Re: [PATCH ath-next 1/2] wifi: ath11k: fix invalid data access in ath11k_dp_rx_h_undecap_nwifi
Jeff Johnson <[email protected]> Mon, 1 Jun 2026 09:09:16 -0700
| Newsgroups | org.infradead.lists.ath11k,org.kernel.vger.linux-kernel,org.kernel.vger.linux-wireless |
|---|---|
| Message-ID | <[email protected]> |
On 5/31/2026 8:47 PM, Baochen Qiang wrote: > > > On 5/12/2026 10:23 AM, Miaoqing Pan wrote: >> In certain cases, hardware might provide packets with a >> length greater than the maximum native Wi-Fi header length. >> This can lead to accessing and modifying fields in the header >> within the ath11k_dp_rx_h_undecap_nwifi() function for the >> DP_RX_DECAP_TYPE_NATIVE_WIFI decap type and >> potentially result in invalid data access and memory corruption. >> >> Kernel stack is corrupted in: ath11k_dp_rx_h_undecap+0x6b0/0x6b0 [ath11k] >> Call trace: >> ath11k_dp_rx_h_mpdu+0x0/0x2e8 [ath11k] >> ath11k_dp_rx_h_mpdu+0x1e0/0x2e8 [ath11k] >> ath11k_dp_rx_wbm_err+0x1e0/0x450 [ath11k] >> ath11k_dp_rx_process_wbm_err+0x2fc/0x460 [ath11k] >> ath11k_dp_service_srng+0x2e0/0x348 [ath11k] >> >> Add a sanity check before processing the SKB to prevent invalid >> data access in the undecap native Wi-Fi function for the >> DP_RX_DECAP_TYPE_NATIVE_WIFI decap type. >> >> This adapted from the discussion/patch of the ath12k driver [1]. >> >> Tested-on: WCN6855 hw2.1 PCI WLAN.HSP.1.1-04685-QCAHSPSWPL_V1_V2_SILICONZ_IOE-1 >> >> Link: https://lore.kernel.org/linux-wireless/[email protected]/ # [1] >> Signed-off-by: Miaoqing Pan <[email protected]> >> --- >> drivers/net/wireless/ath/ath11k/dp_rx.c | 50 +++++++++++++++++++++++-- >> 1 file changed, 47 insertions(+), 3 deletions(-) >> >> diff --git a/drivers/net/wireless/ath/ath11k/dp_rx.c b/drivers/net/wireless/ath/ath11k/dp_rx.c >> index fe79109adc70..fbe2061a544d 100644 >> --- a/drivers/net/wireless/ath/ath11k/dp_rx.c >> +++ b/drivers/net/wireless/ath/ath11k/dp_rx.c >> @@ -2502,6 +2502,29 @@ static void ath11k_dp_rx_deliver_msdu(struct ath11k *ar, struct napi_struct *nap >> ieee80211_rx_napi(ar->hw, pubsta, msdu, napi); >> } >> >> +static bool ath11k_dp_rx_check_nwifi_hdr_len_valid(struct ath11k_base *ab, >> + struct hal_rx_desc *rx_desc, >> + struct sk_buff *msdu) >> +{ >> + struct ieee80211_hdr *hdr; >> + u8 decap_type; >> + u32 hdr_len; >> + >> + decap_type = ath11k_dp_rx_h_msdu_start_decap_type(ab, rx_desc); >> + if (decap_type != DP_RX_DECAP_TYPE_NATIVE_WIFI) >> + return true; >> + >> + hdr = (struct ieee80211_hdr *)msdu->data; >> + hdr_len = ieee80211_hdrlen(hdr->frame_control); >> + >> + if ((likely(hdr_len <= DP_MAX_NWIFI_HDR_LEN))) > > nit: Double parentheses on likely() I've fixed this in the 'pending' branch: https://git.kernel.org/pub/scm/linux/kernel/git/ath/ath.git/commit/?h=pending&id=99f35f3f082fca14fc3324e48abd805871d39c69