CVE-2026-64571: wifi: p54: validate RX frame length in p54_rx_eeprom_readback()
Greg Kroah-Hartman <[email protected]>
| Newsgroups | org.kernel.vger.linux-cve-announce |
|---|---|
| Message-ID | <2026080559-CVE-2026-64571-f2f0@gregkh> |
From: Greg Kroah-Hartman <[email protected]> Description =========== In the Linux kernel, the following vulnerability has been resolved: wifi: p54: validate RX frame length in p54_rx_eeprom_readback() p54_rx_eeprom_readback() copies the requested EEPROM slice out of a device-supplied readback frame without checking that the skb actually holds that many bytes. Commit da1b9a55ff11 ("wifi: p54: prevent buffer-overflow in p54_rx_eeprom_readback()") closed the destination overflow by copying a fixed priv->eeprom_slice_size (and rejecting a mismatched advertised len), but the source side is still unbounded: nothing verifies the frame is long enough to supply that many bytes. A malicious USB device can send a short frame whose advertised len matches priv->eeprom_slice_size while the payload is truncated. The equality check passes and memcpy() reads past the end of the skb, leaking adjacent heap: BUG: KASAN: slab-out-of-bounds in p54_rx (drivers/net/wireless/intersil/p54/txrx.c:507) Read of size 1016 at addr ffff88800f077114 by task swapper/0/0 Call Trace: <IRQ> ... __asan_memcpy (mm/kasan/shadow.c:105) p54_rx (drivers/net/wireless/intersil/p54/txrx.c:507) p54u_rx_cb (drivers/net/wireless/intersil/p54/p54usb.c:163) __usb_hcd_giveback_urb (drivers/usb/core/hcd.c:1657) dummy_timer (drivers/usb/gadget/udc/dummy_hcd.c:2005) ... </IRQ> The buggy address belongs to the object at ffff88800f0770c0 which belongs to the cache skbuff_small_head of size 704 The buggy address is located 84 bytes inside of allocated 704-byte region [ffff88800f0770c0, ffff88800f077380) Check that the slice fits in the skb before copying. The Linux kernel CVE team has assigned CVE-2026-64571 to this issue. Affected and fixed versions =========================== Issue introduced in 2.6.28 with commit 7cb770729ba895f73253dfcd46c3fcba45d896f9 and fixed in 6.6.148 with commit 25c3b85af3fc4f8043159b14e65790fc3bbdaf48 Issue introduced in 2.6.28 with commit 7cb770729ba895f73253dfcd46c3fcba45d896f9 and fixed in 6.12.101 with commit f46f8f9c43fd02f4dd5f716d4bda296a523c04f0 Issue introduced in 2.6.28 with commit 7cb770729ba895f73253dfcd46c3fcba45d896f9 and fixed in 6.18.42 with commit d38f5d868a0a4770e3bcd0925e16c46acdbc9509 Issue introduced in 2.6.28 with commit 7cb770729ba895f73253dfcd46c3fcba45d896f9 and fixed in 7.1.6 with commit 9096e1f7014174067239a63df18ae5f28301990d Issue introduced in 2.6.28 with commit 7cb770729ba895f73253dfcd46c3fcba45d896f9 and fixed in 7.2-rc4 with commit ebd6d37fa94bee929e0b4c9ca19fdf9b1dcf6cea Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2026-64571 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: drivers/net/wireless/intersil/p54/txrx.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/25c3b85af3fc4f8043159b14e65790fc3bbdaf48 https://git.kernel.org/stable/c/f46f8f9c43fd02f4dd5f716d4bda296a523c04f0 https://git.kernel.org/stable/c/d38f5d868a0a4770e3bcd0925e16c46acdbc9509 https://git.kernel.org/stable/c/9096e1f7014174067239a63df18ae5f28301990d https://git.kernel.org/stable/c/ebd6d37fa94bee929e0b4c9ca19fdf9b1dcf6cea