From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mx0b-0031df01.pphosted.com (mx0b-0031df01.pphosted.com [205.220.180.131]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id ECB813C4B68 for ; Thu, 16 Jul 2026 22:15:48 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=205.220.180.131 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784240153; cv=none; b=UND8ArIJNWsHeJ0cvcss25vfd6HLyd0ws1uiX1O2JtpI7WcycIb3sAH2pFoWTkibgVI04EXSsYXjcnqxhojireLt42D2xhWGqcNj+W6FYPVDuZHnh5QxfZYrJhzrtxtYzFbKvOw0D3xzG4L/tg20+J2n+UYk4AesgGJpp7rfWFg= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784240153; c=relaxed/simple; bh=GQqo9CiV7JQLABv+7tA6z3T46isVGIyY4M7cdy9fbpw=; h=Message-ID:Date:MIME-Version:Subject:To:Cc:References:From: In-Reply-To:Content-Type; b=cOYweTTiqD4aNBIJnzXlPvFXP7lFX2tZakuig0nDBbuIND/mgkOh/5+benA07KkG/qLUD3DUvJwXSSZQvcbHa2nnOwPPkfNFKzZbu/58cbiLRcSL6aG2DIbypn/Dg07pizTuHs9VoDprj3GArbkZ105yCnnCOQIejMo/HBiL58I= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=oss.qualcomm.com; spf=pass smtp.mailfrom=oss.qualcomm.com; dkim=pass (2048-bit key) header.d=qualcomm.com header.i=@qualcomm.com header.b=EljSp0ew; dkim=pass (2048-bit key) header.d=oss.qualcomm.com header.i=@oss.qualcomm.com header.b=TgvWViFp; arc=none smtp.client-ip=205.220.180.131 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=oss.qualcomm.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=oss.qualcomm.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=qualcomm.com header.i=@qualcomm.com header.b="EljSp0ew"; dkim=pass (2048-bit key) header.d=oss.qualcomm.com header.i=@oss.qualcomm.com header.b="TgvWViFp" Received: from pps.filterd (m0279871.ppops.net [127.0.0.1]) by mx0a-0031df01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 66GJqNVd3853452 for ; Thu, 16 Jul 2026 22:15:46 GMT DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=qualcomm.com; h= cc:content-transfer-encoding:content-type:date:from:in-reply-to :message-id:mime-version:references:subject:to; s=qcppdkim1; bh= NMKQda4dVuMkYRZlsJ1mDDmzA5C8SBekER+swHoK56A=; b=EljSp0ewnO9vdcvY YH/kSt83yqKIq4mbO8eHXZbNIvXkxdbJ///BODFPe25shNuu60AwZvUnvovvV1oN 4FbbgjNmHlQnmsMRto1MjIiq8Ord6QP9NAAG4PcmSz6a4E/Kw0N58abI2fp6B+pb xyQz/kCOu7Pg+x1cA9czO9WDw9aceGhMRv1PWtaIcyKCbZrhLkX3KzzF3w33ENQu TJw54RRtZqnMnpvacaa1R/UVp74E83CyJ7RI6Yczvg/obU4G1whVFJU0TYXMNWoQ TGnlkQJkcKehtwS3Tax3RG/H2YuUfIrvAjaL3lhpbIak4F3RgE/32qdcFKYM/GHm WT/Zug== Received: from mail-pg1-f199.google.com (mail-pg1-f199.google.com [209.85.215.199]) by mx0a-0031df01.pphosted.com (PPS) with ESMTPS id 4feym1abj4-1 (version=TLSv1.3 cipher=TLS_AES_128_GCM_SHA256 bits=128 verify=NOT) for ; Thu, 16 Jul 2026 22:15:45 +0000 (GMT) Received: by mail-pg1-f199.google.com with SMTP id 41be03b00d2f7-cb11535e6a1so3578934a12.0 for ; Thu, 16 Jul 2026 15:15:45 