mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH v2] wifi: brcmfmac: cyw: fix heap overflow on a short auth frame
@ 2026-07-07  6:31 Maoyi Xie
  2026-07-07 11:32 ` Arend van Spriel
  0 siblings, 1 reply; 4+ messages in thread
From: Maoyi Xie @ 2026-07-07  6:31 UTC (permalink / raw)
  To: Arend van Spriel
  Cc: linux-wireless, brcm80211, brcm80211-dev-list.pdl, linux-kernel

brcmf_notify_auth_frame_rx() takes the frame length from the firmware
event and copies the frame body with the management header offset
subtracted:

	u32 mgmt_frame_len = e->datalen - sizeof(struct brcmf_rx_mgmt_data);
	...
	memcpy(&mgmt_frame->u, frame,
	       mgmt_frame_len - offsetof(struct ieee80211_mgmt, u));

The only length check is e->datalen >= sizeof(*rxframe), so mgmt_frame_len
can be anything from 0 up. offsetof(struct ieee80211_mgmt, u) is 24. When
mgmt_frame_len is below that, the subtraction wraps as an unsigned value to
a huge length. The memcpy then runs far past the kzalloc'd buffer. A
malicious or malfunctioning AP can make the frame short during the
external SAE auth exchange, so this is a remotely triggered heap overflow.

Reject frames shorter than the management header offset before the copy.

Fixes: 66f909308a7c ("wifi: brcmfmac: cyw: support external SAE authentication in station mode")
Cc: stable@vger.kernel.org
Co-developed-by: Kaixuan Li <kaixuan.li@ntu.edu.sg>
Signed-off-by: Kaixuan Li <kaixuan.li@ntu.edu.sg>
Signed-off-by: Maoyi Xie <maoyixie.tju@gmail.com>
Acked-by: Arend van Spriel <arend.vanspriel@broadcom.com>
---
v2: drop the Link: tag (Arend), add Arend's Acked-by.

v1: https://lore.kernel.org/r/20260627131313.3878893-1-maoyixie.tju@gmail.com
 drivers/net/wireless/broadcom/brcm80211/brcmfmac/cyw/core.c | 6 ++++++
 1 file changed, 6 insertions(+)

diff --git a/drivers/net/wireless/broadcom/brcm80211/brcmfmac/cyw/core.c b/drivers/net/wireless/broadcom/brcm80211/brcmfmac/cyw/core.c
index ce09d44fa7..873754be51 100644
--- a/drivers/net/wireless/broadcom/brcm80211/brcmfmac/cyw/core.c
+++ b/drivers/net/wireless/broadcom/brcm80211/brcmfmac/cyw/core.c
@@ -293,6 +293,12 @@ brcmf_notify_auth_frame_rx(struct brcmf_if *ifp,
 		return -EINVAL;
 	}
 
+	if (mgmt_frame_len < offsetof(struct ieee80211_mgmt, u)) {
+		bphy_err(drvr, "Event %s (%d) frame too small. Ignore\n",
+			 brcmf_fweh_event_name(e->event_code), e->event_code);
+		return -EINVAL;
+	}
+
 	wdev = &ifp->vif->wdev;
 	WARN_ON(!wdev);
 
-- 
2.34.1


^ permalink raw reply	[flat|nested] 4+ messages in thread

* Re: [PATCH v2] wifi: brcmfmac: cyw: fix heap overflow on a short auth frame
  2026-07-07  6:31 [PATCH v2] wifi: brcmfmac: cyw: fix heap overflow on a short auth frame Maoyi Xie
@ 2026-07-07 11:32 ` Arend van Spriel
  2026-07-07 11:40   ` Arend van Spriel
  0 siblings, 1 reply; 4+ messages in thread
From: Arend van Spriel @ 2026-07-07 11:32 UTC (permalink / raw)
  To: Maoyi Xie; +Cc: linux-wireless, brcm80211, brcm80211-dev-list.pdl, linux-kernel

On 07/07/2026 08:31, Maoyi Xie wrote:
> brcmf_notify_auth_frame_rx() takes the frame length from the firmware
> event and copies the frame body with the management header offset
> subtracted:
> 
> 	u32 mgmt_frame_len = e->datalen - sizeof(struct brcmf_rx_mgmt_data);
> 	...
> 	memcpy(&mgmt_frame->u, frame,
> 	       mgmt_frame_len - offsetof(struct ieee80211_mgmt, u));
> 
> The only length check is e->datalen >= sizeof(*rxframe), so mgmt_frame_len
> can be anything from 0 up. offsetof(struct ieee80211_mgmt, u) is 24. When
> mgmt_frame_len is below that, the subtraction wraps as an unsigned value to
> a huge length. The memcpy then runs far past the kzalloc'd buffer. A
> malicious or malfunctioning AP can make the frame short during the
> external SAE auth exchange, so this is a remotely triggered heap overflow.
> 
> Reject frames shorter than the management header offset before the copy.
> 
> Fixes: 66f909308a7c ("wifi: brcmfmac: cyw: support external SAE authentication in station mode")
> Cc: stable@vger.kernel.org
> Co-developed-by: Kaixuan Li <kaixuan.li@ntu.edu.sg>
> Signed-off-by: Kaixuan Li <kaixuan.li@ntu.edu.sg>
> Signed-off-by: Maoyi Xie <maoyixie.tju@gmail.com>
> Acked-by: Arend van Spriel <arend.vanspriel@broadcom.com>

Thanks. Nothing to add here.

