From nobody Tue Sep 29 04:10:16 2026 Received: from mail-wr1-f47.google.com (mail-wr1-f47.google.com [209.85.221.47]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 458A933F59D for ; Wed, 12 Aug 2026 19:05:59 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.221.47 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786561561; cv=none; b=AGLvhJgCxrSrudazwEUtjJ7RgBttvFFNTL9goIhWpkMHWDDyOHMaMXWRq691uaZUWKFE1mrpR5izVsNQ/Lt0F/dMGJiZbru8tJ8f7+nFuWx5pF/iOFqkI+OcL2Px3DMOSIHygE3LalbKpyGut7NqfOfCsfK78//+50JhUn0AMLA= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786561561; c=relaxed/simple; bh=eQp8XVqRjvd60SUbMt+7dhshdzEr9vsuv1ssHGoq5HM=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=SfEZAHBYk++2QELrtUZbWyBUKHXdnuteLMDRpXeSh1W1fTh6kXwBGdubyd2p37X9VJQxqMZRrLs8LQDPl5y1mxk3QFnISsV7aC9RLD66H3ldnopYxsPcl/GL4E2FPCsWgYE0kDp2eievS9hjQbuPRLz7PB7r4AnOdjBubw9liX4= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=MEYFVEFO; arc=none smtp.client-ip=209.85.221.47 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="MEYFVEFO" Received: by mail-wr1-f47.google.com with SMTP id ffacd0b85a97d-476a130c138so1084471f8f.0 for ; Wed, 12 Aug 2026 12:05:59 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1786561558; x=1787166358; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=VfMnRH4aX6HLrkbz/tRyXORgXHNB5l3UhNoONEXfJJI=; b=MEYFVEFOsOhn28YdReysg9cEPgapDU4qhiBTKkLuaaizeMI8xhJjgdIiLTlUVEBEOb XS2CV7A3iFdsrwIK4byFRq4uWC0xkp6ghOvean61pEeZ5l/bbKkA83qsYLX/KzMXtIVL QdyFzJbz+1Va70dweidd8P0vh82VF+L1TbXDFBQGy9l6SW7E6sd1GJnln0be4Z/L5wSX iLkaYlLt/CVHPLOFO/6LoMqSd8gLMtdJNTtdrUZQj7KeekWbEZ8BJCnplsIK7FJ4ycyp 3ercN+k1/4MBpXRIw9mswSjojlBMpk/VIfxb47l5loRrOESBI09vXHvf/QQx3XtRYidh atzQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786561558; x=1787166358; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=VfMnRH4aX6HLrkbz/tRyXORgXHNB5l3UhNoONEXfJJI=; b=aUsRfuSDrekJduP4S0eD8H/UxYjDgDqFjSc1MSeMImhnVCUj/7OwsFUnaBCq4yjoK4 dMNdOL239Nmmh4GbFh3Ac7MBZwOi31JnVT4eUxd0N23HO7wia7xaJryrqO98eYHA0tr7 4XfaG8is+WH0P9+fl7v/sTibMl833b4e+sfqWQe8an/vvH6ximcLNugQqpZQ1DOogVfp +7ynBX5JJ4NwcZXtAN8SZAbnIpsNVCnYpb1wYhuTI0VatdMGB4ORtO6pWUxmqxEVgxyr q04b3dgKIec/KrRnu4R6PKSwIOcJG/NLWok5Nyv+uiLb2pqZHwg/EGocDf6esS2KMokn mwpA== X-Forwarded-Encrypted: i=1; AHgh+RrrTESfZ07TmV/GHV+oD9DI560uF1lfxpHMLVhL5DNgEBSRJ7AbINTq41r2ir7tocCHtVwzA6k7G2uhtgU=@vger.kernel.org X-Gm-Message-State: AOJu0YwKhHBUpNvzwix+6KcYD7nL7b/HZ8AIkPPSG/OKgYFJ9MrUuud/ TrBX3qU8TGiH/i/ohxFMZHbS4IxVL5cIIC5zWtSnVNpHaJMY1N3YUaT0 X-Gm-Gg: AR+sD11bBr7TkfxkAU6CSDYUpN8fTHPtP2wYKynNiI8DU1cu3tZKfEdqM1VR4QUtly+ MI32zor2mrwNuPwELGKA4xAoIqejpWbHFEbJUzPK4Ab69iXXNfynFPVJcWikz5MVN4btxRLtRO/ egR2TxJD5yO3lvLR22nVpem/VOhbULMW3EzLTUfH0o+7YYkN63/LZZDE5oHr6DSLtfD+yMZC0fk nuUH248wiBMeAOFjINp1TrKyRaMUXc/nfRKnXl24Utd2MAkG+PxxiPiBlI4q9OGZVJuQriqS7MA XwSHMe4z1/2nWxtsCh0v9V0vUE8aCAE9kBxLd4ULWTm5s3M5rNHoUuKwuCGKZhHSmlV6iRLclyj a0wgHv7EG22mCfcpI1xVMwxWLbUVEVIUS7cHGJXZC5CFb3wPACtSo5MClHEqWRchh6JcBh6bzgN Ib2BqfOUdX7r/MY/mazp7WiSUn63/nryP6nHXT+VilFUR0E36PB8WL/wTXZnqvplWPx7ADJIMMd azKHiI4CSlyFA8WYVllOeMtR2hn6uc9dkCugpyETOs3RnpShfv801X2DYzhBs42kfYUEyASg5F8 sZ1J6g== X-Received: by 2002:a05:6000:29c2:b0:47f:71a6:970e with SMTP id ffacd0b85a97d-48159c8da03mr411377f8f.2.1786561557974; Wed, 12 Aug 2026 12:05:57 -0700 (PDT) Received: from Mac.home ([95.35.242.1]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-48150d5eb2csm9179875f8f.30.2026.08.12.12.05.56 (version=TLS1_3 cipher=TLS_CHACHA20_POLY1305_SHA256 bits=256/256); Wed, 12 Aug 2026 12:05:57 -0700 (PDT) From: Shmulik Cohen To: stas.yakovlev@gmail.com Cc: johannes@sipsolutions.net, linux-wireless@vger.kernel.org, linux-kernel@vger.kernel.org, Shmulik Cohen Subject: [PATCH 1/3] wifi: libipw: reject too-short beacon and probe responses Date: Wed, 12 Aug 2026 22:04:10 +0300 Message-ID: <20260812190412.18333-2-anuk909@gmail.com> X-Mailer: git-send-email 2.51.2 In-Reply-To: <20260812190412.18333-1-anuk909@gmail.com> References: <20260812190412.18333-1-anuk909@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" libipw_process_probe_response() and the libipw_network_init() call it makes assume the frame contains the full 36-byte beacon and probe response prefix, but the ipw2100 and ipw2200 receive paths only establish that a management frame carries the generic 24-byte three-address header. libipw_network_init() then computes the information element length as stats->len - sizeof(*beacon) stats->len is a u16 and sizeof() has type size_t, so the subtraction is evaluated as size_t and wraps instead of going negative. Truncating that to the u16 length parameter of libipw_parse_info_param() yields 65524 for a 24-byte beacon, and the parser then walks the receive buffer as if it held almost 64 KiB of information elements, reading past the allocation. Reject the frame before any fixed field is touched. Found by an AI-assisted review of length arithmetic in management frame parsers. Verified with a KUnit case under Generic KASAN on arm64 under QEMU; I do not have the hardware, so it is not tested on a real device. Fixes: b453872c35cf ("[NET] ieee80211 subsystem") Assisted-by: Claude:claude-opus-5 Signed-off-by: Shmulik Cohen --- drivers/net/wireless/intel/ipw2x00/libipw_rx.c | 3 +++ 1 file changed, 3 insertions(+) diff --git a/drivers/net/wireless/intel/ipw2x00/libipw_rx.c b/drivers/net/w= ireless/intel/ipw2x00/libipw_rx.c