From nobody Tue Sep 29 00:34:17 2026 Received: from mailgw.kylinos.cn (mailgw.kylinos.cn [124.126.103.232]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 488E746C859; Fri, 14 Aug 2026 12:28:23 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=124.126.103.232 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786710507; cv=none; b=RtsnAPxWw0LxPKQWir1Oe+4MIN4G41y5gOpDz/9H53oWG3j06h1eLFiBymnkib5eCrKpAbg/KMMH7+omS++AvCzAwduERYHXt0IW/cTOe0c2MpObJA/eqnIm0n703UOnlg1aaLJKHDdptcMqv9Xa9LQMK39G+aTH5y3JULnAlLw= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786710507; c=relaxed/simple; bh=lzkWAFAEM5ZUpn7TE98LwjsTtc4ludonkbm3ESilUWU=; h=From:To:Cc:Subject:Date:Message-Id:In-Reply-To:References: MIME-Version; b=Uy9x/YOzQTZiLAy1YLaAxmYCANcNb8JdjAgkrgF+BkA4Squz+8klKVw1sSKmUGX0ZkLM0xaqYowtxsj7XsobYeeKogfaG8ILrIf+gExyuoWNCuCmt+bMB+5KBKJe+WnLuxTu/oPvQiE18qOHnxKJwTx3le/A2uJRrigCwjzn1NY= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=kylinos.cn; spf=pass smtp.mailfrom=kylinos.cn; arc=none smtp.client-ip=124.126.103.232 Authentication-Results: smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=kylinos.cn Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=kylinos.cn X-UUID: a054ac1697db11f1aa26b74ffac11d73-20260814 X-CID-P-RULE: Release_Ham X-CID-O-INFO: VERSION:1.3.12,REQID:80524ab1-acb7-411a-a404-bffb664c1fc1,IP:0,U RL:0,TC:0,Content:-25,EDM:25,RT:0,SF:0,FILE:0,BULK:0,RULE:Release_Ham,ACTI ON:release,TS:0 X-CID-META: VersionHash:e7bac3a,CLOUDID:81179d32ce9a0963e74b9ff468a2bbe1,BulkI D:nil,BulkQuantity:0,Recheck:0,SF:81|82|102|850|865|898,TC:nil,Content:0|1 5|50,EDM:5,IP:nil,URL:0,File:nil,RT:nil,Bulk:nil,QS:nil,BEC:nil,COL:0,OSI: 0,OSA:0,AV:0,LES:1,SPR:NO,DKR:0,DKP:0,BRR:0,BRE:0,ARC:0 X-CID-BVR: 2,SSN|SDN X-CID-BAS: 2,SSN|SDN,0,_ X-CID-FACTOR: TF_CID_SPAM_SNR X-CID-RHF: D41D8CD98F00B204E9800998ECF8427E X-UUID: a054ac1697db11f1aa26b74ffac11d73-20260814 X-User: lilinmao@kylinos.cn Received: from localhost.localdomain [(10.44.16.150)] by mailgw.kylinos.cn (envelope-from ) (Generic MTA with TLSv1.3 TLS_AES_256_GCM_SHA384 256/256) with ESMTP id 1351507832; Fri, 14 Aug 2026 20:28:16 +0800 From: Linmao Li To: Jeff Chen Cc: Francesco Dolcini , Johannes Berg , linux-wireless@vger.kernel.org, linux-kernel@vger.kernel.org, Linmao Li Subject: [PATCH wireless-next 1/3] wifi: nxpwifi: validate the length of the VDLL indication event Date: Fri, 14 Aug 2026 20:28:08 +0800 Message-Id: <20260814122810.2999536-2-lilinmao@kylinos.cn> X-Mailer: git-send-email 2.25.1 In-Reply-To: <20260814122810.2999536-1-lilinmao@kylinos.cn> References: <20260814122810.2999536-1-lilinmao@kylinos.cn> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" nxpwifi_process_vdll_event() reads the ten-byte struct vdll_ind_event that follows the four-byte event cause without checking that the event is long enough to hold it. The receive path does not guarantee that: nxpwifi_sdio_decode_rx_packet() takes the event cause from the first four bytes and hands the skb on whatever its length is, copying an event body only when there is one. A short event therefore makes the driver read past the end of the buffer and then act on the type, offset and block length it finds there. Check the length