Skip to content

Commit 0a1ac50

Browse files
P Praneeshsmb49
authored andcommitted
wifi: ath12k: Add MSDU length validation for TKIP MIC error
BugLink: https://bugs.launchpad.net/bugs/2119603 [ Upstream commit 763216fe6c5df95d122c71ef34c342427c987820 ] In the WBM error path, while processing TKIP MIC errors, MSDU length is fetched from the hal_rx_desc's msdu_end. This MSDU length is directly passed to skb_put() without validation. In stress test scenarios, the WBM error ring may receive invalid descriptors, which could lead to an invalid MSDU length. To fix this, add a check to drop the skb when the calculated MSDU length is greater than the skb size. Tested-on: QCN9274 hw2.0 PCI WLAN.WBE.1.3.1-00173-QCAHKSWPL_SILICONZ-1 Tested-on: WCN7850 hw2.0 PCI WLAN.HMT.1.0.c5-00481-QCAHMTSWPL_V1.0_V2.0_SILICONZ-3 Fixes: d889913 ("wifi: ath12k: driver for Qualcomm Wi-Fi 7 devices") Signed-off-by: P Praneesh <[email protected]> Signed-off-by: Nithyanantham Paramasivam <[email protected]> Reviewed-by: Vasanthakumar Thiagarajan <[email protected]> Link: https://patch.msgid.link/20250416021903.3178962-1-nithyanantham.paramasivam@oss.qualcomm.com Signed-off-by: Jeff Johnson <[email protected]> Signed-off-by: Sasha Levin <[email protected]> Signed-off-by: Manuel Diewald <[email protected]> Signed-off-by: Mehmet Basaran <[email protected]>
1 parent 59639a8 commit 0a1ac50

File tree

1 file changed

+9
-0
lines changed
  • drivers/net/wireless/ath/ath12k

1 file changed

+9
-0
lines changed

drivers/net/wireless/ath/ath12k/dp_rx.c

Lines changed: 9 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -3824,6 +3824,15 @@ static bool ath12k_dp_rx_h_tkip_mic_err(struct ath12k *ar, struct sk_buff *msdu,
38243824

38253825
l3pad_bytes = ath12k_dp_rx_h_l3pad(ab, desc);
38263826
msdu_len = ath12k_dp_rx_h_msdu_len(ab, desc);
3827+
3828+
if ((hal_rx_desc_sz + l3pad_bytes + msdu_len) > DP_RX_BUFFER_SIZE) {
3829+
ath12k_dbg(ab, ATH12K_DBG_DATA,
3830+
"invalid msdu len in tkip mic err %u\n", msdu_len);
3831+
ath12k_dbg_dump(ab, ATH12K_DBG_DATA, NULL, "", desc,
3832+
sizeof(*desc));
3833+
return true;
3834+
}
3835+
38273836
skb_put(msdu, hal_rx_desc_sz + l3pad_bytes + msdu_len);
38283837
skb_pull(msdu, hal_rx_desc_sz + l3pad_bytes);
38293838

0 commit comments

Comments
 (0)