From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from omta040.useast.a.cloudfilter.net (omta040.useast.a.cloudfilter.net [44.202.169.39]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 445C221FF2C for ; Mon, 21 Jul 2025 18:55:14 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=44.202.169.39 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1753124116; cv=none; b=pQn4px0YLtD+qtfqmvv+E/xiTqArHNKs0pSZxJFefGwjPGpSv32Vxm2RXahihzkYF3JawnFtJ3196Fe6OHyu57Fe4JMdEFQhOPxLaAXvbIr3XnBWQ3uVZQYJdzXjG8oYZIXf2ahdnoj09iO7/AsQUQw/SPcQ6HHHwdkGy9Bw49A= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1753124116; c=relaxed/simple; bh=rnHeXAcRyQ3rssGoQ+P6O2rG+zqGthi1REfAADS6Vl0=; h=Message-ID:Date:MIME-Version:Subject:To:Cc:References:From: In-Reply-To:Content-Type; b=kefGyYoTTGzXMeHEu9Rg1Zb6cepH1mDkkcjprbgml3vqrSxc1LXpUI0yeN+H49i0z2kJHIJZJGvV9kekcm9r04/9/32ooFJY51NsXVOGBWtEaWOt59VD6CmoUuGExz1NRlRnV81hNr5njQlqklaGg9fO2PjWQ5YthMMoegrL3YU= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=embeddedor.com; spf=pass smtp.mailfrom=embeddedor.com; dkim=pass (2048-bit key) header.d=embeddedor.com header.i=@embeddedor.com header.b=KF+ywaYt; arc=none smtp.client-ip=44.202.169.39 Authentication-Results: smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=embeddedor.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=embeddedor.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=embeddedor.com header.i=@embeddedor.com header.b="KF+ywaYt" Received: from eig-obgw-6008a.ext.cloudfilter.net ([10.0.30.227]) by cmsmtp with ESMTPS id dpBauKWlXVkcRdvfHu1W8g; Mon, 21 Jul 2025 18:55:07 +0000 Received: from gator4166.hostgator.com ([108.167.133.22]) by cmsmtp with ESMTPS id dvfGue1DiXiq1dvfGupQhX; Mon, 21 Jul 2025 18:55:06 +0000 X-Authority-Analysis: v=2.4 cv=WeQKaVhX c=1 sm=1 tr=0 ts=687e8d0a a=1YbLdUo/zbTtOZ3uB5T3HA==:117 a=elAakMZAzsQyfqpwiXQzJA==:17 a=IkcTkHD0fZMA:10 a=Wb1JkmetP80A:10 a=7T7KSl7uo7wA:10 a=VwQbUJbxAAAA:8 a=stkexhm8AAAA:8 a=KF2CoUmeBr3NaIPvZjYA:9 a=QEXdDO2ut3YA:10 a=pIW3pCRaVxJDc-hWtpF8:22 a=xYX6OU9JNrHFPr8prv8u:22 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=embeddedor.com; s=default; h=Content-Transfer-Encoding:Content-Type: In-Reply-To:From:References:Cc:To:Subject:MIME-Version:Date:Message-ID:Sender :Reply-To:Content-ID:Content-Description:Resent-Date:Resent-From: Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:List-Id:List-Help: List-Unsubscribe:List-Subscribe:List-Post:List-Owner:List-Archive; bh=rVL5hVz9/5SnJaz7ql/wnvCuNsYr81PNsB+ycNjAoUw=; b=KF+ywaYtMvjOXA5ExoaW4ScvB3 8ME+m46DzmJihhbL8Q6xR58UeRGjH2o0+dS6iVtNJZ1bPwanNlYYus9A+VAZ5CbWojBI8ZKDZX+Un FlIfF7Fd4DALcBl1/xQHAkkiftDeYAZIKk0uvn0z1mdzc/T0EeJYczBlbHBkhYUN3fvxqlcrvt4Cr Gl37Z7M5swg1pB74hL2WK3jHW6o05YQU4dOlPmcyFdc0IcD8y/aRl0Ds3o5b7PAHzERC140l8Ibeh as2du0L4MXBzoGZAPF0uai5SDslxwmSBJKT+N0oZJo7UFC3i/GkpOl9+KLY+CQ1w048knF0UqpEOP mLEn7i9A==; Received: from [177.238.16.239] (port=55416 helo=[192.168.0.21]) by