index c8841f9b9ad9..2661dac6985e 100644 --- a/drivers/net/wireless/intel/ipw2x00/libipw_rx.c +++ b/drivers/net/wireless/intel/ipw2x00/libipw_rx.c @@ -1421,6 +1421,9 @@ static void libipw_process_probe_response(struct libi= pw_device #endif unsigned long flags; =20 + if (stats->len < sizeof(*beacon)) + return; + LIBIPW_DEBUG_SCAN("'%*pE' (%pM): %c%c%c%c %c%c%c%c-%c%c%c%c %c%c%c%c\n", info_element->len, info_element->data, beacon->header.addr3, --=20 2.50.1 (Apple Git-155) From nobody Tue Sep 29 04:10:16 2026 Received: from mail-wr1-f49.google.com (mail-wr1-f49.google.com [209.85.221.49]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 02C393112A5 for ; Wed, 12 Aug 2026 19:06:03 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.221.49 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786561565; cv=none; b=lBfYSaQAL3AgIgwPRU4gFMLRQwiU7eqitb1PJRWBShvgUWdmDg/5ZdreuRu5uu75O0oVnzUqUfZ3VtF62WatIRSPXMyUPt2z1h64UoMPhjv71iRgiK5fY/uouv8rAXzmOUeQJfFy2E49NWzuFMiyEyOm0I+MusHy1lWMqHTBHOU= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786561565; c=relaxed/simple; bh=XgKH/QMgnQwl7EBN8sR3LbzgpflW0fob5QcEkkgOi6c=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=pVTyG4M5O05CSiNNzpxO2nv2Mi/f6+tUEj+VCgQ2Zs8XbRttVZuL4RyytILZmf5Kfhd74O/nqAKQe2/Mj7QkivJhap1xf9ti7foYrCtUx2hxqj6jwbVFRnc7Vt7ysdvkFUjlKsutIBOfWH2Zd2fIbewTDa58qbWYfX+tWgLJhbI= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=JAHV+02N; arc=none smtp.client-ip=209.85.221.49 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="JAHV+02N" Received: by mail-wr1-f49.google.com with SMTP id ffacd0b85a97d-47fe2d179e2so788484f8f.1 for ; Wed, 12 Aug 2026 12:06:03 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1786561562; x=1787166362; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=/1tMxUnulpGOwRXNg8wdc8brX/d0czOuEVfcemqNqzM=; b=JAHV+02NPqcAu4lrYJDl3p7Pdi8ohEOQCtgshlnKQ1CduvJ+s1KmkNY91liKpASGzk oQJ8TBZ3t0s0BcUD7mCDF5LvuRXH2zTGxNo55U+pJubBYeESrAGxOg1NfC7JtL07+Z9A rUC6fWGhCC+iGoo2IOQ2HHBC+ay9Uk48zfBiUCY7KLGHTciid/urCDJd2blkmCZctXml HtX7UPwwCRl589p23rgSKgsqoo2CtewVbL1QSEafkM0FOxpD3NYDVP/7chj6G2cnp7q9 obxW8gngUIRWwUjqUIuKhEgHZBVp09muzMjiexeZt86RsSGN+muhx59sr2U0X9chQLOb 6eGA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786561562; x=1787166362; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=/1tMxUnulpGOwRXNg8wdc8brX/d0czOuEVfcemqNqzM=; b=N/7bCZ4nV/pSP+3FKUBkgiOF0zwfAPcPp0Yo3XRv0aMERSGB3Y7ewK5VeuQd0p3QEB SiOdAfH8+dS+Rmh1PK/PUifWIiXExY2+AuUhaFb6ExlMk+QXXWo/ojG8y7n1k80qndpP ZsWYP/iIeVp2L9n7ZTNlW/tJgOn+7AqimA44Q3pO6Fuzv3mn67ZmzYN/N1POmEjZQkFd KbKZrDKHb28wKp7un0tSLZL2bWbD+MkWk+Xud/AhIDbRO4fAWiYX7mj0NV+vFFTq9rKL BK8xtod1TJAx8g/IVqBEXDtLqT4ZKGP7VWLLx102K/SXKLh6jwTPUPO3xO2w4eDnAARF