From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-ot1-f100.google.com (mail-ot1-f100.google.com [209.85.210.100]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 5E602313E31 for ; Sat, 27 Jun 2026 12:09:22 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.210.100 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1782562163; cv=none; b=rhi6skT0lDL45MWRaIU1P0fEfua49e/xzIj+PqpBLGW+400e6qhStfks+MCyaFkQXwlqkKu4cFKtUQ+WDk69dewLa6oVsiHO5MSHwyfv76ZubZTF6YMDA3wpE635JZ2vbQzGyGusXR1M7QYQjCgpI0Eqb3dF+VoeV9f+I7AMnc8= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1782562163; c=relaxed/simple; bh=Qz5V/qZ1e2NMwyP/pVi6BiSztUfVHSA7XJ1uHZTnzNU=; h=Message-ID:Date:MIME-Version:Subject:To:Cc:References:From: In-Reply-To:Content-Type; b=JP6EunElgqWjhAXf8y9yipeAP8r6iXhLpYa3P1KjnvRBzU6xAt9OdgO9fIKTDDOCOEFxHkkD0SWFHWcNOxOmhQsTbncvVWv9LtWEboG4bDUGpU1jBmuxucFgiIuKYOrVeXEjPzDwXXeLlhlJOj5zFEsQeajBslJ/gt9Kbsi1Uyc= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=broadcom.com; spf=fail smtp.mailfrom=broadcom.com; dkim=pass (1024-bit key) header.d=broadcom.com header.i=@broadcom.com header.b=IZVOSjUF; arc=none smtp.client-ip=209.85.210.100 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=broadcom.com Authentication-Results: smtp.subspace.kernel.org; spf=fail smtp.mailfrom=broadcom.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=broadcom.com header.i=@broadcom.com header.b="IZVOSjUF" Received: by mail-ot1-f100.google.com with SMTP id 46e09a7af769-7e9b895ee02so534660a34.0 for ; Sat, 27 Jun 2026 05:09:22 -0700 (PDT) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1782562161; x=1783166961; h=content-transfer-encoding:in-reply-to:from:content-language :references:cc:to:subject:user-agent:mime-version:date:message-id :dkim-signature:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to; bh=nfFcnLrFbJ0cBvqWefNxS93tH3j42/SSWzQHOvhNJQg=; b=ixJ8tUY9W+9hlX6tAw+UyGBizFjqKtIUYpEwVhOQlwmkjga7JfLQjWny9HEFoGFbKc JZ89DdFxbh+/fUkk4BXSbEyG2VMg3EKBqPburoQUOX2XDtAtB0SlVnJn33EDNxIchnQF UheiqEzniHAhNZydsD8lxbCZcrCz2IIeqdYzg9sEZICpDYr04k9YsLK/Dq/4Rvmi0ROe /BJIRnvtbbM/lH/dTIZ15v0cSs7RQmqAocnC7QD0amR8NaDI5PKjYhqTjvqWnslLdbrz 6QB8BuZEfDI7kAaEiW0GOi8dlXiD17q8Ol6HeksumvjEVvjhfBCYTzp/xPuRW6Ed1StF PQuQ== X-Forwarded-Encrypted: i=1; AFNElJ8VyebbN3BptWibdw1aNDKWtIWq226pYLBRtO2y5nUJFb0gZonO4AXgRxWIkrj2i/qKr/fLLPOkpeJS8p4=@vger.kernel.org X-Gm-Message-State: AOJu0YzXDQKyWT74vJM/x5H5KeyuVQaVqwVllOh7EnbC7CxgStD/NRaA OHYsT1IzP7HQZtcRMnGq0uRrwX9fzR03bfa5+9OQr1+hn1lNzIeGCl2468sdZYqT6GXjCDgBC6/ wHr42ydbhnEha/eGKLxKPDqBofXYpX2L7ByDCVMA0PyXGxzlMIrbX/WVfF9YwQQQBJP84UTv1gR O79elnvxVhatphKraz82ZMyQpn1O+YeNuQZuZ+81VpD+LNjjn1ltaj3vJonx2XVb8jUldwVouXV 2X3i39ZDq9S+lSS+fmJl7UJYA== X-Gm-Gg: AfdE7ckygw5yx086rScrXa+NIBbTuyvyg3PEEjmwVd+z9rZBIl0vvUznJhAk4F4gvvF z1ghDFbu27Q6R9BD7g/38zcIpps9vfxxZ8VAxhKq9LxRgIJ/jXOKxWLQBmGdg6XZGismK/3EtVe baKiLj8rNSr53gwktmu72w/oCma5Eh4E5Rbk8w8MsHCSS3+Vn4BPr1eVGQopHiavPa6ZBD+L2Jn oWtlhtQstRrv9AJQQmOI0nLol7v8Qhlveju/1ayS6Lwz4nZJEGB1KvyS0FP0TPl67u8dPYi+T3b HmIz1Avg8EGojreRmJcFsbzpAljKb6W1+LC/ij44ew9bNCRoCBCDzOSMcHLSWMJr4Cr27WJGu0T ZkU7fs1scn577tJrMriLL4818zSiKFOR1/hQMjLb4DZhZMlnDUYA4GZH10ewGEZAg817SjJZ9nO Zv/ZXrfOcILx0/TmEz2uksF/Wrevs+8ws6kdpwX7caCvVakYZaFg== X-Received: by 2002:a05:6820:f004:b0:6a1:50eb:2104 with SMTP id 006d021491bc7-6a150eb22cfmr2553345eaf.57.1782562160765; Sat, 27 Jun 2026 05:09:20 -0700 (PDT) Received: from smtp-us-east1-p01-i01-si01.dlp.protect.broadcom.com (address-144-49-247-25.dlp.protect.broadcom.com. [144.49.247.25]) by smtp-relay.gmail.com with ESMTPS id 586e51a60fabf-4472ed51daasm1934077fac.5.2026.06.27.05.09.20 for (version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128); Sat, 27 Jun 2026 05:09:20 -0700 (PDT) X-Relaying-Domain: broadcom.com X-CFilter-Loop: Reflected Received: by mail-dy1-f199.google.com with SMTP id 5a478bee46e88-30ba395b047so5990788eec.0 for ; Sat, 27 Jun 2026 05:09:19 