]> git.ipfire.org Git - thirdparty/linux.git/commitdiff
wifi: carl9170: bound memcpy length in cmd callback to prevent OOB read
authorTristan Madani <tristan@talencesecurity.com>
Tue, 21 Apr 2026 13:49:26 +0000 (13:49 +0000)
committerJeff Johnson <jeff.johnson@oss.qualcomm.com>
Mon, 13 Jul 2026 13:55:19 +0000 (06:55 -0700)
When the firmware sends a command response with a length mismatch,
carl9170_cmd_callback() logs the mismatch and calls carl9170_restart()
but then falls through to memcpy(ar->readbuf, buffer + 4, len - 4).
Since len comes from the firmware and can exceed ar->readlen, this
copies more data than the readbuf was allocated for.

Bound the memcpy to min(len - 4, ar->readlen) so that the response
is still completed -- avoiding repeated restarts from queued garbage --
while preventing an overread past the response buffer.

Fixes: a84fab3cbfdc ("carl9170: 802.11 rx/tx processing and usb backend")
Signed-off-by: Tristan Madani <tristan@talencesecurity.com>
Acked-by: Christian Lamparter <chunkeey@gmail.com>
Closes: https://syzkaller.appspot.com/bug?extid=5c1ca6ccaa1215781cac
Link: https://patch.msgid.link/20260421134929.325662-2-tristmd@gmail.com
Signed-off-by: Jeff Johnson <jeff.johnson@oss.qualcomm.com>
drivers/net/wireless/ath/carl9170/rx.c

index 6833430130f4ca6bc8cf39eff056558396f80aa6..f6855efc05c0f1a44f49e7368a32c9d365124310 100644 (file)
@@ -150,7 +150,8 @@ static void carl9170_cmd_callback(struct ar9170 *ar, u32 len, void *buffer)
        spin_lock(&ar->cmd_lock);
        if (ar->readbuf) {
                if (len >= 4)
-                       memcpy(ar->readbuf, buffer + 4, len - 4);
+                       memcpy(ar->readbuf, buffer + 4,
+                              min_t(u32, len - 4, ar->readlen));
 
                ar->readbuf = NULL;
        }