From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-wm1-f54.google.com (mail-wm1-f54.google.com [209.85.128.54]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 536FE32470E for ; Fri, 4 Sep 2026 08:49:44 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.128.54 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788511785; cv=none; b=Bz7CW1as6ldWtdkBS9azQ/V8v/85U1B1243azhTLblpBdSG5sY1r8/26ueLKN18XQRkBo9nqS+gxAfiWGqVaw4MUBCumo3Zj0YVbtoBCkiBEupax7Ow1vg9JG2HnZw9Ymt8cYFhtlkw6iAQNjq7KKPGtFrmFR0HUaPhVcXdmoL0= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788511785; c=relaxed/simple; bh=Z8mPENNWcv1eq8P/28+Mi9OOdfEllu2+UZehW5EHxFU=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=ltNjbP0Pnlqfq72nJws2ApiQ4kypJXvZZJSAIIxTW7o8RpZZXI+Qfy+8PTf7rHLPB3yZaciCw7YmZgLgQO1E47BCjeQ9uXlRb3G903emgwHS6l/cGuy7OniQ8H47Qv/q5cA2BsnwdfFQnfd60dmAqTgfawQ2HWIh3iOkQWXWApI= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=n1lOqSst; arc=none smtp.client-ip=209.85.128.54 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="n1lOqSst" Received: by mail-wm1-f54.google.com with SMTP id 5b1f17b1804b1-495437bb891so5548835e9.1 for ; Fri, 04 Sep 2026 01:49:44 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1788511782; x=1789116582; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=Jfu2EemlakeU3G/i0hecUm1qkaXQeHbKJFBtMpImgJw=; b=n1lOqSstD3Dli/+SNwFHxQkCrAzROyLT0LInxHbSTlaMF0/lRvLfiJpIxgX+7hbYxa /FlJ3YmqBSEo+VxK84raVUghIeROORfFY5MZZT3NHfd1ZaJteHxBQPTHIanHnI8tviaQ QNLki2uYxRCTN/eCwzZBxG+e+JXQW+0GHuKcRbcuGlAhrlpGkIIKPdMlOVQD/8XS8kXZ sfD+675CKJwXrkdNElNqXfssQ2KCGkaxKfW45HBZPYV722n+h4hx63IV+d8aWGqjA+bO zmMfBOxmN64pMUVW7UtGcsj5yjA0sxlkStC9l0jhcUQphIm6JjWNmkF+DrBD51a7DY5t AwtA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788511782; x=1789116582; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=Jfu2EemlakeU3G/i0hecUm1qkaXQeHbKJFBtMpImgJw=; b=FhWGbczGm7m8ensa/Re7f2K8wSAacDfobT3XHYb2Y+09jnbpcwMjo5CNtGtI6X4g6o uiMiZ9QLEuGRs8w4tiRIJ5Pq08C2oKPj2NNVnVZJUFq/JqJIfECNsNAqDjbWGbrqwnTB fmk0J4Ys906bAzCwJmgFCBkDBLA14ArDhjKYNUrXC0fEiTXqWOeKr1dS7DW1+QYaU2Ox 9zabdz4y5uO7dPdnCRiJs9479pmvp02FqusbJJLxq2K1tzHHVOzWfXQQT+E8Zpx6tN26 QQciaTRIR7c8NAIrfxJt5DvJx6axsjipcgLvWQtWNZOb8zHV+N3yow3SgnSdhew+1QxT Ohzg== X-Forwarded-Encrypted: i=1; AKwUvBxPQGh63iaOI0+i1e2S1k/Vi55atwhtyks7S9BhduaibTFTWvcgPL2TdOpxi8Q9Kr5oP/S/8rkqRFgHNbA=@vger.kernel.org X-Gm-Message-State: AFuF++mhvEgja+Mgk5tAzyUhLbhVo8WAecpE/l/UrHP2U1YpQTLtU4pT snzPSbxuoSFMQ1c5fJksKqo5paoOI69iHZZnN2YWof8xq4JxDT3WGqI= X-Gm-Gg: AYBFou3ucrunXL0giJ1iX60lTgunImcnsQFRCYNPV22Zmp0ISOZHwkd1BwV3VNT3cbI aDdd4Gtt/bJXJBce2PkybNS2StyqjY3IUs/2Vfkm5StiPXmy4qu7/xT+7188jWCseDdCuK2shXC Myi6QVupk3l8K3STTtjc1yJ9tmhzbIbytunQuqK3dKWdsSaNXzAK356wJ83JjWOmegMpjt4hvGv cjyH9meEQPf/cOxN0cIrEYxfqF4HqYjHJjchC++Y0l6+kxESp7V0VqHHANvjnTLz2ncgq39vAGj gBAymKaD71lx8U0EG5wX8ILEBizzTpKFSFxKvVMj3CxF1sZNN4wk/XfpLq+5FTJrbaJZVdP2uwf lgqVDigvP31tdHzn/yk2KCrXBftw9dIw2Eap1rqMOSHk3/Vh5nYbQ++BDMaOkIKzHKCjn/yhZaj l13uRSUHSe5XAYGm0Qy7DLhAUcjEiSWg== X-Received: by 2002:a05:600c:8b8c:b0:49c:f13e:e52 with SMTP id 5b1f17b1804b1-49cf893b58bmr31193105e9.15.1788511782473; Fri, 