]> git.ipfire.org Git - thirdparty/kernel/linux.git/commitdiff
wifi: nl80211: validate nested MBSSID IE blobs
authorZhao Li <enderaoelyther@gmail.com>
Fri, 12 Jun 2026 13:18:55 +0000 (21:18 +0800)
committerJohannes Berg <johannes.berg@intel.com>
Mon, 6 Jul 2026 12:11:09 +0000 (14:11 +0200)
Validate each nested NL80211_ATTR_MBSSID_ELEMS entry as a well-formed
information-element stream before storing it for beacon construction.

RNR parsing already validates each nested blob with validate_ie_attr()
before storing it. Apply the same syntactic IE validation to MBSSID
entries before counting and copying their data and length pointers.

Fixes: dc1e3cb8da8b ("nl80211: MBSSID and EMA support in AP mode")
Assisted-by: Codex:gpt-5.5
Assisted-by: Claude:claude-opus-4.8
Signed-off-by: Zhao Li <enderaoelyther@gmail.com>
Link: https://patch.msgid.link/20260612131854.43575-3-enderaoelyther@gmail.com
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
net/wireless/nl80211.c

index 056388c045994a6cbf50ee19698445e101f75122..26b781770d4ff37e3e475e2b335177a77b320378 100644 (file)
@@ -6510,7 +6510,8 @@ static int nl80211_parse_mbssid_config(struct wiphy *wiphy,
 }
 
 static struct cfg80211_mbssid_elems *
-nl80211_parse_mbssid_elems(struct wiphy *wiphy, struct nlattr *attrs)
+nl80211_parse_mbssid_elems(struct wiphy *wiphy, struct nlattr *attrs,
+                          struct netlink_ext_ack *extack)
 {
        struct nlattr *nl_elems;
        struct cfg80211_mbssid_elems *elems;
@@ -6521,6 +6522,12 @@ nl80211_parse_mbssid_elems(struct wiphy *wiphy, struct nlattr *attrs)
                return ERR_PTR(-EINVAL);
 
        nla_for_each_nested(nl_elems, attrs, rem_elems) {
+               int ret;
+
+               ret = validate_ie_attr(nl_elems, extack);
+               if (ret)
+                       return ERR_PTR(ret);
+
                if (num_elems >= 255)
                        return ERR_PTR(-EINVAL);
                num_elems++;
@@ -6787,7 +6794,8 @@ static int nl80211_parse_beacon(struct cfg80211_registered_device *rdev,
        if (attrs[NL80211_ATTR_MBSSID_ELEMS]) {
                struct cfg80211_mbssid_elems *mbssid =
                        nl80211_parse_mbssid_elems(&rdev->wiphy,
-                                                  attrs[NL80211_ATTR_MBSSID_ELEMS]);
+                                                  attrs[NL80211_ATTR_MBSSID_ELEMS],
+                                                  extack);
 
                if (IS_ERR(mbssid))
                        return PTR_ERR(mbssid);