EuRw== X-Forwarded-Encrypted: i=1; AHgh+Rps4XvTjzI37g0gCH7SMt6gKcfpC/gzrOyuV0LC7LVpnTWG32iEbs6DlIcxT79leLCcP07H/1a4y47mPHo=@vger.kernel.org X-Gm-Message-State: AOJu0Yw/v20+HbIJjT/gA7//YauIEqx0Et47BE3Gy56J1rEuDUPRbq9w cT9azruv0RD9iNgYkiNZtBR7lDDuJGV89ewgPqQAVnBYEkO8kAMRx9fY X-Gm-Gg: AR+sD10QEK0jVtM+Oy7Spmsfx26JJxNnS3/wKB/wlpLl1y4mn9FbtnNQ61l4kj1ru53 gig+8CBJn9dCpGZGNSvwnpu9ps1tT0EkSat7s/2+xoGkuf9ITpDdVSRM3tJLdVhEWRtG3PVVf8I P0WOPRKBNRg+4ZGABwzUNLyUiAeAIcgjS8Z4ThHf5ytBYXOuFtdr5wLtYE9J7NDqtByfUZbGLXT gxtoDvSSytPz1KsDxQlYmNBo8qwlWG4gkzjJ6O1CqWV5BHztBIHwY9AqNaEKwLvl77LWd595DOz 3DfBPTGGYz0aTVH8PKJA4TpShTMUxpX7Mr6EW1aaIxAqRflrQxHlLzujNS3ZTASzO022LaWhdlW 4PmstZ+JAsSj5P1AmZG+qOnMR/WMejyQTzmbRnYZIC2jWX0m6uJJGlLzygjiMQJPWzkM6ircrg5 B60iV2j6/X8qHFfdBOIojFxVt1fJGlA9eynshViioRNMff/qLF5hrwo7bohCwLHqX4Fivg31g6e VM00xD0SAyaOIibaduCSMaCZw60NqOUxVyECapn3WicPTF721uK/Hc+ALbn+JeJIdW1KYAub9a+ 8dBxHg== X-Received: by 2002:a5d:50cc:0:b0:481:51ce:542f with SMTP id ffacd0b85a97d-4815a028804mr313422f8f.21.1786561561990; Wed, 12 Aug 2026 12:06:01 -0700 (PDT) Received: from Mac.home ([95.35.242.1]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-48150d5eb2csm9179875f8f.30.2026.08.12.12.06.00 (version=TLS1_3 cipher=TLS_CHACHA20_POLY1305_SHA256 bits=256/256); Wed, 12 Aug 2026 12:06:01 -0700 (PDT) From: Shmulik Cohen To: stas.yakovlev@gmail.com Cc: johannes@sipsolutions.net, linux-wireless@vger.kernel.org, linux-kernel@vger.kernel.org, Shmulik Cohen Subject: [PATCH 2/3] wifi: libipw: reject too-short association responses Date: Wed, 12 Aug 2026 22:04:11 +0300 Message-ID: <20260812190412.18333-3-anuk909@gmail.com> X-Mailer: git-send-email 2.51.2 In-Reply-To: <20260812190412.18333-1-anuk909@gmail.com> References: <20260812190412.18333-1-anuk909@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" libipw_handle_assoc_resp() reads the capability, status and aid fields of the 30-byte association response prefix and then computes the information element length as stats->len - sizeof(*frame) stats->len is a u16 and sizeof() has type size_t, so the subtraction is evaluated as size_t and wraps instead of going negative. Truncating that to the u16 length parameter of libipw_parse_info_param() turns a frame shorter than the fixed fields into a length near 64 KiB, and the parser then reads past the receive buffer. Both the ipw2100 and ipw2200 management receive paths reach this function having established only that the frame carries the generic 24-byte three-address header. Reject the frame before any fixed field is touched. Found by an AI-assisted review of length arithmetic in management frame parsers. Verified with a KUnit case under