04 Sep 2026 01:49:42 -0700 (PDT) Received: from debian.. ([2001:41d0:303:db6b::]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49ce5941cb4sm83963155e9.4.2026.09.04.01.49.41 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 04 Sep 2026 01:49:41 -0700 (PDT) From: Tristan Madani To: Ping-Ke Shih Cc: linux-wireless@vger.kernel.org, linux-kernel@vger.kernel.org, Tristan Madani , stable@vger.kernel.org Subject: [PATCH wireless] wifi: rtlwifi: fix OOB reads in IE parsing functions Date: Fri, 4 Sep 2026 08:49:40 +0000 Message-ID: <20260904084940.3885379-1-tristmd@gmail.com> X-Mailer: git-send-email 2.47.3 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit From: Tristan Madani rtl_find_ie() and rtl_find_221_ie() iterate over information elements in beacon frames using a loop condition of `while (pos < end)`. When only one byte remains (pos == end - 1), the loop body accesses pos[1] which reads one byte beyond the validated buffer boundary. In rtl_find_ie(), pos[1] is read in the bounds check expression `pos + 2 + pos[1] > end` before the result of that check can prevent the access. In rtl_find_221_ie(), the situation is worse: when the last byte happens to be 0xDD (221, vendor-specific IE), the code accesses pos[1] for the length, pos[2] for the data pointer, and passes both to rtl_chk_vendor_ouisub() which performs memcmp() on the out-of-bounds data. The bounds check `pos + 2 + pos[1] > end` only appears after the vendor IE has already been fully processed. Fix both functions by tightening the loop condition to `while (pos + 2 <= end)`, which ensures that at least the IE id (pos[0]) and length (pos[1]) bytes are within bounds before any access. Additionally, in rtl_find_221_ie(), move the full IE bounds check before the vendor-specific processing to prevent accessing IE data that extends past the buffer. Fixes: acd48572c396 ("rtlwifi: Change base routines for addition of rtl8192se and rtl8192de") Cc: stable@vger.kernel.org Signed-off-by: Tristan Madani --- drivers/net/wireless/realtek/rtlwifi/base.c | 12 ++++++------ 1 file changed, 6 insertions(+), 6 deletions(-) diff --git a/drivers/net/wireless/realtek/rtlwifi/base.c b/drivers/net/wireless/realtek/rtlwifi/base.c index 9e98c01bb90e6..9671b9247b571 100644 --- a/drivers/net/wireless/realtek/rtlwifi/base.c +++ b/drivers/net/wireless/realtek/rtlwifi/base.c @@ -2373,7 +2373,7 @@ u8 *rtl_find_ie(u8 *data, unsigned int len, u8 ie) pos = (u8 *)mgmt->u.beacon.variable; end = data + len; - while (pos < end) { + while (pos + 2 <= end) { if (pos + 2 + pos[1] > end) return NULL; @@ -2597,17 +2597,17 @@ static bool rtl_find_221_ie(struct ieee80211_hw *hw, u8 *data, pos = (u8 *)mgmt->u.beacon.variable; end = data + len; - while (pos < end) { - if (pos[0] == 221) { + while (pos + 2 <= end) { + if (pos + 2 + pos[1] > end) + return false; + + if (pos[0] == 221 && pos[1] >= 3) { vendor_ie.length = pos[1]; vendor_ie.octet = &pos[2]; if (rtl_chk_vendor_ouisub(hw, vendor_ie)) return true; } - if (pos + 2 + pos[1] > end) - return false; - pos += 2 + pos[1]; } return false; -- 2.47.3