From nobody Mon Sep 28 04:51:31 2026 Received: from sg-2-5.ptr.blmpb.com (sg-2-5.ptr.blmpb.com [71.18.227.5]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 3AB4D40DB49 for ; Wed, 26 Aug 2026 17:08:32 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=71.18.227.5 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787764120; cv=none; b=qenW7h9nOJeXTUL1dcsgXdnvkz2EpQVrB7r94KRSNZuk5HsSyaBzGQqXmfDpkuH2BdJjk4a2ww/7h7YPkjC2k+fEYU3C0575TxAg/zBif7USsoZKgwYzsH/+b88COBwGeJj4T10MswcIVVrgeNSCR9p90PT3xBnzSvXpIKwdsPU= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787764120; c=relaxed/simple; bh=4xBhgvMDLs/XLN2pd56fd3I5TV/RbHd5HZxG+sUGfYE=; h=In-Reply-To:Date:Content-Type:References:Cc:Message-Id:To:Subject: Mime-Version:From; b=WHYaIfFsg8ttYHWmOygsEMUDVXdMlVlr4oVOck1AIhXdjXKMGHDwtEE69PIR5kKXWpKknG2YCwEl5SL1DdDx00jVXgf/+yE/FDYph0NGX8lSvyz5Q5CXZOR3jLkbu1/9oaEiIJjw+Y1W7mBJysDHAH5Mrkl0eCIEIuPWQYMSp5Q= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=cherr.cc; spf=pass smtp.mailfrom=cherr.cc; dkim=pass (2048-bit key) header.d=cherr.cc header.i=@cherr.cc header.b=lr8a2Wyd; arc=none smtp.client-ip=71.18.227.5 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=cherr.cc Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=cherr.cc Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=cherr.cc header.i=@cherr.cc header.b="lr8a2Wyd" DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; s=feishu2604220257; d=cherr.cc; t=1787764067; h=from:subject: mime-version:from:date:message-id:subject:to:cc:reply-to:content-type: mime-version:in-reply-to:message-id; bh=PJ594cLpPW6v3aDbK0/v/dsM4wWK1cUjGz46u5+Upc8=; b=lr8a2WydUUTX98ut1cOxoPJt1e3sxlbvLI3l9DmCiBzlw0KJPSq9c5axlmNijbfTm34PHz 5loafIostJobZknPqe4IRoIp0SBuTI8KZyWtPG+TrqtPc4Y+Nav6x5+bKz6a3ekQPbWz8i dHfHWBsxf51a86oYVV/ryoGlGCe8SsyOdw4wno+A2QKuemCbdqWoLXh4tcyZSgcGee6mAN 7pB2jD3sdCNt0kFA3nHor15GFw6EU8YA6U7uxBWCkD5xV+rnB8rvGfXl2PhTyz0m364CJl BxOEwwln4A3+VIMg2qUtH10cKhVMgJfmUd7+Sfid/BSIIgLJ/hArm0FYKuiUpA== X-Mailer: b4 0.14.2 In-Reply-To: <20260827-p54-pda-validation-v1-0-bdc2b0675056@cherr.cc> X-Lms-Return-Path: Content-Transfer-Encoding: quoted-printable Date: Thu, 27 Aug 2026 01:07:39 +0800 References: <20260827-p54-pda-validation-v1-0-bdc2b0675056@cherr.cc> Cc: , , , "Shengzhuo Wei" Message-Id: <20260827-p54-pda-validation-v1-1-bdc2b0675056@cherr.cc> Received: from [192.168.9.107] ([111.42.148.29]) by smtp.feishu.cn with ESMTPS; Thu, 27 Aug 2026 01:07:45 +0800 To: "Christian Lamparter" , "Michael Wu" , "John W. Linville" , "David S. Miller" Subject: [PATCH 1/2] wifi: p54: validate curve data length in p54_parse_eeprom() Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 X-Original-From: Shengzhuo Wei From: "Shengzhuo Wei" Content-Type: text/plain; charset="utf-8" p54_convert_rev0() and p54_convert_rev1() walk channels * (2 + points_per_channel * sizeof(sample)) bytes of the curve data entry, with both counts taken verbatim from the device-supplied EEPROM. An entry that declares channels=3D255, points_per_channel=3D255 but carries only the 4-byte