* [PATCH v2] wifi: brcmfmac: cyw: fix heap overflow on a short auth frame
@ 2026-07-07 6:31 Maoyi Xie
2026-07-07 11:32 ` Arend van Spriel
0 siblings, 1 reply; 4+ messages in thread
From: Maoyi Xie @ 2026-07-07 6:31 UTC (permalink / raw)
To: Arend van Spriel
Cc: linux-wireless, brcm80211, brcm80211-dev-list.pdl, linux-kernel
brcmf_notify_auth_frame_rx() takes the frame length from the firmware
event and copies the frame body with the management header offset
subtracted:
u32 mgmt_frame_len = e->datalen - sizeof(struct brcmf_rx_mgmt_data);
...
memcpy(&mgmt_frame->u, frame,
mgmt_frame_len - offsetof(struct ieee80211_mgmt, u));
The only length check is e->datalen >= sizeof(*rxframe), so mgmt_frame_len
can be anything from 0 up. offsetof(struct ieee80211_mgmt, u) is 24. When
mgmt_frame_len is below that, the subtraction wraps as an unsigned value to
a huge length. The memcpy then runs far past the kzalloc'd buffer. A
malicious or malfunctioning AP can make the frame short during the
external SAE auth exchange, so this is a remotely triggered heap overflow.
Reject frames shorter than the management header offset before the copy.
Fixes: 66f909308a7c ("wifi: brcmfmac: cyw: support external SAE authentication in station mode")
Cc: stable@vger.kernel.org
Co-developed-by: Kaixuan Li <kaixuan.li@ntu.edu.sg>
Signed-off-by: Kaixuan Li <kaixuan.li@ntu.edu.sg>
Signed-off-by: Maoyi Xie <maoyixie.tju@gmail.com>
Acked-by: Arend van Spriel <arend.vanspriel@broadcom.com>
---
v2: drop the Link: tag (Arend), add Arend's Acked-by.
v1: https://lore.kernel.org/r/20260627131313.3878893-1-maoyixie.tju@gmail.com
drivers/net/wireless/broadcom/brcm80211/brcmfmac/cyw/core.c | 6 ++++++
1 file changed, 6 insertions(+)
diff --git a/drivers/net/wireless/broadcom/brcm80211/brcmfmac/cyw/core.c b/drivers/net/wireless/broadcom/brcm80211/brcmfmac/cyw/core.c
index ce09d44fa7..873754be51 100644
--- a/drivers/net/wireless/broadcom/brcm80211/brcmfmac/cyw/core.c
+++ b/drivers/net/wireless/broadcom/brcm80211/brcmfmac/cyw/core.c
@@ -293,6 +293,12 @@ brcmf_notify_auth_frame_rx(struct brcmf_if *ifp,
return -EINVAL;
}
+ if (mgmt_frame_len < offsetof(struct ieee80211_mgmt, u)) {
+ bphy_err(drvr, "Event %s (%d) frame too small. Ignore\n",
+ brcmf_fweh_event_name(e->event_code), e->event_code);
+ return -EINVAL;
+ }
+
wdev = &ifp->vif->wdev;
WARN_ON(!wdev);
--
2.34.1
^ permalink raw reply [flat|nested] 4+ messages in thread* Re: [PATCH v2] wifi: brcmfmac: cyw: fix heap overflow on a short auth frame
2026-07-07 6:31 [PATCH v2] wifi: brcmfmac: cyw: fix heap overflow on a short auth frame Maoyi Xie
@ 2026-07-07 11:32 ` Arend van Spriel
2026-07-07 11:40 ` Arend van Spriel
0 siblings, 1 reply; 4+ messages in thread
From: Arend van Spriel @ 2026-07-07 11:32 UTC (permalink / raw)
To: Maoyi Xie; +Cc: linux-wireless, brcm80211, brcm80211-dev-list.pdl, linux-kernel
On 07/07/2026 08:31, Maoyi Xie wrote:
> brcmf_notify_auth_frame_rx() takes the frame length from the firmware
> event and copies the frame body with the management header offset
> subtracted:
>
> u32 mgmt_frame_len = e->datalen - sizeof(struct brcmf_rx_mgmt_data);
> ...
> memcpy(&mgmt_frame->u, frame,
> mgmt_frame_len - offsetof(struct ieee80211_mgmt, u));
>
> The only length check is e->datalen >= sizeof(*rxframe), so mgmt_frame_len
> can be anything from 0 up. offsetof(struct ieee80211_mgmt, u) is 24. When
> mgmt_frame_len is below that, the subtraction wraps as an unsigned value to
> a huge length. The memcpy then runs far past the kzalloc'd buffer. A
> malicious or malfunctioning AP can make the frame short during the
> external SAE auth exchange, so this is a remotely triggered heap overflow.
>
> Reject frames shorter than the management header offset before the copy.