Generic KASAN on arm64 under QEMU; I do not have the hardware, so it is not tested on a real device. Fixes: 9e8571affd1c ("[PATCH] ieee80211: Add QoS (WME) support to the ieee8= 0211 subsystem") Assisted-by: Claude:claude-opus-5 Signed-off-by: Shmulik Cohen --- drivers/net/wireless/intel/ipw2x00/libipw_rx.c | 3 +++ 1 file changed, 3 insertions(+) diff --git a/drivers/net/wireless/intel/ipw2x00/libipw_rx.c b/drivers/net/w= ireless/intel/ipw2x00/libipw_rx.c index 2661dac6985e..424349a6935e 100644 --- a/drivers/net/wireless/intel/ipw2x00/libipw_rx.c +++ b/drivers/net/wireless/intel/ipw2x00/libipw_rx.c @@ -1209,6 +1209,9 @@ static int libipw_handle_assoc_resp(struct libipw_dev= ice *ieee, struct libipw_as struct libipw_network *network =3D &network_resp; struct net_device *dev =3D ieee->dev; =20 + if (stats->len < sizeof(*frame)) + return 1; + network->flags =3D 0; network->qos_data.active =3D 0; network->qos_data.supported =3D 0; --=20 2.50.1 (Apple Git-155) From nobody Tue Sep 29 04:10:16 2026 Received: from mail-wm1-f48.google.com (mail-wm1-f48.google.com [209.85.128.48]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 895373112A5 for ; Wed, 12 Aug 2026 19:06:08 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.128.48 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786561570; cv=none; b=IgRwj5WmY7HIwjG6p39J2UD3GZF1/vr1qbG/HmYsXCQLWgh2QobiM+C3i7Xpj07OlQI53BgNEfYk/0qhUv3gwbqAAkbTnNo7RQbH7IKQJwg6fiiUnY5r+4bXy5FyFh6N43JenglIJJleDbcrWo3IBbAYvKsJ50xTP2+XAKjpEKY= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786561570; c=relaxed/simple; bh=T3sPnoq0RTs0uG8HPlVWHRGrVSNIKWFyaLvT/6yrFPQ=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=h3xMgDcxeXeNajXP3oupEC/uktd6WMSyJuK2sc/ir2DRV+smdrcC1p+Ftr4wpjulBOivYUSQAQFWL6dfcdhvvDV/qWXYFav+SHyyb4OwkNss5KrQM5Cb+c16+UFcilQbEAe1VUkLaH9whLksqDCJfePVU3wykfM1OCzISY3YsPY= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=XXQC3PK3; arc=none smtp.client-ip=209.85.128.48 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="XXQC3PK3" Received: by mail-wm1-f48.google.com with SMTP id 5b1f17b1804b1-495757ccbc1so11680345e9.2 for ; Wed, 12 Aug 2026 12:06:08 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1786561567; x=1787166367; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=jw5hnegB1m/L5wmsBBcHwaBQGgRjAN6McFTUJSuZSpc=; b=XXQC3PK3c6w2rexY4dXeMslJdD5bFihF0Bx3NXelxugdDn0Yu5z9yK5IS0Im3OXpcQ qLQTSAUGUl0SUAkS05b7yqbd0j1PKt44rGDk4FkFTuu+qJCW2cZx5sQyT+6au8UZlN3A xth5o+Lx9YGdfl3bszCwMGZ8TSqiecsCaGapwUULvLYoXVIFHRtMcOIw7IwmSBYwxrbR S7qfYsgqXnTjvLpBo9zDynZwh8vn9VobxQYFBX9017/aL9bxyL5xufBsRwhOCyk00/L9 V3bpjKuI2WlDbIPL3SRaGy/0/3vhwOCZmJWvB+DiLQh+yZn0YEIxDFgZ7o5PK4C3PrOH