before the header is dereferenced. Fixes: 73b01e57ed3e ("wifi: nxp: add nxpwifi driver for IW61x") Signed-off-by: Linmao Li --- drivers/net/wireless/nxp/nxpwifi/util.c | 21 +++++++++++++++------ 1 file changed, 15 insertions(+), 6 deletions(-) diff --git a/drivers/net/wireless/nxp/nxpwifi/util.c b/drivers/net/wireless= /nxp/nxpwifi/util.c index bbfefb81d8d3b..549661ca049a0 100644 --- a/drivers/net/wireless/nxp/nxpwifi/util.c +++ b/drivers/net/wireless/nxp/nxpwifi/util.c @@ -1255,15 +1255,24 @@ int nxpwifi_process_vdll_event(struct nxpwifi_priva= te *priv, struct sk_buff *skb) { struct nxpwifi_adapter *adapter =3D priv->adapter; - struct vdll_ind_event *vdll_evt =3D - (struct vdll_ind_event *)(skb->data + sizeof(u32)); - u16 type =3D le16_to_cpu(vdll_evt->type); - u16 vdll_id =3D le16_to_cpu(vdll_evt->vdll_id); - u32 offset =3D le32_to_cpu(vdll_evt->offset); - u16 block_len =3D le16_to_cpu(vdll_evt->block_len); struct vdll_dnld_ctrl *ctrl =3D &adapter->vdll_ctrl; + struct vdll_ind_event *vdll_evt; + u16 type, vdll_id, block_len; + u32 offset; int ret =3D 0; =20 + if (skb->len < sizeof(u32) + sizeof(*vdll_evt)) { + nxpwifi_dbg(adapter, ERROR, + "VDLL IND: event too short: %u\n", skb->len); + return -EINVAL; + } + + vdll_evt =3D (struct vdll_ind_event *)(skb->data + sizeof(u32)); + type =3D le16_to_cpu(vdll_evt->type); + vdll_id =3D le16_to_cpu(vdll_evt->vdll_id); + offset =3D le32_to_cpu(vdll_evt->offset); + block_len =3D le16_to_cpu(vdll_evt->block_len); + switch (type) { case VDLL_IND_TYPE_REQ: nxpwifi_dbg(adapter, EVENT, --=20 2.25.1 From nobody Tue Sep 29 00:34:17 2026 Received: from mailgw.kylinos.cn (mailgw.kylinos.cn [124.126.103.232]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 4879446C4A3; Fri, 14 Aug 2026 12:28:24 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=124.126.103.232 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786710507; cv=none; b=jrCFw+fn9eB48u4y9rXx0pWs1d+YACfbUQjUytg8we22Qm2UJlmxKTutRfROYAU00RSWu59RwSbS4q+ouCUQwwJmv9lp7JJ+ndQ13ViaiGs2aDGY4EfCbJrs/LFL9K+6sKi8GcRF7X9b6cc5ECkboN9OFJ6Kl8JnF0FYrIfWu4k= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786710507; c=relaxed/simple; bh=2P5Gc3Is03hQgwND7ruC36jXV4PUahlyxLtqscfpGvI=; h=From:To:Cc:Subject:Date:Message-Id:In-Reply-To:References: MIME-Version; b=bWN2cU9Cm0UeKFWCCR9uJhzayTJHc/G7ZkCANJ1vnGYKQIyAPwTn9Y7OzxSs0eDmsbmaCjiJitGnDWGoMQH6Wd3K3eCxtu1ySZguUTlQUzzZWiEEOQh1HEnS/UWnpCsv7YH/AmEmzMKJn0KIj+C+hgpQgArRz0Pt8Ji8NPS8eqE= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=kylinos.cn; spf=pass smtp.mailfrom=kylinos.cn; arc=none smtp.client-ip=124.126.103.232 Authentication-Results: smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=kylinos.cn Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=kylinos.cn X-UUID: a126e34897db11f1aa26b74ffac11d73-20260814 X-CID-P-RULE: Release_Ham X-CID-O-INFO: VERSION:1.3.12,REQID:e67fa118-135e-4dc6-9982-bfac917809a1,IP:0,U RL:0,TC:0,Content:-25,EDM:25,RT:0,SF:0,FILE:0,BULK:0,RULE:Release_Ham,ACTI ON:release,TS:0 X-CID-META: VersionHash:e7bac3a,CLOUDID:60df73f0ab7585f505f2084eac97868a,BulkI D:nil,BulkQuantity:0,Recheck:0,SF:81|82|102|850|865|898,TC:nil,Content:0|1 5|50,EDM:5,IP:nil,URL:0,File:nil,RT:nil,Bulk:nil,QS:nil,BEC:nil,COL:0,OSI: 