn Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=kylinos.cn X-UUID: 2a816c86961411f1aa26b74ffac11d73-20260812 X-CID-P-RULE: Release_Ham X-CID-O-INFO: VERSION:1.3.12,REQID:d70cf44e-4b7a-47e8-ab28-b4557b563245,IP:0,U RL:0,TC:0,Content:-5,EDM:25,RT:0,SF:0,FILE:0,BULK:0,RULE:Release_Ham,ACTIO N:release,TS:20 X-CID-META: VersionHash:e7bac3a,CLOUDID:53d3b6b9f4122bd44a4513ecb6b5f556,BulkI D:nil,BulkQuantity:0,Recheck:0,SF:81|82|102|136|850|865|898,TC:nil,Content :0|15|50,EDM:5|-100,IP:nil,URL:0,File:nil,RT:nil,Bulk:nil,QS:nil,BEC:nil,C OL:0,OSI:0,OSA:0,AV:0,LES:1,SPR:NO,DKR:0,DKP:0,BRR:0,BRE:0,ARC:0 X-CID-BVR: 2,SSN|SDN X-CID-BAS: 2,SSN|SDN,0,_ X-CID-FACTOR: TF_CID_SPAM_SNR X-CID-RHF: D41D8CD98F00B204E9800998ECF8427E X-UUID: 2a816c86961411f1aa26b74ffac11d73-20260812 X-User: lilinmao@kylinos.cn Received: from localhost.localdomain [(10.44.16.150)] by mailgw.kylinos.cn (envelope-from ) (Generic MTA with TLSv1.3 TLS_AES_256_GCM_SHA384 256/256) with ESMTP id 581914761; Wed, 12 Aug 2026 14:07:58 +0800 From: Linmao Li To: Lachlan Hodges Cc: Dan Callaghan , Arien Judge , Johannes Berg , linux-wireless@vger.kernel.org, linux-kernel@vger.kernel.org, Linmao Li Subject: [PATCH wireless-next 2/4] wifi: mm81x: do not discard a failed firmware segment write Date: Wed, 12 Aug 2026 14:07:38 +0800 Message-Id: <20260812060740.1275280-3-lilinmao@kylinos.cn> X-Mailer: git-send-email 2.25.1 In-Reply-To: <20260812060740.1275280-1-lilinmao@kylinos.cn> References: <20260812060740.1275280-1-lilinmao@kylinos.cn> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" When mm81x_dm_write() fails while downloading a PT_LOAD segment, mm81x_fw_load_fw() sets ret to -EIO and breaks out of the loop. The boot address write at the end of the function then overwrites ret, so a partially downloaded image is reported as loaded and the chip is triggered on it instead of the load being retried. Leave the function as soon as a segment fails. Fixes: b1906cea00b0 ("wifi: mm81x: add mm81x Wi-Fi HaLow driver") Signed-off-by: Linmao Li --- drivers/net/wireless/morsemicro/mm81x/fw.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/drivers/net/wireless/morsemicro/mm81x/fw.c b/drivers/net/wirel= ess/morsemicro/mm81x/fw.c index d407b57f4c9cb..a2cb97cefc4e9 100644 --- a/drivers/net/wireless/morsemicro/mm81x/fw.c +++ b/drivers/net/wireless/morsemicro/mm81x/fw.c @@ -162,7 +162,7 @@ static int mm81x_fw_load_fw(struct mm81x *mors, const s= truct firmware *fw) mm81x_release_bus(mors); if (status) { ret =3D -EIO; - break; + goto out_free; } } } --=20 2.25.1 From nobody Tue Sep 29 05:35:25 2026 Received: from mailgw.kylinos.cn (mailgw.kylinos.cn [124.126.103.232]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id F131C3148D0; Wed, 12 Aug 2026 06:08:07 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=124.126.103.232 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786514891; cv=none; b=vEdOocP0t4Y3x6UYo7FnC6bf6DY9kwnQ+ng6s0hxdKGCamUXb7GhQu1vfydaw5z65phkjHdKVoHoinoLVfza38Alg35cweLWzrtjZGbbnYYJO66DM34DrXyluJlXk9otWxAq9dwyJQd9pFkUs+EkvOlYn/HHlg6sllvnODeFXlw= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786514891; c=relaxed/simple; bh=tQ1k/tIcckyMmnS8tsT6Z0X0s5QMb+r4aEyOZYtZ6h8=; h=From:To:Cc:Subject:Date:Message-Id:In-Reply-To:References: MIME-Version; b=uAcyHRgmLLtD68g4r7DSJp/CPND1uDVcE0Lvot09ZzUcvjvPeexkjnYfiHgWyFvTxKk2obw+VU2VXrjUR+/SN/jENHJ9621qp0eAP+tEBwzSaYB4VYn0UWvdcsqealOKxoDhBYOLxk+DFsyArs9YbpcMXM5PqfQwIYbCgjk3duo= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=kylinos.cn; spf=pass smtp.mailfrom=kylinos.cn; arc=none smtp.client-ip=124.126.103.232 Authentication-Results: smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=kylinos.cn Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=kylinos.cn X-UUID: 2c74e5c2961411f1aa26b74ffac11d73-20260812 X-CID-P-RULE: Release_Ham X-CID-O-INFO: VERSION:1.3.12,REQID:d4c173ca-74d7-49b1-bb5f-57630f49bfb0,IP:0,U RL:0,TC:0,Content:-5,EDM:25,RT:0,SF:0,FILE:0,BULK:0,RULE:Release_Ham,ACTIO N:release,TS:20 X-CID-META: VersionHash:e7bac3a,CLOUDID:cb7aab0023b1ac9047cc38007e75f7e9,BulkI D:nil,BulkQuantity:0,Recheck:0,SF:81|82|102|850|865|898,TC:nil,Content:0|1 5|50,EDM:5,IP:nil,URL:0,File:nil,RT:nil,Bulk:nil,QS:nil,BEC:nil,COL:0,OSI: 0,OSA:0,AV:0,LES:1,SPR:NO,DKR:0,DKP:0,BRR:0,BRE:0,ARC:0 X-CID-BVR: 2,SSN|SDN X-CID-BAS: 2,SSN|SDN,0,_ X-CID-FACTOR: TF_CID_SPAM_SNR X-CID-RHF: D41D8CD98F00B204E9800998ECF8427E X-UUID: 2c74e5c2961411f1aa26b74ffac11d73-20260812 X-User: lilinmao@kylinos.cn Received: from localhost.localdomain [(10.44.16.150)] by mailgw.kylinos.cn (envelope-from ) (Generic MTA with TLSv1.3 TLS_AES_256_GCM_SHA384 256/256) with ESMTP id 422827498; Wed, 12 Aug 2026 14:08:01 +0800 From: Linmao Li To: Lachlan Hodges Cc: Dan Callaghan , Arien Judge , Johannes Berg , linux-wireless@vger.kernel.org, linux-kernel@vger.kernel.org, Linmao Li Subject: [PATCH wireless-next 3/4] wifi: mm81x: bound the .fw_info TLV walk Date: Wed, 12 Aug 2026 14:07:39 +0800 Message-Id: <20260812060740.1275280-4-lilinmao@kylinos.cn> X-Mailer: git-send-email 2.25.1 In-Reply-To: <20260812060740.1275280-1-lilinmao@kylinos.cn> References: <20260812060740.1275280-1-lilinmao@kylinos.cn> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" mm81x_fw_parse_info() only checks that a TLV header starts before the end of the section, so a header that straddles the end is read anyway, and MM81X_FW_INFO_TLV_BCF_ADDR reads its four-byte value without looking at the TLV length at all. The BCF address can come from whatever follows the section. Walk by remaining length, and only take the address when the value is really there. Fixes: b1906cea00b0 ("wifi: mm81x: add mm81x Wi-Fi HaLow driver") Signed-off-by: Linmao Li --- drivers/net/wireless/morsemicro/mm81x/fw.c | 24 ++++++++++++++-------- 1 file changed, 16 insertions(+), 8 deletions(-) diff --git a/drivers/net/wireless/morsemicro/mm81x/fw.c b/drivers/net/wirel= ess/morsemicro/mm81x/fw.c index a2cb97cefc4e9..d2fba42e53627 100644 --- a/drivers/net/wireless/morsemicro/mm81x/fw.c +++ b/drivers/net/wireless/morsemicro/mm81x/fw.c @@ -54,21 +54,29 @@ static int mm81x_fw_get_header(const u8 *data, Elf32_Eh= dr *ehdr) =20 static void mm81x_fw_parse_info(struct mm81x *mors, const u8 *data, int le= ngth) { - const struct mm81x_fw_info_tlv *tlv =3D - (const struct mm81x_fw_info_tlv *)data; + const u8 *end =3D data + length; + const u8 *pos =3D data; + + while (end - pos >=3D (ptrdiff_t)sizeof(struct mm81x_fw_info_tlv)) { + const struct mm81x_fw_info_tlv *tlv =3D + (const struct mm81x_fw_info_tlv *)pos; + u16 tlv_len =3D le16_to_cpu(tlv->length); + + pos =3D tlv->val; + if (tlv_len > end - pos) + break; =20 - while ((u8 *)tlv < (data + length)) { switch (le16_to_cpu(tlv->type)) { case MM81X_FW_INFO_TLV_BCF_ADDR: - mors->bcf_address =3D get_unaligned_le32(tlv->val); + if (tlv_len >=3D sizeof(__le32)) + mors->bcf_address =3D + get_unaligned_le32(tlv->val); break; default: break; } - tlv =3D (const struct mm81x_fw_info_tlv *)((u8 *)tlv + - le16_to_cpu( - tlv->length) + - sizeof(*tlv)); + + pos +=3D tlv_len; } } =20 --=20 2.25.1 From nobody Tue Sep 29 05:35:25 2026 Received: from mailgw.kylinos.cn (mailgw.kylinos.cn [124.126.103.232]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 86AD5315D58; Wed, 12 Aug 2026 06:08:09 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=124.126.103.232 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786514892; cv=none; b=SKkn9TJhdVXNd4ADkwlmWdy4M8HP/z9jzLPD67k6I9ypFWuTiAYK1b2p0luAo1QeUG4vZQxGQTaBN8NVMCDRgYMxLhOnIpUlwuMs6E9mBH0t6tBt+Hg8BPSJ76yAqk3nsZvqBUrpYQxIgn4ihAZ7y/eKYWw3LxyoODr3n3D4cT8= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786514892; c=relaxed/simple; bh=1Zgoh7KwYe19jPX28ywjpTtR7fob6aZecEE4CDysbag=; h=From:To:Cc:Subject:Date:Message-Id:In-Reply-To:References: MIME-Version; b=U132ZhI+neWUf/sS1CYqJ4nHdQC2M7Avqjtmq1xNn/UkwpjzPjzV0ftYk0suC9Jp3M9w2MKsyqDaeHiYO96L8pO/QRJEIZQnM4rWg8Rq2DJjkSiP8ffagxU3wSWncpwaPXc2XOMKrg4PubDGUjO3oFhHPeYDPaDmNksHZLRQoII= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=kylinos.cn; spf=pass smtp.mailfrom=kylinos.cn; arc=none smtp.client-ip=124.126.103.232 Authentication-Results: smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=kylinos.cn Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=kylinos.cn X-UUID: 2d767f76961411f1aa26b74ffac11d73-20260812 X-CID-P-RULE: Release_Ham X-CID-O-INFO: VERSION:1.3.12,REQID:358db522-993e-451c-8923-f7160c3eb2a1,IP:0,U RL:0,TC:0,Content:-25,EDM:25,RT:0,SF:0,FILE:0,BULK:0,RULE:Release_Ham,ACTI ON:release,TS:0 X-CID-META: VersionHash:e7bac3a,CLOUDID:222384f615f6213ad7a20a2ec4404eb4,BulkI D:nil,BulkQuantity:0,Recheck:0,SF:81|82|102|850|865|898,TC:nil,Content:0|1 5|50,EDM:5,IP:nil,URL:0,File:nil,RT:nil,Bulk:nil,QS:nil,BEC:nil,COL:0,OSI: 0,OSA:0,AV:0,LES:1,SPR:NO,DKR:0,DKP:0,BRR:0,BRE:0,ARC:0 X-CID-BVR: 2,SSN|SDN X-CID-BAS: 2,SSN|SDN,0,_ X-CID-FACTOR: TF_CID_SPAM_SNR X-CID-RHF: D41D8CD98F00B204E9800998ECF8427E X-UUID: 2d767f76961411f1aa26b74ffac11d73-20260812 X-User: lilinmao@kylinos.cn Received: from localhost.localdomain [(10.44.16.150)] by mailgw.kylinos.cn (envelope-from ) (Generic MTA with TLSv1.3 TLS_AES_256_GCM_SHA384 256/256) with ESMTP id 2103006533; Wed, 12 Aug 2026 14:08:03 +0800 From: Linmao Li To: Lachlan Hodges Cc: Dan Callaghan , Arien Judge , Johannes Berg , linux-wireless@vger.kernel.org, linux-kernel@vger.kernel.org, Linmao Li Subject: [PATCH wireless-next 4/4] wifi: mm81x: bound the extended host table walk Date: Wed, 12 Aug 2026 14:07:40 +0800 Message-Id: <20260812060740.1275280-5-lilinmao@kylinos.cn> X-Mailer: git-send-email 2.25.1 In-Reply-To: <20260812060740.1275280-1-lilinmao@kylinos.cn> References: <20260812060740.1275280-1-lilinmao@kylinos.cn> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" The extended host table is read from the chip into a buffer sized from the length register, then walked without any of its contents being checked: - the length the table declares in its own header is used to