Skip to content

Commit 6a6c61d

Browse files
Peng Xugregkh
authored andcommitted
nl80211: Define policy for packet pattern attributes
commit ad670233c9e1d5feb365d870e30083ef1b889177 upstream. Define a policy for packet pattern attributes in order to fix a potential read over the end of the buffer during nla_get_u32() of the NL80211_PKTPAT_OFFSET attribute. Note that the data there can always be read due to SKB allocation (with alignment and struct skb_shared_info at the end), but the data might be uninitialized. This could be used to leak some data from uninitialized vmalloc() memory, but most drivers don't allow an offset (so you'd just get -EINVAL if the data is non-zero) or just allow it with a fixed value - 100 or 128 bytes, so anything above that would get -EINVAL. With brcmfmac the limit is 1500 so (at least) one byte could be obtained. Cc: stable@kernel.org Signed-off-by: Peng Xu <pxu@qti.qualcomm.com> Signed-off-by: Jouni Malinen <jouni@qca.qualcomm.com> [rewrite description based on SKB allocation knowledge] Signed-off-by: Johannes Berg <johannes.berg@intel.com> Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
1 parent f2bb4bc commit 6a6c61d

1 file changed

Lines changed: 10 additions & 2 deletions

File tree

net/wireless/nl80211.c

Lines changed: 10 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -485,6 +485,14 @@ nl80211_plan_policy[NL80211_SCHED_SCAN_PLAN_MAX + 1] = {
485485
[NL80211_SCHED_SCAN_PLAN_ITERATIONS] = { .type = NLA_U32 },
486486
};
487487

488+
/* policy for packet pattern attributes */
489+
static const struct nla_policy
490+
nl80211_packet_pattern_policy[MAX_NL80211_PKTPAT + 1] = {
491+
[NL80211_PKTPAT_MASK] = { .type = NLA_BINARY, },
492+
[NL80211_PKTPAT_PATTERN] = { .type = NLA_BINARY, },
493+
[NL80211_PKTPAT_OFFSET] = { .type = NLA_U32 },
494+
};
495+
488496
static int nl80211_prepare_wdev_dump(struct sk_buff *skb,
489497
struct netlink_callback *cb,
490498
struct cfg80211_registered_device **rdev,
@@ -9410,7 +9418,7 @@ static int nl80211_set_wowlan(struct sk_buff *skb, struct genl_info *info)
94109418
u8 *mask_pat;
94119419

94129420
nla_parse(pat_tb, MAX_NL80211_PKTPAT, nla_data(pat),
9413-
nla_len(pat), NULL);
9421+
nla_len(pat), nl80211_packet_pattern_policy);
94149422
err = -EINVAL;
94159423
if (!pat_tb[NL80211_PKTPAT_MASK] ||
94169424
!pat_tb[NL80211_PKTPAT_PATTERN])
@@ -9660,7 +9668,7 @@ static int nl80211_parse_coalesce_rule(struct cfg80211_registered_device *rdev,
96609668
u8 *mask_pat;
96619669

96629670
nla_parse(pat_tb, MAX_NL80211_PKTPAT, nla_data(pat),
9663-
nla_len(pat), NULL);
9671+
nla_len(pat), nl80211_packet_pattern_policy);
96649672
if (!pat_tb[NL80211_PKTPAT_MASK] ||
96659673
!pat_tb[NL80211_PKTPAT_PATTERN])
96669674
return -EINVAL;

0 commit comments

Comments
 (0)