0,OSA:0,AV:0,LES:1,SPR:NO,DKR:0,DKP:0,BRR:0,BRE:0,ARC:0 X-CID-BVR: 2,SSN|SDN X-CID-BAS: 2,SSN|SDN,0,_ X-CID-FACTOR: TF_CID_SPAM_SNR X-CID-RHF: D41D8CD98F00B204E9800998ECF8427E X-UUID: a126e34897db11f1aa26b74ffac11d73-20260814 X-User: lilinmao@kylinos.cn Received: from localhost.localdomain [(10.44.16.150)] by mailgw.kylinos.cn (envelope-from ) (Generic MTA with TLSv1.3 TLS_AES_256_GCM_SHA384 256/256) with ESMTP id 1755544429; Fri, 14 Aug 2026 20:28:18 +0800 From: Linmao Li To: Jeff Chen Cc: Francesco Dolcini , Johannes Berg , linux-wireless@vger.kernel.org, linux-kernel@vger.kernel.org, Linmao Li Subject: [PATCH wireless-next 2/3] wifi: nxpwifi: reject VDLL blocks that do not fit the command buffer Date: Fri, 14 Aug 2026 20:28:09 +0800 Message-Id: <20260814122810.2999536-3-lilinmao@kylinos.cn> X-Mailer: git-send-email 2.25.1 In-Reply-To: <20260814122810.2999536-1-lilinmao@kylinos.cn> References: <20260814122810.2999536-1-lilinmao@kylinos.cn> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" nxpwifi_download_vdll_block() copies block_len bytes into ctrl->skb, a single NXPWIFI_SIZE_OF_CMD_BUFFER byte buffer allocated once at init time. block_len comes from the VDLL indication event and is clamped only against the length of the VDLL image, which is taken from the firmware file and is far larger than the command buffer. Two things go wrong once a block exceeds it. msg_len is a u16, so a block_len near 65535 wraps it to a small value: skb_put_zero() then reserves a few bytes while the memcpy() below still writes block_len bytes past the end of the buffer. Without the wrap, skb_put_zero() itself runs past the tail of the skb and panics. Reject a block that does not fit before the skb is touched. Fixes: 73b01e57ed3e ("wifi: nxp: add nxpwifi driver for IW61x") Signed-off-by: Linmao Li --- drivers/net/wireless/nxp/nxpwifi/util.c | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/drivers/net/wireless/nxp/nxpwifi/util.c b/drivers/net/wireless= /nxp/nxpwifi/util.c index 549661ca049a0..97811ee25f392 100644 --- a/drivers/net/wireless/nxp/nxpwifi/util.c +++ b/drivers/net/wireless/nxp/nxpwifi/util.c @@ -1228,6 +1228,12 @@ int nxpwifi_download_vdll_block(struct nxpwifi_adapt= er *adapter, u16 msg_len =3D block_len + S_DS_GEN; int ret =3D 0; =20 + if (block_len > NXPWIFI_SIZE_OF_CMD_BUFFER - S_DS_GEN) { + nxpwifi_dbg(adapter, ERROR, + "VDLL block does not fit: len: %d\n", block_len); + return -EINVAL; + } + skb_trim(ctrl->skb, 0); skb_put_zero(ctrl->skb, msg_len); =20 --=20 2.25.1 From nobody Tue Sep 29 00:34:17 2026 Received: from mailgw.kylinos.cn (mailgw.kylinos.cn [124.126.103.232]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 7FBC146D2A3; Fri, 14 Aug 2026 12:28:25 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=124.126.103.232 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786710513; cv=none; b=TIVF98ZyeoGm/twzPMMDatCW8d8lSNe3pUwgQGaBram6i1WCX/M9W2QzyYbr0LeFTl/hBstl01k4RfRcW71FnpnUlHnoz7/xvE0NIy4CiIMi+jOV1bMqVT3kTQMZxqbv8AE7ZWwfZQ6X/AzQB6qkQyIOTQ8YO+/kfst6aHL5e0Y= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786710513; c=relaxed/simple; bh=B/8nEI3SmiQ1pi08MAmCaBlVZm+8qxKzsozhKrTsI8I=; h=From:To:Cc:Subject:Date:Message-Id:In-Reply-To:References: MIME-Version; b=jSjgQNsMUHs5QmS7Ughn4gt8Ny7OvN7fRxJusilLm3SEaioKp2Oeag84jX75ZjURKdffYnEf+KVJlFJxDfbyM7Pr10gCRE1rXWMzHW5B7z5GGCkgOj4ORidaTWiouzfAV0RU+a8plgjTG/e/S6yh2lY7TvAAGDeLhZKpu293t/0= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=kylinos.cn; spf=pass smtp.mailfrom=kylinos.cn; arc=none smtp.client-ip=124.126.103.232 Authentication-Results: smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=kylinos.cn Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=kylinos.cn X-UUID: a1ff58c297db11f1aa26b74ffac11d73-20260814 X-CID-P-RULE: Release_Ham X-CID-O-INFO: VERSION:1.3.12,REQID:0e5453ea-b9ab-4482-ae39-0765930bae6e,IP:0,U RL:0,TC:0,Content:-5,EDM:25,RT:0,SF:0,FILE:0,BULK:0,RULE:Release_Ham,ACTIO N:release,TS:20 X-CID-META: VersionHash:e7bac3a,CLOUDID:3cbf55c59a5fe0538462ea6efaacdcd8,BulkI D:nil,BulkQuantity:0,Recheck:0,SF:81|82|102|850|865|898,TC:nil,Content:0|1 5|50,EDM:5,IP:nil,URL:0,File:nil,RT:nil,Bulk:nil,QS:nil,BEC:nil,COL:0,OSI: 0,OSA:0,AV:0,LES:1,SPR:NO,DKR:0,DKP:0,BRR:0,BRE:0,ARC:0 X-CID-BVR: 2,SSN|SDN X-CID-BAS: 2,SSN|SDN,0,_ X-CID-FACTOR: TF_CID_SPAM_SNR X-CID-RHF: D41D8CD98F00B204E9800998ECF8427E X-UUID: a1ff58c297db11f1aa26b74ffac11d73-20260814 X-User: lilinmao@kylinos.cn Received: from localhost.localdomain [(10.44.16.150)] by mailgw.kylinos.cn (envelope-from ) (Generic MTA with TLSv1.3 TLS_AES_256_GCM_SHA384 256/256) with ESMTP id 356174463; Fri, 14 Aug 2026 20:28:19 +0800 From: Linmao Li To: Jeff Chen Cc: Francesco Dolcini , Johannes Berg , linux-wireless@vger.kernel.org, linux-kernel@vger.kernel.org, Linmao Li Subject: [PATCH wireless-next 3/3] wifi: nxpwifi: release the firmware when the VDLL image does not fit Date: Fri, 14 Aug 2026 20:28:10 +0800 Message-Id: <20260814122810.2999536-4-lilinmao@kylinos.cn> X-Mailer: git-send-email 2.25.1 In-Reply-To: <20260814122810.2999536-1-lilinmao@kylinos.cn> References: <20260814122810.2999536-1-lilinmao@kylinos.cn> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" nxpwifi_get_vdll_image() requests the firmware file when the driver no longer holds it and drops that reference once the image has been copied. The error path taken when the requested VDLL length is not smaller than the firmware returns without dropping it, and nothing else releases adapter->firmware after the initial download completes, so the whole firmware image stays pinned for the lifetime of the adapter. Release it on that path too. Fixes: 73b01e57ed3e ("wifi: nxp: add nxpwifi driver for IW61x") Signed-off-by: Linmao Li --- drivers/net/wireless/nxp/nxpwifi/util.c | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/drivers/net/wireless/nxp/nxpwifi/util.c b/drivers/net/wireless= /nxp/nxpwifi/util.c index 97811ee25f392..1d664967ca854 100644 --- a/drivers/net/wireless/nxp/nxpwifi/util.c +++ b/drivers/net/wireless/nxp/nxpwifi/util.c @@ -1206,6 +1206,10 @@ static int nxpwifi_get_vdll_image(struct nxpwifi_ada= pter *adapter, u32 vdll_len) nxpwifi_dbg(adapter, ERROR, "Invalid VDLL length =3D %d, fw_len=3D%d\n", vdll_len, (int)adapter->firmware->size); + if (req_fw) { + release_firmware(adapter->firmware); + adapter->firmware =3D NULL; + } return -EINVAL; } if (req_fw) { --=20 2.25.1