header drives a ~191 KB slab-out-of-bounds read past the EEPROM buffer (verified with a KASAN reproducer of the conversion loop). The sibling converters p54_convert_output_limits() and p54_convert_db() already validate their counts against the entry length; this path was missed. Reject the entry when the counts do not fit in the entry data. Fixes: eff1a59c48e3 ("[P54]: add mac80211-based driver for prism54 softmac = hardware") Cc: stable@vger.kernel.org Assisted-by: GLM:5.3 Signed-off-by: Shengzhuo Wei --- drivers/net/wireless/intersil/p54/eeprom.c | 16 ++++++++++++++++ 1 file changed, 16 insertions(+) diff --git a/drivers/net/wireless/intersil/p54/eeprom.c b/drivers/net/wirel= ess/intersil/p54/eeprom.c index 95580921d933827c5eac55b79404e26bd7a57ba4..968ce9a411358e0e6b83117b1a0= 77becc3207090 100644 --- a/drivers/net/wireless/intersil/p54/eeprom.c +++ b/drivers/net/wireless/intersil/p54/eeprom.c @@ -763,6 +763,8 @@ int p54_parse_eeprom(struct ieee80211_hw *dev, void *ee= prom, int len) case PDR_PRISM_PA_CAL_CURVE_DATA: { struct pda_pa_curve_data *curve_data =3D (struct pda_pa_curve_data *)entry->data; + size_t needed; + if (data_len < sizeof(*curve_data)) { err =3D -EINVAL; goto err; @@ -770,9 +772,23 @@ int p54_parse_eeprom(struct ieee80211_hw *dev, void *e= eprom, int len) =20 switch (curve_data->cal_method_rev) { case 0: + needed =3D curve_data->channels * + (sizeof(struct pda_pa_curve_data_sample_rev0) * + curve_data->points_per_channel + 2); + if (data_len - sizeof(*curve_data) < needed) { + err =3D -EINVAL; + goto err; + } err =3D p54_convert_rev0(dev, curve_data); break; case 1: + needed =3D curve_data->channels * + (sizeof(struct pda_pa_curve_data_sample_rev1) * + curve_data->points_per_channel + 3); + if (data_len - sizeof(*curve_data) < needed) { + err =3D -EINVAL; + goto err; + } err =3D p54_convert_rev1(dev, curve_data); break; default: --=20 2.47.3 From nobody Mon Sep 28 04:51:31 2026 Received: from sg-2-4.ptr.blmpb.com (sg-2-4.ptr.blmpb.com [71.18.227.4]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 07ADA3AAF41 for ; Wed, 26 Aug 2026 17:08:03 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=71.18.227.4 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787764109; cv=none; b=unzSA00kiKHjKZGGRBcGTzuVUIj0Dv6LTR135VL+j+2kYXPXFAskViNwDIijDiVqzjvlqH++aRqxRRjPKi+Kc+s7bBIQX11wohlu72O4spbn7x8H+nr5jZNU8QSbqKkkmRuFiW68xAYUXu3qXJZJxapOYuQG3YytzqIf1UXG548= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787764109; c=relaxed/simple; bh=lA8uhkZaDW7Vi5VTYYunr4NGhJoC8vUeSIjSRZVsHBI=; h=In-Reply-To:From:Date:Cc:References:Content-Type:Subject: Message-Id:Mime-Version:To; b=OrtvaZVcQw/BNoTTmTHcjtTa8pzAXG1KYis6QHXdukfnZfjn/Hu0pnXQHlQiQRzHQ0h/cyapKSzA3jzg2ud9uweoEQsfSzQyaPTGt1u3pED5uS7xrAs8EpQNEskxIRR62U5Wku37ERxw0sOjTlGKJO5WhM+s+lZr/hJ1D/5W1k4= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=cherr.cc; spf=pass smtp.mailfrom=cherr.cc; dkim=pass (2048-bit key) header.d=cherr.cc header.i=@cherr.cc header.b=psu6tyQd; arc=none smtp.client-ip=71.18.227.4 