From nobody Mon Sep 28 10:44:10 2026 Received: from mail-qt1-f178.google.com (mail-qt1-f178.google.com [209.85.160.178]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 6066E33F8B2 for ; Sat, 22 Aug 2026 16:52:18 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.160.178 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787417540; cv=none; b=MVsguO7MX8s+WdzKnWBk3I8tvlhlHSA9+HSIwP3c51G2vsmL/SFuYSJFOYPUl4v7IxMi6/zz51cxgvAlpUueQPPip1Ao3wJbuY+W0O2KtqKUi58ANS/eY5qb2Pa86aQo3HnTHAVwChIBpEszFA7wkbH/YJSVilnuxRCNXSVWsCE= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787417540; c=relaxed/simple; bh=DByPZRUvyVcEdHD1jpRTlxqduptfCBNbhR048Af42tQ=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=Jue+6JPEpwtvVVFhOa6Q6uJDmCsN2S/RH+0wIMpnk6n+p1L8/29IwwHwRjB74puLAhQxcxTexHeymaa+n9o7aUKkcOsoLan3S7Tq8S9EtHNfPRQHVCuJ5PhsKXZeYRLRrtusC4NFPzW1eHNvkrUVPJsQNEi6JhDpspTOZE0vQ5I= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=kabsSs8m; arc=none smtp.client-ip=209.85.160.178 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="kabsSs8m" Received: by mail-qt1-f178.google.com with SMTP id d75a77b69052e-52d5bfa4bafso21151491cf.3 for ; Sat, 22 Aug 2026 09:52:17 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1787417537; x=1788022337; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=Tzs5YoNsBThnaikyqAQZp9SOqHfVyefiIDTKcmb/YvU=; b=kabsSs8mBV6ioyMIFKy7cbWcVD1130DI5qnGcxAeTaBz/b9G1a0sBeFsgMGYQxEEQp ExvuQkMlWvC5vLEaCJOzcdjETRSDlw78SRi7zoCOt/j+vYA9X18sYRuUyTyQG0RrSXcX BtqptQEG0YYnCIgwwmMJIFLKiuLwMH14jtewZ637MN+9tWDTsdmpkYeb7DrMiZHhdJqh 4DZDJniIaEhyIyFmClyDM8Jo4P2Bt5WcYRH7CztEEPKWaea8BSCDd48A9XYSFexolugN AyLuhY5aGca1tYIBTCYBqUV7ZqnZ0DgC2k5gPruwFD5UgDAeJ5hgzhCnXGu+tbaDJ/OV Plfg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787417537; x=1788022337; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=Tzs5YoNsBThnaikyqAQZp9SOqHfVyefiIDTKcmb/YvU=; b=pEKiKSKM6kXTICBogl06Q7CTRq1PP6w9Y7wkS4QsvqecI43FDt4Pa1NsxIcSA4KljZ CaBqdaFdqTSNtRPxRdEGDWreNQyoUJkR12WmKwQhiXHm+Yl6aFwow4ehMfVfu337Wnev AQGd21sSqJOfbhx83tKlBSJeYTHC3y/ztqbbz57CE5Adr0qwm5XI58KYfChrmJ94/Ish 0P2Q/ZRvLwNSKLArDTu8o0GnZdd6FyHnIHfQEMBJFiTSXkesBhtTxA83U2m7xxRZYVrZ te/OvEMoWqlhJOr+pPFlckeMRSfLi2YQDQq7649uZD/vy2FjwX33iG3Gtbcq6Wtl38if ErhA== X-Forwarded-Encrypted: i=1; AHgh+Rp8QxmOUz72ge2QpDkoHox2fkuaYiLGwMVBlqhNdXcCGvc96GarGlMJtbUetEhtyo34gCRrQNjL8tYKb0E=@vger.kernel.org X-Gm-Message-State: AFuF++kKhqGVyB2rS3Fa+xSnJ0DEvNiYu/ok/SruD4L07y6mDxpn4/9M AtdCxfjiivvrFETFm7duldU/p2gF3+zrioTwpEm22/y9JvfOI6rPdKoiul1TFLsY X-Gm-Gg: AR+sD11zc0acCuL79uTyCG6TSqmYtj+/KPiKNc3Ch2dUwJ/lzj7F7wzBacxrzDbXV2I 8OzS9DBOBSxFWzOiFzOl1qGOf4z7Ye7lBhsoIjLvFMJKA+Q2uOkYuRfE+aofnDzuE0XspU0bWek S3JdHu4RSNRwxcWWHgxc2ZEx4F5/ILZ0hw0JuGDfX+uJnttSPKjE7ie0qL3wjFzDqwU5Hpob8pC 79MnfOQB2rg2UiKjwZAZ0GbJ0RAHP1gs98uvIHr7zuPSr16q8gsYpJlWJ7cv/x+52vLWlc+pFJf ECbGCFISIaHk3PUC7wFcKEZnot1fOeYZ3JxmY5HEQSJzeW6nf4ilTi26HXLOHYXzcVgxaqw36AR eruXeHeokKK/XLzC3MePOuXzz+te+YdFYk2V3ULH09/m4ROZKby7oOKeaTqczIWplBliQ6ty5OH 6XNt2g8Goy3zYDr3+dnCTtRLnvF9+aaCLsTdmR06N7orYfT2/mYnduvCCRXV9/LpIhLU9b6/WQm 2GHYBXe+sOOO6hdAw5epPeypP4YAg== X-Received: by 2002:ac8:58c9:0:b0:52d:796d:4563 with SMTP id d75a77b69052e-52df585c299mr147209511cf.26.1787417536703; Sat, 22 Aug 2026 09:52:16 -0700 (PDT) Received: from reolab.localdomain ([146.70.168.136]) by smtp.gmail.com with ESMTPSA id 6a1803df08f44-90c935e63e3sm17779056d6.5.2026.08.22.09.52.14 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sat, 22 Aug 2026 09:52:16 -0700 (PDT) From: Amir Mohammad Jahangirzad To: johannes@sipsolutions.net Cc: linux-wireless@vger.kernel.org, linux-kernel@vger.kernel.org, Amir