]> git.ipfire.org Git - thirdparty/kernel/linux.git/commitdiff
wifi: rsi: validate beacon length before fixed buffer copy
authorPengpeng Hou <pengpeng@iscas.ac.cn>
Sun, 5 Jul 2026 08:48:24 +0000 (16:48 +0800)
committerJohannes Berg <johannes.berg@intel.com>
Mon, 6 Jul 2026 12:11:09 +0000 (14:11 +0200)
rsi_prepare_beacon() copies the mac80211 beacon frame after
FRAME_DESC_SZ into a management skb whose usable tailroom may be smaller
than MAX_MGMT_PKT_SIZE after alignment.

Validate the beacon length against the actual tailroom before the copy
and skb_put(). Leave ownership of the management skb with the caller on
error, matching the existing rsi_send_beacon() cleanup path.

Signed-off-by: Pengpeng Hou <pengpeng@iscas.ac.cn>
Link: https://patch.msgid.link/20260705084824.68105-1-pengpeng@iscas.ac.cn
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
drivers/net/wireless/rsi/rsi_91x_hal.c

index a0c36144eb0b23f7e3f9c7eec3378514308340f8..501071104a9fe631247458430f646380376fc31d 100644 (file)
@@ -431,6 +431,7 @@ int rsi_prepare_beacon(struct rsi_common *common, struct sk_buff *skb)
        struct ieee80211_vif *vif;
        struct sk_buff *mac_bcn;
        u8 vap_id = 0, i;
+       unsigned int tailroom;
        u16 tim_offset = 0;
 
        for (i = 0; i < RSI_MAX_VIFS; i++) {
@@ -480,6 +481,13 @@ int rsi_prepare_beacon(struct rsi_common *common, struct sk_buff *skb)
        if (mac_bcn->data[tim_offset + 2] == 0)
                bcn_frm->frame_info |= cpu_to_le16(RSI_DATA_DESC_DTIM_BEACON);
 
+       tailroom = skb_tailroom(skb);
+       if (tailroom < FRAME_DESC_SZ ||
+           mac_bcn->len > tailroom - FRAME_DESC_SZ) {
+               dev_kfree_skb(mac_bcn);
+               return -EMSGSIZE;
+       }
+
        memcpy(&skb->data[FRAME_DESC_SZ], mac_bcn->data, mac_bcn->len);
        skb_put(skb, mac_bcn->len + FRAME_DESC_SZ);