]> git.ipfire.org Git - thirdparty/kernel/linux.git/commitdiff
wifi: iwlwifi: mvm: fix out-of-bounds tid_data access in BA notif
authorEmmanuel Grumbach <emmanuel.grumbach@intel.com>
Wed, 15 Jul 2026 18:57:11 +0000 (21:57 +0300)
committerMiri Korenblit <miriam.rachel.korenblit@intel.com>
Thu, 16 Jul 2026 18:12:19 +0000 (21:12 +0300)
mvmsta->tid_data was indexed by the TFD loop counter 'i' instead of
the actual TID value 'tid'. This writes lq_color into a random tid_data
slot unrelated to the BA entry.
Since multi-TID blockack is not really in use, 'i' was always 0 and no
harm was done.
Add a out-of-bound check before accessing the array.

Assisted-by: GitHubCopilot:gpt-5.3-codex
Signed-off-by: Emmanuel Grumbach <emmanuel.grumbach@intel.com>
Signed-off-by: Miri Korenblit <miriam.rachel.korenblit@intel.com>
Link: https://patch.msgid.link/20260715215523.919edee567eb.Ie85c350e3afe2b39709d0039072740d86660f8ae@changeid
drivers/net/wireless/intel/iwlwifi/mvm/tx.c

index d8b088e7c2504ac1dcf785e98ae0608a52620783..e02c376296c497d1832a76beacf8ff8e625c335d 100644 (file)
@@ -2134,8 +2134,14 @@ void iwl_mvm_rx_ba_notif(struct iwl_mvm *mvm, struct iwl_rx_cmd_buffer *rxb)
                        if (tid == IWL_MGMT_TID)
                                tid = IWL_MAX_TID_COUNT;
 
+                       if (IWL_FW_CHECK(mvm, tid >=
+                                        ARRAY_SIZE(mvmsta->tid_data),
+                                        "invalid TID %d in compressed BA\n",
+                                        tid))
+                               continue;
+
                        if (mvmsta)
-                               mvmsta->tid_data[i].lq_color = lq_color;
+                               mvmsta->tid_data[tid].lq_color = lq_color;
 
                        iwl_mvm_tx_reclaim(mvm, sta_id, tid,
                                           (int)(le16_to_cpu(ba_tfd->q_num)),