https://github.com/torvalds/linux
Revision 9a6847ba1747858ccac53c5aba3e25c54fbdf846 authored by Johannes Berg on 08 April 2021, 13:45:20 UTC, committed by Johannes Berg on 08 April 2021, 14:43:05 UTC
If the beacon head attribute (NL80211_ATTR_BEACON_HEAD)
is too short to even contain the frame control field,
we access uninitialized data beyond the buffer. Fix this
by checking the minimal required size first. We used to
do this until S1G support was added, where the fixed
data portion has a different size.

Reported-and-tested-by: syzbot+72b99dcf4607e8c770f3@syzkaller.appspotmail.com
Suggested-by: Eric Dumazet <eric.dumazet@gmail.com>
Fixes: 1d47f1198d58 ("nl80211: correctly validate S1G beacon head")
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Link: https://lore.kernel.org/r/20210408154518.d9b06d39b4ee.Iff908997b2a4067e8d456b3cb96cab9771d252b8@changeid
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
1 parent abaf94e
History
Tip revision: 9a6847ba1747858ccac53c5aba3e25c54fbdf846 authored by Johannes Berg on 08 April 2021, 13:45:20 UTC
nl80211: fix beacon head validation
Tip revision: 9a6847b

back to top