> ---
> v2: drop the Link: tag (Arend), add Arend's Acked-by.
> 
> v1: https://lore.kernel.org/r/20260627131313.3878893-1-maoyixie.tju@gmail.com
>   drivers/net/wireless/broadcom/brcm80211/brcmfmac/cyw/core.c | 6 ++++++
>   1 file changed, 6 insertions(+)

^ permalink raw reply	[flat|nested] 4+ messages in thread

* Re: [PATCH v2] wifi: brcmfmac: cyw: fix heap overflow on a short auth frame
  2026-07-07 11:32 ` Arend van Spriel
@ 2026-07-07 11:40   ` Arend van Spriel
  2026-07-07 11:53     ` Johannes Berg
  0 siblings, 1 reply; 4+ messages in thread
From: Arend van Spriel @ 2026-07-07 11:40 UTC (permalink / raw)
  To: Maoyi Xie; +Cc: linux-wireless, brcm80211, brcm80211-dev-list.pdl, linux-kernel

On 07/07/2026 13:32, Arend van Spriel wrote:
> On 07/07/2026 08:31, Maoyi Xie wrote:
>> brcmf_notify_auth_frame_rx() takes the frame length from the firmware
>> event and copies the frame body with the management header offset
>> subtracted:
>>
>>     u32 mgmt_frame_len = e->datalen - sizeof(struct brcmf_rx_mgmt_data);
>>     ...
>>     memcpy(&mgmt_frame->u, frame,
>>            mgmt_frame_len - offsetof(struct ieee80211_mgmt, u));
>>
>> The only length check is e->datalen >= sizeof(*rxframe), so 
>> mgmt_frame_len
>> can be anything from 0 up. offsetof(struct ieee80211_mgmt, u) is 24. When
>> mgmt_frame_len is below that, the subtraction wraps as an unsigned 
>> value to
>> a huge length. The memcpy then runs far past the kzalloc'd buffer. A
>> malicious or malfunctioning AP can make the frame short during the
>> external SAE auth exchange, so this is a remotely triggered heap 
>> overflow.
>>
>> Reject frames shorter than the management header offset before the copy.
>>
>> Fixes: 66f909308a7c ("wifi: brcmfmac: cyw: support external SAE 
>> authentication in station mode")
>> Cc: stable@vger.kernel.org
>> Co-developed-by: Kaixuan Li <kaixuan.li@ntu.edu.sg>
>> Signed-off-by: Kaixuan Li <kaixuan.li@ntu.edu.sg>
>> Signed-off-by: Maoyi Xie <maoyixie.tju@gmail.com>
>> Acked-by: Arend van Spriel <arend.vanspriel@broadcom.com>
> 
> Thanks. Nothing to add here.

Actually v1 was already applied to the wireless tree.

>> ---
>> v2: drop the Link: tag (Arend), add Arend's Acked-by.
>>
>> v1: https://lore.kernel.org/r/20260627131313.3878893-1- 
>> maoyixie.tju@gmail.com
>>   drivers/net/wireless/broadcom/brcm80211/brcmfmac/cyw/core.c | 6 ++++++
>>   1 file changed, 6 insertions(+)


^ permalink raw reply	[flat|nested] 4+ messages in thread

* Re: [PATCH v2] wifi: brcmfmac: cyw: fix heap overflow on a short auth frame
  2026-07-07 11:40   ` Arend van Spriel
@ 2026-07-07 11:53     ` Johannes Berg
  0 siblings, 0 replies; 4+ messages in thread
From: Johannes Berg @ 2026-07-07 11:53 UTC (permalink / raw)
  To: Arend van Spriel, Maoyi Xie
  Cc: linux-wireless, brcm80211, brcm80211-dev-list.pdl, linux-kernel

On Tue, 2026-07-07 at 13:40 +0200, Arend van Spriel wrote:
> 
> Actually v1 was already applied to the wireless tree.

Yeah, I thought the Link: was fine - I (only) add links to the patch
submission itself for tracking (Linus isn't super happy about accepts it
now), but the link given was to a report/further discussion, so that
seemed OK.

johannes

^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2026-07-07 11:54 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-07-07  6:31 [PATCH v2] wifi: brcmfmac: cyw: fix heap overflow on a short auth frame Maoyi Xie
2026-07-07 11:32 ` Arend van Spriel
2026-07-07 11:40   ` Arend van Spriel
2026-07-07 11:53     ` Johannes Berg

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®