]> git.ipfire.org Git - thirdparty/kernel/linux.git/commitdiff
wifi: at76c50x-usb: avoid length underflow in at76_guess_freq()
authorHuihui Huang <hhhuang@smu.edu.sg>
Wed, 15 Jul 2026 14:08:10 +0000 (22:08 +0800)
committerJohannes Berg <johannes.berg@intel.com>
Tue, 21 Jul 2026 11:27:38 +0000 (13:27 +0200)
at76_guess_freq() checks only that the received frame is at least a bare
802.11 header (24 bytes) before subtracting the fixed management-body
offset:

len -= el_off;

For both beacon and probe response frames, el_off is 36. If the frame is
shorter than el_off, subtracting it causes the calculated IE length to
wrap. The length is eventually passed to cfg80211_find_elem_match() as a
very large unsigned value, so the element walk runs beyond the RX skb.

This path is reached from at76_rx_tasklet() while scanning. If the device
delivers a truncated beacon or probe response, the oversized IE length
causes an out-of-bounds read during scanning.

Skip the IE lookup if the frame does not reach the variable elements,
before subtracting el_off.

Fixes: 1264b951463a ("at76c50x-usb: add driver")
Cc: stable@vger.kernel.org
Assisted-by: Claude:claude-opus-4-8
Signed-off-by: Huihui Huang <hhhuang@smu.edu.sg>
Link: https://patch.msgid.link/20260715140815.1242033-1-hhhuang@smu.edu.sg
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
drivers/net/wireless/atmel/at76c50x-usb.c

index 32e3e09e7680bb528bc55d809ad32f10cd9353be..d9c2809be4ba93ba7b52deb4219dd7b35988ed42 100644 (file)
@@ -1521,13 +1521,16 @@ static inline int at76_guess_freq(struct at76_priv *priv)
 
        if (ieee80211_is_probe_resp(hdr->frame_control)) {
                el_off = offsetof(struct ieee80211_mgmt, u.probe_resp.variable);
-               el = ((struct ieee80211_mgmt *)hdr)->u.probe_resp.variable;
        } else if (ieee80211_is_beacon(hdr->frame_control)) {
                el_off = offsetof(struct ieee80211_mgmt, u.beacon.variable);
-               el = ((struct ieee80211_mgmt *)hdr)->u.beacon.variable;
        } else {
                goto exit;
        }
+
+       if (len < el_off)
+               goto exit;
+
+       el = priv->rx_skb->data + el_off;
        len -= el_off;
 
        el = cfg80211_find_ie(WLAN_EID_DS_PARAMS, el, len);