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=oss.qualcomm.com; s=google; t=1784240145; x=1784844945; darn=vger.kernel.org; h=content-transfer-encoding:content-type:in-reply-to:content-language :from:references:cc:to:subject:user-agent:mime-version:date :message-id:from:to:cc:subject:date:message-id:reply-to:content-type; bh=NMKQda4dVuMkYRZlsJ1mDDmzA5C8SBekER+swHoK56A=; b=TgvWViFpmGWYsv25sxab0c0yVE9RcP0/gnOMuL4WaOv3DuZvVNs2RwpiIoM/iBrt8q PCFVDwMuFrhYE7AMTil+6ly3i8su/o5N7bILrBRHXz6+coQVVDhGjd0Iu+z1XCM5FxP7 fmhc0dE82xxRy6CrTpwBH0KWTHseOlonIFnfoGwqWWL+wgEotU1czPRo00y9QJBkLd/w qB98cCf37xVFAxl25v0xaUN98e8TVcrLm1ruedkh32pRKH41hBB8kp/W2tIMtvagfIoR roLn1JeLYmtNKCoNYhooT8sZqx4TAJ9BWdbd+nWewWNxVgRuKDo0HWl4hmCMpuqex2uU 52DQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784240145; x=1784844945; h=content-transfer-encoding:content-type:in-reply-to:content-language :from:references:cc:to:subject:user-agent:mime-version:date :message-id:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=NMKQda4dVuMkYRZlsJ1mDDmzA5C8SBekER+swHoK56A=; b=nj8MGzu4Pj4/RFj55uZgvTtEbl9Syf8GThvy6usEFdgUtkTGbFkcgSHt+LrM9arv92 np82lYIumNKcg/Qov0DG6nmtJjO30t4GchrLcolBZukHqEKZHPoA0FFcoxm7SWKETqzx 5wlMqka9e6bPDITqXK+b0ZadFjs0fk31KaijoHLhaWNercOj1bGB414lhGUzmUAqTa8D XVqLra/LfSMslstoXo1LBx7UFwT3+mhMq1kToEsQd4iHIFXrRKxyWV8ZxqqtGSwk66JG a8E81ta4bNYm+X/KzWvthtjRmUr2ZHYyYEkFrjPRM3e+hGSCWMt+aOpyaCNQvlKq90IF UDMg== X-Forwarded-Encrypted: i=1; AHgh+Rr7WgbP66zNzxTp6uL4/QVBJtGfZFrzGDk7hh/UXR/IDEU1MLOo4AKKnlVz9wnTIl1Zc1qnMMPPGnyOgWI=@vger.kernel.org X-Gm-Message-State: AOJu0YxeWetmi8DdeXTL8FyYx8TXBk97nWxrGo43LYFIPLRV/z5ZbSSl aTazBqaedmXhnKerJEuToi8E6vaqHQ1EdqkMI+BsQnehVjG9NTgIRbJS0hat0DAYWQDaDaLev46 jYaBPN6wR1PprJE63SXtDUz1DzlLQKlQ0GJg/oQAAZhCztrgMg23fIouHKN5sbuXz75c= X-Gm-Gg: AfdE7ck7Eu2pH8OhA57TTBDm7DLlFqRo9ISPf2IHNNyJDrJNKblPXPldITi2MXYlG2U aWqkXgkW7x3Xx1QEmjqsI01weOBfRw4j8SMO3LSjX4IJtMYHX00/VObDrE+hTtIBf5aU2nkrrsG fCTiL+j78RTcnA2UrZiJsEHwBHSrgzYm7IhOf0zK7jAgVEffhJ/PVFZRUaV//wRoySpuFlOvXwW hDFu3m9QCcPfPvp28kOeF3kgdg8gi+kTDUa4kD2bd6ghd2gvdQMtqOIXhE8wkwVF6P6UdoxB5Ep zASdrHQ7RWWLXXAoc1g3UJkboulT4Pado51dXyOOZwPPJZrqpof6TFzaD1LjuE8LECrF139n8ot TguaOwNaGl8WixUt5qfTQ6cXVUQC0qNvlS2A5aDlsiSDYv/7nhwbwAe+47g== X-Received: by 2002:a17:90b:528d:b0:380:ced0:ecf9 with SMTP id 98e67ed59e1d1-38e29ff9736mr8333490a91.4.1784240144758; Thu, 16 Jul 2026 15:15:44 -0700 (PDT) X-Received: by 2002:a17:90b:528d:b0:380:ced0:ecf9 with SMTP id 98e67ed59e1d1-38e29ff9736mr8333446a91.4.1784240144155; Thu, 16 Jul 2026 15:15:44 -0700 (PDT) Received: from [192.168.1.11] (15.sub-75-218-246.myvzw.com. [75.218.246.15]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-31429f9d444sm21764eec.6.2026.07.16.15.15.42 (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Thu, 16 Jul 2026 15:15:43 -0700 (PDT) Message-ID: <7bd71d11-d6f2-473d-b5ae-f5fbc972ef40@oss.qualcomm.com> Date: Thu, 16 Jul 2026 15:15:41 -0700 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 User-Agent: Mozilla Thunderbird Subject: Re: [PATCH] wifi: ar5523: fix integer underflow in ar5523_data_rx_cb() To: pip-izony , Ingo Molnar , Thomas Gleixner , Johannes Berg , Roopni Devanathan Cc: Kyungtae Kim , Pontus Fuchs , "John W . Linville" , linux-wireless@vger.kernel.org, linux-kernel@vger.kernel.org References: <20251103195519.3152385-2-eeodqql09@gmail.com> From: Jeff Johnson Content-Language: en-US In-Reply-To: <20251103195519.3152385-2-eeodqql09@gmail.com> Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit X-Authority-Analysis: v=2.4 cv=KPRqylFo c=1 sm=1 tr=0 ts=6a595811 cx=c_pps a=Oh5Dbbf/trHjhBongsHeRQ==:117 a=6VQYfvmiyQ8t40WkS/mQdw==:17 a=IkcTkHD0fZMA:10 a=RAioF0-LDSMA:10 a=s4-Qcg_JpJYA:10 a=VkNPw1HP01LnGYTKEx00:22 a=u7WPNUs3qKkmUXheDGA7:22 a=3WHJM1ZQz_JShphwDgj5:22 a=pGLkceISAAAA:8 a=AuuJo6D-WAaWUL1cUgMA:9 a=3ZKOabzyN94A:10 a=QEXdDO2ut3YA:10 a=_Vgx9l1VpLgwpw_dHYaR:22 X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwNzE2MDIyNiBTYWx0ZWRfXy0Qf/f6S5o65 HH9ovXAbnfnydqyNIltBltQbLdcic14COSx2DnGI4+v75EwXPU5PbmMdpVETPtjlbZBYUHs94wQ 0m6uuZ1S/f+VhiVMKq7H+bvD8Ual5OY1VUkysA7MWUADnS9XkOWLV7gnsLLEy5Sz6QEYp3BwEUY FAaC/oL3HTLReUxMWMmMelT51YkfcgNjd3Y5/Do6cQxxdMEbGUgmqqQneYfFY2OMWzRdNNJxzR0 uQATPbOeWqBVRGnOOhXbHMuZpRdanhtbNWqine6r8mlP8bo9oAPD93051A0sa2KyEXZLP2i7h6K AKbi/UwyAb/hkPtq9fQpD7QG/tcxaqqbEndC5MzdiNGyzg0qLgQoHW5G/88BJeYRbC+srQ+phlU QbFPMTOiqGFlnGskxikzVn5eE4/QC8sqbK7bxl5RKghseOXHOP1VjigkYoD9/UZodQtF2Mo4hoK /3apBE6E2grdtoAL4Dw== X-Proofpoint-Spam-Info: AW1haW4tMjYwNzE2MDIyNiBTYWx0ZWRfX121u14aPyOmM Sy++Z8N+KKoxz94C0KXpXtP2//trXuyRqNIet6LLOj1uoppxJrJOwLCdSS7jNITxwKmdBtowC0V BFRNujEdc9HwIpghC/LTNTtwNCKn6zU= X-Proofpoint-GUID: XxWIqNIv736WiBPn5r4oQd_I36l4ltKx X-Proofpoint-ORIG-GUID: XxWIqNIv736WiBPn5r4oQd_I36l4ltKx X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1143,Hydra:6.1.134,FMLib:17.12.100.49 definitions=2026-07-16_07,2026-07-15_02,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 priorityscore=1501 lowpriorityscore=0 adultscore=0 impostorscore=0 clxscore=1015 malwarescore=0 bulkscore=0 spamscore=0 phishscore=0 suspectscore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2606150000 definitions=main-2607160226 On 11/3/2025 11:55 AM, pip-izony wrote: > From: Seungjin Bae > > In ar5523_data_rx_cb(), the `rxlen` variable is derived from desc->len, > which is provided by the USB device. > > The function checks for an upper bound (rxlen > ar->rxbufsz) and for a > zero value (!rxlen), but it fails to check for a proper lower bound > against the size of the descriptor. > > If a malicious device provides an `rxlen` value that is positive > but smaller than sizeof(struct ar5523_rx_desc), the subtraction in > the call to skb_put() will result in an integer underflow. > > This passes a very large unsigned value to skb_put(), which then > triggers a kernel panic upon detecting the potential buffer overflow. > > Fix this by adding a check to ensure `rxlen` is at