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=cherr.cc Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=cherr.cc Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=cherr.cc header.i=@cherr.cc header.b="psu6tyQd" DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; s=feishu2604220257; d=cherr.cc; t=1787764069; h=from:subject: mime-version:from:date:message-id:subject:to:cc:reply-to:content-type: mime-version:in-reply-to:message-id; bh=YouVmwbOXKFmVb2f6IWbuJ+2i64UrcZ34QAzG438L0c=; b=psu6tyQdcrrnkkO6tYEsVLTgEuM9t/ECaJrSNYZ+9r+u1wLDWxXa15wn5Z8d3LMttpDfm2 iDxQrR/OfIfczWBvpJ5w2Alwl8svTFTOBOpgKaUUXSIuzYXfeTOfdPQFViK7vjvUEFCStl SaVDvkAveNE3f9VKE69mgGCQb7fMJkGU/zbcLV6ZwPD2M6eb4vJBNrVTLXWXkTBZaZ2ggy +jblA9mio1YLjLeLuct5e0lG9J6o6DDpW31OZGl3R/pCMNBuaKrlaFDIlGb58iOKuLY/d5 whvXsw0EgrVBEFqnQwHgOSZYaYDvFQqNUwzLhsunEUa/nnA3RKOxNz9GQWkguA== In-Reply-To: <20260827-p54-pda-validation-v1-0-bdc2b0675056@cherr.cc> From: "Shengzhuo Wei" Date: Thu, 27 Aug 2026 01:07:40 +0800 Content-Transfer-Encoding: quoted-printable Cc: , , , "Shengzhuo Wei" X-Lms-Return-Path: References: <20260827-p54-pda-validation-v1-0-bdc2b0675056@cherr.cc> X-Original-From: Shengzhuo Wei Subject: [PATCH 2/2] wifi: p54: require a full exp_if record in PDR_INTERFACE_LIST Message-Id: <20260827-p54-pda-validation-v1-2-bdc2b0675056@cherr.cc> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 Received: from [192.168.9.107] ([111.42.148.29]) by smtp.feishu.cn with ESMTPS; Thu, 27 Aug 2026 01:07:46 +0800 X-Mailer: b4 0.14.2 To: "Christian Lamparter" , "Michael Wu" , "John W. Linville" , "David S. Miller" Content-Type: text/plain; charset="utf-8" The PDR_INTERFACE_LIST loop only checks that the record start is within the entry before reading an entire struct exp_if from it. A truncated trailing record makes the if_id/variant reads cross the entry boundary into the heap beyond the EEPROM buffer (verified with a KASAN reproducer of the loop). The variant also feeds the synth front-end selection, so this is not only a leak. Advance only while a full record still fits in the entry. Fixes: eff1a59c48e3 ("[P54]: add mac80211-based driver for prism54 softmac = hardware") Cc: stable@vger.kernel.org Assisted-by: GLM:5.3 Signed-off-by: Shengzhuo Wei Acked-by: Christian Lamparter --- drivers/net/wireless/intersil/p54/eeprom.c | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/drivers/net/wireless/intersil/p54/eeprom.c b/drivers/net/wirel= ess/intersil/p54/eeprom.c index 968ce9a411358e0e6b83117b1a077becc3207090..472edecf55772893afdf8be3020= e6baaf80097a5 100644 --- a/drivers/net/wireless/intersil/p54/eeprom.c +++ b/drivers/net/wireless/intersil/p54/eeprom.c @@ -817,7 +817,8 @@ int p54_parse_eeprom(struct ieee80211_hw *dev, void *ee= prom, int len) break; case PDR_INTERFACE_LIST: tmp =3D entry->data; - while ((u8 *)tmp < entry->data + data_len) { + while ((u8 *)tmp + sizeof(struct exp_if) <=3D + entry->data + data_len) { struct exp_if *exp_if =3D tmp; if (exp_if->if_id =3D=3D cpu_to_le16(IF_ID_ISL39000)) synth =3D le16_to_cpu(exp_if->variant); --=20 2.47.3