>
> Fixes: 66f909308a7c ("wifi: brcmfmac: cyw: support external SAE authentication in station mode")
> Cc: stable@vger.kernel.org
> Co-developed-by: Kaixuan Li <kaixuan.li@ntu.edu.sg>
> Signed-off-by: Kaixuan Li <kaixuan.li@ntu.edu.sg>
> Signed-off-by: Maoyi Xie <maoyixie.tju@gmail.com>
> Acked-by: Arend van Spriel <arend.vanspriel@broadcom.com>
Thanks. Nothing to add here.
> ---
> v2: drop the Link: tag (Arend), add Arend's Acked-by.
>
> v1: https://lore.kernel.org/r/20260627131313.3878893-1-maoyixie.tju@gmail.com
> drivers/net/wireless/broadcom/brcm80211/brcmfmac/cyw/core.c | 6 ++++++
> 1 file changed, 6 insertions(+)
^ permalink raw reply [flat|nested] 4+ messages in thread* Re: [PATCH v2] wifi: brcmfmac: cyw: fix heap overflow on a short auth frame
2026-07-07 11:32 ` Arend van Spriel
@ 2026-07-07 11:40 ` Arend van Spriel
2026-07-07 11:53 ` Johannes Berg
0 siblings, 1 reply; 4+ messages in thread
From: Arend van Spriel @ 2026-07-07 11:40 UTC (permalink / raw)
To: Maoyi Xie; +Cc: linux-wireless, brcm80211, brcm80211-dev-list.pdl, linux-kernel
On 07/07/2026 13:32, Arend van Spriel wrote:
> On 07/07/2026 08:31, Maoyi Xie wrote:
>> brcmf_notify_auth_frame_rx() takes the frame length from the firmware
>> event and copies the frame body with the management header offset
>> subtracted:
>>
>> u32 mgmt_frame_len = e->datalen - sizeof(struct brcmf_rx_mgmt_data);
>> ...
>> memcpy(&mgmt_frame->u, frame,
>> mgmt_frame_len - offsetof(struct ieee80211_mgmt, u));
>>
>> The only length check is e->datalen >= sizeof(*rxframe), so
>> mgmt_frame_len
>> can be anything from 0 up. offsetof(struct ieee80211_mgmt, u) is 24. When
>> mgmt_frame_len is below that, the subtraction wraps as an unsigned
>> value to
>> a huge length. The memcpy then runs far past the kzalloc'd buffer. A
>> malicious or malfunctioning AP can make the frame short during the
>> external SAE auth exchange, so this is a remotely triggered heap
>> overflow.
>>
>> Reject frames shorter than the management header offset before the copy.
>>
>> Fixes: 66f909308a7c ("wifi: brcmfmac: cyw: support external SAE
>> authentication in station mode")
>> Cc: stable@vger.kernel.org
>> Co-developed-by: Kaixuan Li <kaixuan.li@ntu.edu.sg>
>> Signed-off-by: Kaixuan Li <kaixuan.li@ntu.edu.sg>
>> Signed-off-by: Maoyi Xie <maoyixie.tju@gmail.com>
>> Acked-by: Arend van Spriel <arend.vanspriel@broadcom.com>
>
> Thanks. Nothing to add here.
Actually v1 was already applied to the wireless tree.
>> ---
>> v2: drop the Link: tag (Arend), add Arend's Acked-by.
>>
>> v1: https://lore.kernel.org/r/20260627131313.3878893-1-
>> maoyixie.tju@gmail.com
>> drivers/net/wireless/broadcom/brcm80211/brcmfmac/cyw/core.c | 6 ++++++
>> 1 file changed, 6 insertions(+)
^ permalink raw reply [flat|nested] 4+ messages in thread* Re: [PATCH v2] wifi: brcmfmac: cyw: fix heap overflow on a short auth frame
2026-07-07 11:40 ` Arend van Spriel
@ 2026-07-07 11:53 ` Johannes Berg
0 siblings, 0 replies; 4+ messages in thread
From: Johannes Berg @ 2026-07-07 11:53 UTC (permalink / raw)
To: Arend van Spriel, Maoyi Xie
Cc: linux-wireless, brcm80211, brcm80211-dev-list.pdl, linux-kernel
On Tue, 2026-07-07 at 13:40 +0200, Arend van Spriel wrote:
>
> Actually v1 was already applied to the wireless tree.
Yeah, I thought the Link: was fine - I (only) add links to the patch
submission itself for tracking (Linus isn't super happy about accepts it
now), but the link given was to a report/further discussion, so that
seemed OK.
johannes
^ permalink raw reply [flat|nested] 4+ messages in thread
end of thread, other threads:[~2026-07-07 11:54 UTC | newest]
Thread overview: 4+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-07-07 6:31 [PATCH v2] wifi: brcmfmac: cyw: fix heap overflow on a short auth frame Maoyi Xie
2026-07-07 11:32 ` Arend van Spriel
2026-07-07 11:40 ` Arend van Spriel
2026-07-07 11:53 ` Johannes Berg
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®