Mohammad Jahangirzad Subject: [PATCH] mac80211: mesh: Fix missing bounds checks in prepare_for_gate() Date: Sat, 22 Aug 2026 20:21:17 +0330 Message-ID: <20260822165117.34396-1-a.jahangirzad@gmail.com> X-Mailer: git-send-email 2.55.0 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" When moving or copying frames to a gate mpath, prepare_for_gate() processes incoming packets by reading the MAC header and modifying the packet to add Address Extension (AE) fields if necessary. However, the function lacked proper bounds checking on the incoming skb, exposing the code to potential crashes and out-of-bounds reads. Specifically, the function calculates `hdrlen` from the frame control field and then directly accesses the mesh header at `skb->data + hdrlen` without checking if `skb->len` is actually large enough to hold this data. If a truncated packet is processed, this can result in an out-of-bounds read. Furthermore, when the packet does not have the Address Extension flags, the function calls `skb_push(skb, 2 * ETH_ALEN)`. It performs this push without verifying if the `skb` actually has enough headroom available. If a packet exhausts the available headroom, this will trigger a BUG() in `skb_push` and cause a kernel crash. This patch fixes these issues by validating `skb->len` before reading any headers and checking `skb_headroom()` before modifying the packet. `prepare_for_gate()` is modified to return an `int` (-EINVAL on failure), and its caller is updated to gracefully drop malformed packets instead of queueing them. Signed-off-by: Amir Mohammad Jahangirzad --- net/mac80211/mesh_pathtbl.c | 21 +++++++++++++++++---- 1 file changed, 17 insertions(+), 4 deletions(-) diff --git a/net/mac80211/mesh_pathtbl.c b/net/mac80211/mesh_pathtbl.c index 03171cf00855..b344f305a85f 100644 --- a/net/mac80211/mesh_pathtbl.c +++ b/net/mac80211/mesh_pathtbl.c @@ -131,22 +131,32 @@ void mesh_path_assign_nexthop(struct mesh_path *mpath= , struct sta_info *sta) spin_unlock_irqrestore(&mpath->frame_queue.lock, flags); } =20 -static void prepare_for_gate(struct sk_buff *skb, char *dst_addr, - struct mesh_path *gate_mpath) +static int prepare_for_gate(struct sk_buff *skb, char *dst_addr, + struct mesh_path *gate_mpath) { struct ieee80211_hdr *hdr; struct ieee80211s_hdr *mshdr; int mesh_hdrlen, hdrlen; char *next_hop; =20 + if (skb->len < sizeof(struct ieee80211_hdr)) + return -EINVAL; + hdr =3D (struct ieee80211_hdr *) skb->data; hdrlen =3D ieee80211_hdrlen(hdr->frame_control); + + if (skb->len < hdrlen + 6) + return -EINVAL; + mshdr =3D (struct ieee80211s_hdr *) (skb->data + hdrlen); =20 if (!(mshdr->flags & MESH_FLAGS_AE)) { /* size of the fixed part of the mesh header */ mesh_hdrlen =3D 6; =20 + if (skb_headroom(skb) < 2 * ETH_ALEN) + return -EINVAL; + /* make room for the two extended addresses */ skb_push(skb, 2 * ETH_ALEN); memmove(skb->data, hdr, hdrlen + mesh_hdrlen); @@ -169,6 +179,7 @@ static void prepare_for_gate(struct sk_buff *skb, char = *dst_addr, rcu_read_unlock(); memcpy(hdr->addr2, gate_mpath->sdata->vif.addr, ETH_ALEN); memcpy(hdr->addr3, dst_addr, ETH_ALEN); + return 0; } =20 /** @@ -218,8 +229,10 @@ static void mesh_path_move_to_queue(struct mesh_path *= gate_mpath, if (WARN_ON(!skb)) break; =20 - prepare_for_gate(skb, gate_mpath->dst, gate_mpath); - skb_queue_tail(&gate_mpath->frame_queue, skb); + if (prepare_for_gate(skb, gate_mpath->dst, gate_mpath) =3D=3D 0) + skb_queue_tail(&gate_mpath->frame_queue, skb); + else + kfree_skb(skb); =20 if (copy) continue; --=20 2.55.0