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=broadcom.com; s=google; t=1782562159; x=1783166959; darn=vger.kernel.org; h=content-transfer-encoding:in-reply-to:from:content-language :references:cc:to:subject:user-agent:mime-version:date:message-id :from:to:cc:subject:date:message-id:reply-to; bh=nfFcnLrFbJ0cBvqWefNxS93tH3j42/SSWzQHOvhNJQg=; b=IZVOSjUF9ywGqcDYhfvLo02KYxY09rmaWWjAKFDWEZUgWc/eM9UhmhU5TLScLuTFrP mEyNV7vn7T551KfN0OzzLlL8YI22VmpX+LvkRVRfJ+6ecu4EVZzKNjrOZh64TcH+EOTt AEkamupRT+jJJAlSAKFj+QuFBIUbuOwm3G428= X-Forwarded-Encrypted: i=1; AHgh+RprnaIxj5e9VqeTjIVqeuOJxsFC/Wwk2qF66i+XjPxpvlnJBqZR2UrV6TVrVJMrsL1EF58h+o6wmbJZulY=@vger.kernel.org X-Received: by 2002:a05:7300:23cb:b0:2c5:b23e:48a6 with SMTP id 5a478bee46e88-30c84dfad18mr11468879eec.23.1782562158943; Sat, 27 Jun 2026 05:09:18 -0700 (PDT) X-Received: by 2002:a05:7300:23cb:b0:2c5:b23e:48a6 with SMTP id 5a478bee46e88-30c84dfad18mr11468858eec.23.1782562158317; Sat, 27 Jun 2026 05:09:18 -0700 (PDT) Received: from [192.168.178.26] (f215227.upc-f.chello.nl. [80.56.215.227]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-30c9d39e7besm18507657eec.26.2026.06.27.05.09.15 (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Sat, 27 Jun 2026 05:09:17 -0700 (PDT) Message-ID: Date: Sat, 27 Jun 2026 14:09:15 +0200 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 User-Agent: Mozilla Thunderbird Subject: Re: brcmfmac: heap overflow in brcmf_notify_auth_frame_rx() on a short auth frame To: Maoyi Xie Cc: linux-wireless@vger.kernel.org, brcm80211@lists.linux.dev, linux-kernel@vger.kernel.org References: <178214417708.2368577.16740907093694208834@maoyixie.com> Content-Language: en-US From: Arend van Spriel In-Reply-To: <178214417708.2368577.16740907093694208834@maoyixie.com> Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: 7bit X-DetectorID-Processed: b00c1d49-9d2e-4205-b15f-d015386d3d5e On 22/06/2026 18:02, Maoyi Xie wrote: > Hi all, > > I think brcmf_notify_auth_frame_rx() in > drivers/net/wireless/broadcom/brcm80211/brcmfmac/cyw/core.c can overflow the > heap when the firmware reports a short external auth frame. I would > appreciate it if you could take a look. > > The handler takes the frame length from the event, then allocates a buffer > for it. > > u32 mgmt_frame_len = e->datalen - sizeof(struct brcmf_rx_mgmt_data); > ... > if (e->datalen < sizeof(*rxframe)) { > ... > return -EINVAL; > } > ... > mgmt_frame = kzalloc(mgmt_frame_len, GFP_KERNEL); > > The only length check is e->datalen >= sizeof(*rxframe). So mgmt_frame_len > can be anything from 0 up. The frame body is then copied with a length that > subtracts the management header offset. > > memcpy(&mgmt_frame->u, frame, > mgmt_frame_len - offsetof(struct ieee80211_mgmt, u)); > > offsetof(struct ieee80211_mgmt, u) is 24. If mgmt_frame_len is less than 24, > the subtraction wraps around as an unsigned value to a huge number. The > memcpy then runs far past the small kzalloc buffer. That is a heap overflow > driven by the frame the firmware passes up. A malicious or malfunctioning AP > can make the frame short during the external SAE auth exchange. > > The p2p path in the same driver allocates with the header offset included, > so it does not have this shape. > > I reproduced the overflow on 7.1-rc7. With mgmt_frame_len set below the 24 > byte header offset, the subtracted length wraps to a huge value and the copy > faults. > > BUG: unable to handle page fault ... in memcpy_orig > > A check that mgmt_frame_len is at least offsetof(struct ieee80211_mgmt, u) > before the copy would close it. > > Does this look like a real bug to you, and is that the right place to bound > it? If so I am happy to send a proper patch with a Fixes tag and Cc stable. > > Kaixuan Li and I found this together. Thanks for reaching out although it would have been fine to just send the patch straight away. I do agree with the assessment given so this is a real bug. Regards, Arend