]> git.ipfire.org Git - thirdparty/kernel/stable.git/commitdiff
wifi: mac80211: drop invalid source address OCB frames
authorJohannes Berg <johannes.berg@intel.com>
Mon, 16 Jun 2025 15:18:38 +0000 (17:18 +0200)
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Thu, 17 Jul 2025 16:24:57 +0000 (18:24 +0200)
[ Upstream commit d1b1a5eb27c4948e8811cf4dbb05aaf3eb10700c ]

In OCB, don't accept frames from invalid source addresses
(and in particular don't try to create stations for them),
drop the frames instead.

Reported-by: syzbot+8b512026a7ec10dcbdd9@syzkaller.appspotmail.com
Closes: https://lore.kernel.org/r/6788d2d9.050a0220.20d369.0028.GAE@google.com/
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Tested-by: syzbot+8b512026a7ec10dcbdd9@syzkaller.appspotmail.com
Link: https://patch.msgid.link/20250616171838.7433379cab5d.I47444d63c72a0bd58d2e2b67bb99e1fea37eec6f@changeid
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
net/mac80211/rx.c

index 99d5f8b58e92e69dbbf900d92e32b5b554fc1fa8..4c805530edfb666db81031e3985831bb5a872595 100644 (file)
@@ -3982,6 +3982,10 @@ static bool ieee80211_accept_frame(struct ieee80211_rx_data *rx)
                if (!multicast &&
                    !ether_addr_equal(sdata->dev->dev_addr, hdr->addr1))
                        return false;
+               /* reject invalid/our STA address */
+               if (!is_valid_ether_addr(hdr->addr2) ||
+                   ether_addr_equal(sdata->dev->dev_addr, hdr->addr2))
+                       return false;
                if (!rx->sta) {
                        int rate_idx;
                        if (status->encoding != RX_ENC_LEGACY)