least > sizeof(struct ar5523_rx_desc) before performing the substraction. > > Fixes: b7d572e1871df ("ar5523: Add new driver") > Signed-off-by: Seungjin Bae > --- > drivers/net/wireless/ath/ar5523/ar5523.c | 6 ++++++ > 1 file changed, 6 insertions(+) > > diff --git a/drivers/net/wireless/ath/ar5523/ar5523.c b/drivers/net/wireless/ath/ar5523/ar5523.c > index 1230e6278f23..dfaccf241560 100644 > --- a/drivers/net/wireless/ath/ar5523/ar5523.c > +++ b/drivers/net/wireless/ath/ar5523/ar5523.c > @@ -589,6 +589,12 @@ static void ar5523_data_rx_cb(struct urb *urb) > goto skip; > } > > + if (rxlen < sizeof(struct ar5523_rx_desc)) { > + ar5523_dbg(ar, "RX: Bad descriptor (len=%d is too small)\n", > + rxlen); > + goto skip; > + } > + > skb_reserve(data->skb, sizeof(*chunk)); > skb_put(data->skb, rxlen - sizeof(struct ar5523_rx_desc)); > Since this is an orphaned driver, this patch has been sitting in my patchwork queue for a very long time. Today I decided to take a look. The patch does address the issue mentioned, but really doesn't completely address the crux of the issue. I believe there should be a fixed correlation between the rxlen and the usblen. I posed the following question to my review agent: given that the usblen should account for the ar5523_chunk header, the payload, and the ar5523_rx_desc, shouldn't the rxlen always be the same as the usblen - sizeof(ar5523_chunk)? And my agent agreed: Yes, that's exactly right. Looking at the struct comment "msg length including header" for desc->len and the frame layout: [ar5523_chunk (4B)] [802.11 payload] [ar5523_rx_desc] ←──────────────────── usblen ──────────────────────→ The invariant should be: rxlen == usblen - sizeof(ar5523_chunk) Because rxlen covers [802.11 payload] + [ar5523_rx_desc], and usblen covers everything including the chunk header. The code never cross-validates them. It independently bounds-checks usblen (via AR5523_MIN_RXBUFSZ) and rxlen (upper bound vs rxbufsz, lower bound added by the patch), but if a malicious device provides rxlen > usblen - sizeof(ar5523_chunk), then: skb_put(data->skb, rxlen - sizeof(struct ar5523_rx_desc)); ...would expose bytes beyond the actual 802.11 payload — potentially biting into the ar5523_rx_desc trailer bytes, or uninitialized skb tail space up to rxbufsz, and pass that garbage to ieee80211_rx_irqsafe(). The existing upper bound check rxlen > ar->rxbufsz prevents a skb_put overflow (since the skb is allocated with rxbufsz), but it's far too loose. The right check would be: if (rxlen != usblen - sizeof(struct ar5523_chunk)) goto skip; Or at minimum a strict upper bound: if (rxlen > usblen - sizeof(struct ar5523_chunk)) goto skip; So the patch fixes the underflow but misses this inconsistency between rxlen and usblen that could allow overreading valid-but-wrong data within the skb buffer. So please consider this analysis and propose a v2 /jeff