Re: [PATCH wireless] wifi: brcmfmac: validate msgbuf flowring IDs before use

Arend van Spriel <[email protected]>
Newsgroups org.kernel.vger.stable,dev.linux.lists.brcm80211,org.kernel.vger.linux-kernel,org.kernel.vger.linux-wireless
Message-ID <[email protected]>
On 02/08/2026 10:39, Arend van Spriel wrote:
> On Thu, 23 Jul 2026 13:56:17 +0800, Can Peng <[email protected]> wrote:
>> Firmware messages carry flow_ring_id values which brcmfmac converts
>> to an internal flowid by subtracting
>> BRCMF_H2D_MSGRING_FLOWRING_IDSTART. The resulting value is used as
>> a bit index in txstatus_done_map and as an array index into
>> msgbuf->flowrings and the flowring state.
>>
>> Validate the firmware supplied flow_ring_id before using it. This
>> prevents flow_ring_id values below BRCMF_H2D_MSGRING_FLOWRING_IDSTART
>> from underflowing and rejects values outside msgbuf->max_flowrings.
>>
>> In the tx status path, complete the packet with an error after
>> removing a valid packet id so the skb is not leaked when the flow
>> ring id is invalid.
>>
>> Fixes: 9a1bb60250d2 ("brcmfmac: Adding msgbuf protocol.")
>> Cc: [email protected]
>> Signed-off-by: Can Peng <[email protected]>
>> ---
>>   .../wireless/broadcom/brcm80211/brcmfmac/msgbuf.c  | 46 +++++++++++++++++++---
>>   1 file changed, 40 insertions(+), 6 deletions(-)
> 
> One nit: there is a double blank line between brcmf_msgbuf_get_flowid()
> and brcmf_msgbuf_dequeue_work() in the resulting code. This comes from
> the pre-existing double blank line that was between
> brcmf_msgbuf_remove_flowring() and brcmf_msgbuf_dequeue_work() -- worth
> cleaning up to a single blank line.
> 
> Minor enough that I will take care of it while applying if you do not
> send a v2.

As I do not apply anything anywhere maybe Johannes will, but feel free 
to send that v2.

Regards,
Arend
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.