gator4166.hostgator.com with esmtpsa (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 (Exim 4.98.1) (envelope-from ) id 1udvfF-00000001wrf-2KLS; Mon, 21 Jul 2025 13:55:06 -0500 Message-ID: <331e54f8-f678-41ee-8788-9e91e3f5ff24@embeddedor.com> Date: Mon, 21 Jul 2025 12:54:59 -0600 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 User-Agent: Mozilla Thunderbird Subject: Re: [PATCH] wifi: mac80211: Write cnt before copying in ieee80211_copy_rnr_beacon() To: Kees Cook , Johannes Berg Cc: linux-wireless@vger.kernel.org, "Gustavo A. R. Silva" , Jeff Johnson , linux-kernel@vger.kernel.org, linux-hardening@vger.kernel.org References: <20250721182521.work.540-kees@kernel.org> Content-Language: en-US From: "Gustavo A. R. Silva" In-Reply-To: <20250721182521.work.540-kees@kernel.org> Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: 7bit X-AntiAbuse: This header was added to track abuse, please include it with any abuse report X-AntiAbuse: Primary Hostname - gator4166.hostgator.com X-AntiAbuse: Original Domain - vger.kernel.org X-AntiAbuse: Originator/Caller UID/GID - [47 12] / [47 12] X-AntiAbuse: Sender Address Domain - embeddedor.com X-BWhitelist: no X-Source-IP: 177.238.16.239 X-Source-L: No X-Exim-ID: 1udvfF-00000001wrf-2KLS X-Source: X-Source-Args: X-Source-Dir: X-Source-Sender: ([192.168.0.21]) [177.238.16.239]:55416 X-Source-Auth: gustavo@embeddedor.com X-Email-Count: 2 X-Org: HG=hgshared;ORG=hostgator; X-Source-Cap: Z3V6aWRpbmU7Z3V6aWRpbmU7Z2F0b3I0MTY2Lmhvc3RnYXRvci5jb20= X-Local-Domain: yes X-CMAE-Envelope: MS4xfLsDjECaMXiZsyCVnW0yR2q1dhbVumRFHRzKAvv2geQqPfvdJRFX8XarYKJVf4UVZ9ZZozQmak1t3W7Dx69xgtpVBavt2oEWsOlcBh9zjYaW/QL4rZzW 5LGD7LiTk11IipPD0Pg7oGzCVLoFfviRxKvzxgcbHrY4tO7j5kXkeqzwiSJ752XAqi0f7sYtRw51xwAxSwBIt8FhXbjaSbKpvnfMX6AhbFVo5PDQf1uja0Lq On 21/07/25 12:25, Kees Cook wrote: > While I caught the need for setting cnt early in nl80211_parse_rnr_elems() > in the original annotation of struct cfg80211_rnr_elems with __counted_by, > I missed a similar pattern in ieee80211_copy_rnr_beacon(). Fix this by > moving the cnt assignment to before the loop. > > Fixes: 7b6d7087031b ("wifi: cfg80211: Annotate struct cfg80211_rnr_elems with __counted_by") > Signed-off-by: Kees Cook Reviewed-by: Gustavo A. R. Silva Thanks! -Gustavo > --- > Cc: Johannes Berg > Cc: > --- > net/mac80211/cfg.c | 2 +- > 1 file changed, 1 insertion(+), 1 deletion(-) > > diff --git a/net/mac80211/cfg.c b/net/mac80211/cfg.c > index 4f20d57ab913..2ed07fa121ab 100644 > --- a/net/mac80211/cfg.c > +++ b/net/mac80211/cfg.c > @@ -1176,13 +1176,13 @@ ieee80211_copy_rnr_beacon(u8 *pos, struct cfg80211_rnr_elems *dst, > { > int i, offset = 0; > > + dst->cnt = src->cnt; > for (i = 0; i < src->cnt; i++) { > memcpy(pos + offset, src->elem[i].data, src->elem[i].len); > dst->elem[i].len = src->elem[i].len; > dst->elem[i].data = pos + offset; > offset += dst->elem[i].len; > } > - dst->cnt = src->cnt; > > return offset; > }