Re: [PATCH wireless] wifi: brcmfmac: validate msgbuf flowring IDs before use

Arend van Spriel <[email protected]>
Newsgroups org.kernel.vger.stable,dev.linux.lists.brcm80211,org.kernel.vger.linux-kernel,org.kernel.vger.linux-wireless
Message-ID <[email protected]>
On Thu, 23 Jul 2026 13:56:17 +0800, Can Peng <[email protected]> wrote:
> Firmware messages carry flow_ring_id values which brcmfmac converts
> to an internal flowid by subtracting
> BRCMF_H2D_MSGRING_FLOWRING_IDSTART. The resulting value is used as
> a bit index in txstatus_done_map and as an array index into
> msgbuf->flowrings and the flowring state.
>
> Validate the firmware supplied flow_ring_id before using it. This
> prevents flow_ring_id values below BRCMF_H2D_MSGRING_FLOWRING_IDSTART
> from underflowing and rejects values outside msgbuf->max_flowrings.
>
> In the tx status path, complete the packet with an error after
> removing a valid packet id so the skb is not leaked when the flow
> ring id is invalid.
>
> Fixes: 9a1bb60250d2 ("brcmfmac: Adding msgbuf protocol.")
> Cc: [email protected]
> Signed-off-by: Can Peng <[email protected]>
> ---
>  .../wireless/broadcom/brcm80211/brcmfmac/msgbuf.c  | 46 +++++++++++++++++++---
>  1 file changed, 40 insertions(+), 6 deletions(-)

One nit: there is a double blank line between brcmf_msgbuf_get_flowid()
and brcmf_msgbuf_dequeue_work() in the resulting code. This comes from
the pre-existing double blank line that was between
brcmf_msgbuf_remove_flowring() and brcmf_msgbuf_dequeue_work() -- worth
cleaning up to a single blank line.

Minor enough that I will take care of it while applying if you do not
send a v2.

To be applied to wireless tree.

Acked-by: Arend van Spriel <[email protected]>

Regards,
Arend
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.