XzPA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786561567; x=1787166367; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=jw5hnegB1m/L5wmsBBcHwaBQGgRjAN6McFTUJSuZSpc=; b=YFS2WzZNEAbPqEp7jC7B3y4+FkskIwRjFm6eKobpNFpUSxMuPzJ4WllnXnr9L7B5SG sf+xRo42pvp1EO77R1wsBZ4TnElsZB99BZtkzXXMEC7EzFyuz32/Nno94SkTYV//aLAy m3IrzhJS0dcHil+BwwJ92ARAXcpJJ+RGCYO362XBDQtotV9TRE9n24P0l0eGFaUVb9qm E08NyVnWAqyBydELsXdmyPhKu2xEIT8GDKuVehl6jsLxsojxrnCw4GVsefqT+iHc9I0q cmWIgVlIGioLN1uczR1/FP/PIjpyFJlsjLFkuxtsi0QavZwzijd/wsvJUpJmCABWid1B kucQ== X-Forwarded-Encrypted: i=1; AHgh+Ron1XiK7f4EaNgfDDTPoOEYymq9fE9Y8z5S+UY2JkU/+bjJEoZFFUBffdhTRFOpLvha5af3er0ivuBb6ec=@vger.kernel.org X-Gm-Message-State: AOJu0YzCqFOUnZSpqmYzv1/anVjpmv2nRAuSbZHTJCHTgkinxooJ1bFe 2/1ahchRslqaEcS3B25Dr6T6g5CbrZniAyQ4tmkixIY7oRdiOJncuH/n X-Gm-Gg: AR+sD13u7AhseOXGzmFVITCOAqAG8jXIyYhjpXEQZiIIzkCVB8MJ9bjabqWUa05rY/T cL56XvJXXn7aT2vZni/85E3gQ4hx20AsmfB+dPvyRkFqwyxJ0JzyZvej7CnM/aizB71AH25O+k4 8NKHYetjgof+IgyneyZyFwqRQOQQvkA95dzdCxLcP2bR3tLFGRuFxeua7ExhN8Go+5f9fqCOSam CloC8/M1G/IP0fTIemV1PfD0fHSXEBk2Vf5ezZ1uLABarXmZIwbxPRUwXyw36C+RnPEyBGouOjK vb+PFGmRV0woN/hXmwd/BbDo5TfVFFyCz4cUscY2VRrfdvZwv6sCONE/SH5fmehdsg9IjVDCqyD KbujD3U/y7rHSS2brmxnSUKE80RwQKtu3x7wBrzQ7tBeshyBSCpN1GqLdnWIng6G35Yq5gkDPpv 7cY/I4uBrwm6l8AJ1x4nvHfBFSq7pgP6NQvf5Pt16wPeXGG5W1lITFpIVBWcgcu6YN3w6J+/ICc GLqRz2DQzoXZvVbcAsbvEfknUcTybU21Si4NTVpdHAEtiZG61DvYAniGDFdjJ4JQcVaeVM9RQGq iZY+Wg== X-Received: by 2002:a05:600c:46c6:b0:498:ee7:e407 with SMTP id 5b1f17b1804b1-4997c1649f5mr87009305e9.17.1786561566686; Wed, 12 Aug 2026 12:06:06 -0700 (PDT) Received: from Mac.home ([95.35.242.1]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-48150d5eb2csm9179875f8f.30.2026.08.12.12.06.04 (version=TLS1_3 cipher=TLS_CHACHA20_POLY1305_SHA256 bits=256/256); Wed, 12 Aug 2026 12:06:06 -0700 (PDT) From: Shmulik Cohen To: stas.yakovlev@gmail.com Cc: johannes@sipsolutions.net, linux-wireless@vger.kernel.org, linux-kernel@vger.kernel.org, Shmulik Cohen Subject: [PATCH 3/3] wifi: ipw2x00: bound management frame length to the receive buffer Date: Wed, 12 Aug 2026 22:04:12 +0300 Message-ID: <20260812190412.18333-4-anuk909@gmail.com> X-Mailer: git-send-email 2.51.2 In-Reply-To: <20260812190412.18333-1-anuk909@gmail.com> References: <20260812190412.18333-1-anuk909@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" Both management receive paths establish a lower bound on the frame length and no upper bound, even though the length originates from the device. ipw2100_corruption_check() returns 0 without inspecting frame_size for management frames, and __ipw2100_rx_process() only rejects a frame smaller than the three-address header, so any reported