CVE-2026-64571: wifi: p54: validate RX frame length in p54_rx_eeprom_readback()

Greg Kroah-Hartman <[email protected]>
Newsgroups org.kernel.vger.linux-cve-announce
Message-ID <2026080559-CVE-2026-64571-f2f0@gregkh>
From: Greg Kroah-Hartman <[email protected]>

Description
===========

In the Linux kernel, the following vulnerability has been resolved:

wifi: p54: validate RX frame length in p54_rx_eeprom_readback()

p54_rx_eeprom_readback() copies the requested EEPROM slice out of a
device-supplied readback frame without checking that the skb actually holds
that many bytes. Commit da1b9a55ff11 ("wifi: p54: prevent buffer-overflow in
p54_rx_eeprom_readback()") closed the destination overflow by copying a
fixed priv->eeprom_slice_size (and rejecting a mismatched advertised len),
but the source side is still unbounded: nothing verifies the frame is long
enough to supply that many bytes.

A malicious USB device can send a short frame whose advertised len matches
priv->eeprom_slice_size while the payload is truncated. The equality check
passes and memcpy() reads past the end of the skb, leaking adjacent heap:

  BUG: KASAN: slab-out-of-bounds in p54_rx (drivers/net/wireless/intersil/p54/txrx.c:507)
  Read of size 1016 at addr ffff88800f077114 by task swapper/0/0
  Call Trace:
   <IRQ>
   ...
   __asan_memcpy (mm/kasan/shadow.c:105)
   p54_rx (drivers/net/wireless/intersil/p54/txrx.c:507)
   p54u_rx_cb (drivers/net/wireless/intersil/p54/p54usb.c:163)
   __usb_hcd_giveback_urb (drivers/usb/core/hcd.c:1657)
   dummy_timer (drivers/usb/gadget/udc/dummy_hcd.c:2005)
   ...
   </IRQ>

  The buggy address belongs to the object at ffff88800f0770c0
   which belongs to the cache skbuff_small_head of size 704
  The buggy address is located 84 bytes inside of
   allocated 704-byte region [ffff88800f0770c0, ffff88800f077380)

Check that the slice fits in the skb before copying.

The Linux kernel CVE team has assigned CVE-2026-64571 to this issue.


Affected and fixed versions
===========================

	Issue introduced in 2.6.28 with commit 7cb770729ba895f73253dfcd46c3fcba45d896f9 and fixed in 6.6.148 with commit 25c3b85af3fc4f8043159b14e65790fc3bbdaf48
	Issue introduced in 2.6.28 with commit 7cb770729ba895f73253dfcd46c3fcba45d896f9 and fixed in 6.12.101 with commit f46f8f9c43fd02f4dd5f716d4bda296a523c04f0
	Issue introduced in 2.6.28 with commit 7cb770729ba895f73253dfcd46c3fcba45d896f9 and fixed in 6.18.42 with commit d38f5d868a0a4770e3bcd0925e16c46acdbc9509
	Issue introduced in 2.6.28 with commit 7cb770729ba895f73253dfcd46c3fcba45d896f9 and fixed in 7.1.6 with commit 9096e1f7014174067239a63df18ae5f28301990d
	Issue introduced in 2.6.28 with commit 7cb770729ba895f73253dfcd46c3fcba45d896f9 and fixed in 7.2-rc4 with commit ebd6d37fa94bee929e0b4c9ca19fdf9b1dcf6cea

Please see https://www.kernel.org for a full list of currently supported
kernel versions by the kernel community.

Unaffected versions might change over time as fixes are backported to
older supported kernel versions.  The official CVE entry at
	https://cve.org/CVERecord/?id=CVE-2026-64571
will be updated if fixes are backported, please check that for the most
up to date information about this issue.


Affected files
==============

The file(s) affected by this issue are:
	drivers/net/wireless/intersil/p54/txrx.c


Mitigation
==========

The Linux kernel CVE team recommends that you update to the latest
stable kernel version for this, and many other bugfixes.  Individual
changes are never tested alone, but rather are part of a larger kernel
release.  Cherry-picking individual commits is not recommended or
supported by the Linux kernel community at all.  If however, updating to
the latest release is impossible, the individual changes to resolve this
issue can be found at these commits:
	https://git.kernel.org/stable/c/25c3b85af3fc4f8043159b14e65790fc3bbdaf48
	https://git.kernel.org/stable/c/f46f8f9c43fd02f4dd5f716d4bda296a523c04f0
	https://git.kernel.org/stable/c/d38f5d868a0a4770e3bcd0925e16c46acdbc9509
	https://git.kernel.org/stable/c/9096e1f7014174067239a63df18ae5f28301990d
	https://git.kernel.org/stable/c/ebd6d37fa94bee929e0b4c9ca19fdf9b1dcf6cea
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.