compute the end pointer, but is never compared against the length that was read, so a larger value moves the end pointer past the buffer; - the walk only requires a TLV header to start before that end, so a header straddling it is read anyway; - every recognised tag is cast to a structure larger than the TLV header and read in full without checking that the TLV is that long, so a short S1G capabilities, checksum or YAPS TLV at the end of the table reads past the allocation. Firmware that reports a table the driver does not agree with is enough to reach these; it does not take a malicious device. Reject a self-declared length that does not fit what was read, and walk the TLVs by remaining length, skipping any TLV too short for the structure its tag selects. Fixes: b1906cea00b0 ("wifi: mm81x: add mm81x Wi-Fi HaLow driver") Signed-off-by: Linmao Li --- drivers/net/wireless/morsemicro/mm81x/fw.c | 47 +++++++++++++++------- 1 file changed, 32 insertions(+), 15 deletions(-) diff --git a/drivers/net/wireless/morsemicro/mm81x/fw.c b/drivers/net/wirel= ess/morsemicro/mm81x/fw.c index d2fba42e53627..50fa9e4b5f803 100644 --- a/drivers/net/wireless/morsemicro/mm81x/fw.c +++ b/drivers/net/wireless/morsemicro/mm81x/fw.c @@ -503,6 +503,13 @@ static int mm81x_fw_read_ext_host_table(struct mm81x *= mors, if (ret) goto exit; =20 + /* The table describes its own length; it must fit what was read */ + if (le32_to_cpu(host_tbl->ext_host_tbl_length) < sizeof(*host_tbl) || + le32_to_cpu(host_tbl->ext_host_tbl_length) > ext_host_tbl_len) { + ret =3D -EINVAL; + goto exit; + } + mm81x_release_bus(mors); *ext_host_table =3D host_tbl; return ret; @@ -570,34 +577,44 @@ int mm81x_fw_parse_ext_host_tbl(struct mm81x *mors) end =3D ((u8 *)ext_host_table) + le32_to_cpu(ext_host_table->ext_host_tbl_length); =20 - while (head < end) { + while (end - head >=3D (ptrdiff_t)sizeof(struct ext_host_tbl_tlv_hdr)) { struct ext_host_tbl_tlv_hdr *hdr =3D (struct ext_host_tbl_tlv_hdr *)head; + u16 tlv_len =3D le16_to_cpu(hdr->length); + + if (tlv_len < sizeof(*hdr) || tlv_len > end - head) + break; =20 switch (le16_to_cpu(hdr->tag)) { - case MM81X_FW_HOST_TABLE_TAG_S1G_CAPABILITIES: - mm81x_fw_update_capabilities( - mors, (struct ext_host_tbl_s1g_caps *)hdr); + case MM81X_FW_HOST_TABLE_TAG_S1G_CAPABILITIES: { + struct ext_host_tbl_s1g_caps *caps =3D (void *)hdr; + + if (tlv_len >=3D sizeof(*caps)) + mm81x_fw_update_capabilities(mors, caps); break; + } + case MM81X_FW_HOST_TABLE_TAG_INSERT_SKB_CHECKSUM: { + struct ext_host_tbl_insert_skb_checksum *csum =3D + (void *)hdr; =20 - case MM81X_FW_HOST_TABLE_TAG_INSERT_SKB_CHECKSUM: - mm81x_fw_update_validate_skb_checksum( - mors, - (struct ext_host_tbl_insert_skb_checksum *)hdr); + if (tlv_len >=3D sizeof(*csum)) + mm81x_fw_update_validate_skb_checksum(mors, + csum); break; + } + case MM81X_FW_HOST_TABLE_TAG_YAPS_TABLE: { + struct ext_host_tbl_yaps_table *yaps =3D (void *)hdr; =20 - case MM81X_FW_HOST_TABLE_TAG_YAPS_TABLE: - mm81x_yaps_hw_read_table( - mors, &((struct ext_host_tbl_yaps_table *)hdr) - ->yaps_table); + if (tlv_len >=3D sizeof(*yaps)) + mm81x_yaps_hw_read_table(mors, + &yaps->yaps_table); break; + } default: break; } =20 - head +=3D le16_to_cpu(hdr->length); - if (!hdr->length) - break; + head +=3D tlv_len; } =20 kfree(ext_host_table); --=20 2.25.1