size up to the u32 limit reaches libipw_rx_mgt() against a receive allocation of IPW_RX_NIC_BUFFER_LENGTH bytes. Check frame_size itself rather than stats.len, which is a u16: a size of 65566 truncates to 30 on assignment and would pass a check made afterwards. ipw_rx() likewise only rejects a frame shorter than the header length. Bound it against the DMA mapped receive buffer. The size passed to alloc_skb() is rounded up by the allocator, so skb_tailroom() can exceed IPW_RX_BUF_SIZE and is not a usable bound here; the existing uses of that idiom in the data paths are too permissive for the same reason. libipw then hands the remainder to libipw_parse_info_param(), which walks information elements for as long as the length allows, so an over-long reported length reads past the receive buffer without any wraparound being involved. The length is device-reported, so per Documentation/process/threat-model.rst this is a robustness fix rather than a vulnerability. Found by an AI-assisted review of length arithmetic in management frame parsers. Compile-tested only for these two hunks; I do not have the hardware, so they are not tested on a real device. Assisted-by: Claude:claude-opus-5 Signed-off-by: Shmulik Cohen --- drivers/net/wireless/intel/ipw2x00/ipw2100.c | 4 +++- drivers/net/wireless/intel/ipw2x00/ipw2200.c | 9 +++++++++ 2 files changed, 12 insertions(+), 1 deletion(-) diff --git a/drivers/net/wireless/intel/ipw2x00/ipw2100.c b/drivers/net/wir= eless/intel/ipw2x00/ipw2100.c index 2b8a23865bfb..43b4e432956b 100644 --- a/drivers/net/wireless/intel/ipw2x00/ipw2100.c +++ b/drivers/net/wireless/intel/ipw2x00/ipw2100.c @@ -2712,7 +2712,9 @@ static void __ipw2100_rx_process(struct ipw2100_priv = *priv) break; } #endif - if (stats.len < sizeof(struct libipw_hdr_3addr)) + if (sq->drv[i].frame_size < + sizeof(struct libipw_hdr_3addr) || + sq->drv[i].frame_size > IPW_RX_NIC_BUFFER_LENGTH) break; switch (WLAN_FC_GET_TYPE(le16_to_cpu(u->rx_data.header.frame_ctl))) { case IEEE80211_FTYPE_MGMT: diff --git a/drivers/net/wireless/intel/ipw2x00/ipw2200.c b/drivers/net/wir= eless/intel/ipw2x00/ipw2200.c index 4bc9bb406e8e..8249d493ee22 100644 --- a/drivers/net/wireless/intel/ipw2x00/ipw2200.c +++ b/drivers/net/wireless/intel/ipw2x00/ipw2200.c @@ -8322,6 +8322,15 @@ static void ipw_rx(struct ipw_priv *priv) break; } =20 + if (unlikely(le16_to_cpu(pkt->u.frame.length) > + IPW_RX_BUF_SIZE - + IPW_RX_FRAME_SIZE)) { + IPW_DEBUG_DROP("Received oversized packet. Dropping.\n"); + priv->net_dev->stats.rx_errors++; + priv->wstats.discard.misc++; + break; + } + switch (WLAN_FC_GET_TYPE (le16_to_cpu(header->frame_ctl))) { =20 --=20 2.50.1 (Apple Git-155)