]> git.ipfire.org Git - thirdparty/kernel/linux.git/commitdiff
staging: rtl8723bs: fix WEP length underflow and OOB read in OnAuth()
authorAlexandru Hossu <hossu.alexandru@gmail.com>
Fri, 22 May 2026 00:46:05 +0000 (02:46 +0200)
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Tue, 7 Jul 2026 11:42:23 +0000 (13:42 +0200)
OnAuth() has two bugs in the shared-key authentication path.

When the Privacy bit is set, rtw_wep_decrypt() is called without
verifying that the frame is long enough to contain a valid WEP IV and
ICV.  Inside rtw_wep_decrypt(), length is computed as:

    length = len - WLAN_HDR_A3_LEN - iv_len

and then passed as (length - 4) to crc32_le().  If len is less than
WLAN_HDR_A3_LEN + iv_len + icv_len (32 bytes), length - 4 is negative
and, after the implicit cast to size_t, causes crc32_le() to read far
beyond the frame buffer.  Add a minimum length check before accessing
the IV field and calling the decryption path.

When processing a seq=3 response, rtw_get_ie() stores the Challenge
Text IE length in ie_len, but the subsequent memcmp() always reads 128
bytes regardless of ie_len.  IEEE 802.11 mandates a challenge text of
exactly 128 bytes; reject any IE whose length field differs, matching
the check already applied to OnAuthClient().

Fixes: 554c0a3abf21 ("staging: Add rtl8723bs sdio wifi driver")
Cc: stable <stable@kernel.org>
Signed-off-by: Alexandru Hossu <hossu.alexandru@gmail.com>
Link: https://patch.msgid.link/20260522004605.1039209-1-hossu.alexandru@gmail.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
drivers/staging/rtl8723bs/core/rtw_mlme_ext.c

index a86d6f97cf02d7cba106cce23807e6e726862dc5..7198be79500080f08eb5e901d1ad0c702d3f12a2 100644 (file)
@@ -677,6 +677,9 @@ unsigned int OnAuth(struct adapter *padapter, union recv_frame *precv_frame)
        if ((pmlmeinfo->state&0x03) != WIFI_FW_AP_STATE)
                return _FAIL;
 
+       if (len < WLAN_HDR_A3_LEN)
+               return _FAIL;
+
        sa = GetAddr2Ptr(pframe);
 
        auth_mode = psecuritypriv->dot11AuthAlgrthm;
@@ -688,6 +691,9 @@ unsigned int OnAuth(struct adapter *padapter, union recv_frame *precv_frame)
                prxattrib->hdrlen = WLAN_HDR_A3_LEN;
                prxattrib->encrypt = _WEP40_;
 
+               if (len < WLAN_HDR_A3_LEN + 8)
+                       return _FAIL;
+
                iv = pframe+prxattrib->hdrlen;
                prxattrib->key_index = ((iv[3]>>6)&0x3);
 
@@ -787,7 +793,7 @@ unsigned int OnAuth(struct adapter *padapter, union recv_frame *precv_frame)
                        p = rtw_get_ie(pframe + WLAN_HDR_A3_LEN + 4 + _AUTH_IE_OFFSET_, WLAN_EID_CHALLENGE, (int *)&ie_len,
                                        len - WLAN_HDR_A3_LEN - _AUTH_IE_OFFSET_ - 4);
 
-                       if (!p || ie_len <= 0) {
+                       if (!p || ie_len != 128) {
                                status = WLAN_STATUS_CHALLENGE_FAIL;
                                goto auth_fail;
                        }