Received: by 2002:a05:6a10:6d10:0:0:0:0 with SMTP id gq16csp773310pxb; Tue, 12 Apr 2022 13:05:22 -0700 (PDT) X-Google-Smtp-Source: ABdhPJwD0+dx9aqGfAMtijPgRf9cPO9vTfgPdtgKLiHhNgxeWqqU24MhMGNGXSOCRClo06+Up34M X-Received: by 2002:a05:6a00:1512:b0:505:da8c:26ba with SMTP id q18-20020a056a00151200b00505da8c26bamr7530620pfu.63.1649793922046; Tue, 12 Apr 2022 13:05:22 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1649793922; cv=none; d=google.com; s=arc-20160816; b=eL2gTLl+YUB1lFxsi9xGMb0vAaVG5pXjFVFEBoCVhTxJy28KDiK5rY4i5sSWzQ3YJS 5WjpJpHgNVsOHwHPCHUpdsPlaLs3vkmRLPLm3hGZ/xOq+3BKkBEKEqB8WNpeBWvYJz02 8D5VZzWa7D2k6DdbJbrxWPQCd37W+5tynv4dX16duFoOObZcTV5xJ+o3Jrt1XtDw1Wyf QfNCE8Q7o7VRek0bscsi+l7KnUNHy/PYCaSfsuz//4YZLVuKvw0+tWmQhu/FQ+boPoZW hTGTmbISLOK8RuF94eRwTIhXJyipsp7JPUhJE3UKVqiOyZzQHVBRAI7d/8sDVPNW1IJi 0D3A== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:content-transfer-encoding:mime-version :user-agent:message-id:in-reply-to:date:references:subject:cc:to :from:dkim-signature; bh=4SRMm+oi+OXE5VmvCpvFhkMlZkhqhIVBfNpql/7kyPQ=; b=CPsgoEZP87gzRHBnk06NBQv4Z4+k9y8FaKWFbX9U0l+aInutBt5tMqeu7zCHZmu5DA 5QPDjKegFa/GFT/c+qAejmkXoZo37CcXHgzdvkO/+gwjb8AX1M9k+XoXeUgq2qsuk+ky fT73SWTIuY2Mys0okB1Qilq6gWpylMgMPcL38G0y/j+iFauAqrc7PDntG3ElnqgC29iz /TrEPD9yDTk/thJnuXs1AoBgKz1C/XYtE1Zoq4SHLYupxqp/g/75uXMajQfuk6VFsWdb JbkSXQGeSXiyAlZJnnhe181hlqLQKehM5HNkywxTrK4cGL266ZrIWoFzOomrUDIyv2vV 3tvA== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@kernel.org header.s=k20201202 header.b=qWV+Lea1; spf=softfail (google.com: domain of transitioning linux-wireless-owner@vger.kernel.org does not designate 23.128.96.19 as permitted sender) smtp.mailfrom=linux-wireless-owner@vger.kernel.org; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=kernel.org Return-Path: Received: from lindbergh.monkeyblade.net (lindbergh.monkeyblade.net. [23.128.96.19]) by mx.google.com with ESMTPS id t2-20020a632242000000b00399322fc262si3252512pgm.663.2022.04.12.13.05.21 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 12 Apr 2022 13:05:22 -0700 (PDT) Received-SPF: softfail (google.com: domain of transitioning linux-wireless-owner@vger.kernel.org does not designate 23.128.96.19 as permitted sender) client-ip=23.128.96.19; Authentication-Results: mx.google.com; dkim=pass header.i=@kernel.org header.s=k20201202 header.b=qWV+Lea1; spf=softfail (google.com: domain of transitioning linux-wireless-owner@vger.kernel.org does not designate 23.128.96.19 as permitted sender) smtp.mailfrom=linux-wireless-owner@vger.kernel.org; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=kernel.org Received: from vger.kernel.org (vger.kernel.org [23.128.96.18]) by lindbergh.monkeyblade.net (Postfix) with ESMTP id F17D86169; Tue, 12 Apr 2022 12:54:20 -0700 (PDT) Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1356120AbiDLN3h (ORCPT + 70 others); Tue, 12 Apr 2022 09:29:37 -0400 Received: from lindbergh.monkeyblade.net ([23.128.96.19]:52318 "EHLO lindbergh.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S232196AbiDLN3X (ORCPT ); Tue, 12 Apr 2022 09:29:23 -0400 Received: from dfw.source.kernel.org (dfw.source.kernel.org [139.178.84.217]) by lindbergh.monkeyblade.net (Postfix) with ESMTPS id 6C9A1D7; Tue, 12 Apr 2022 06:27:05 -0700 (PDT) Received: from smtp.kernel.org (relay.kernel.org [52.25.139.140]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by dfw.source.kernel.org (Postfix) with ESMTPS id 07F46619D7; Tue, 12 Apr 2022 13:27:05 +0000 (UTC) Received: by smtp.kernel.org (Postfix) with ESMTPSA id 9577EC385A1; Tue, 12 Apr 2022 13:27:02 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kernel.org; s=k20201202; t=1649770024; bh=4SRMm+oi+OXE5VmvCpvFhkMlZkhqhIVBfNpql/7kyPQ=; h=From:To:Cc:Subject:References:Date:In-Reply-To:From; b=qWV+Lea1tXQSYUwgAZtZ4pFi645XWEi86YDrMS5snj9TX+F+EB71mhkf6z+nkVQJC pOFfIIwNE6tbqP0AaW10xIYlFU2dMzdNbED/siTYxuiUe+9uYD1wZXB054SuoKew7x J3CtwsI6+cA9Lwk567ss31520Qs02GSKDHEfO0VgnH+2s4h0yb4tuZWhVniTKsAi+w G9BwMQj/ECIY1rGwnGy5SbQQ+vxCNu+VhmwBcuRaHTehE09xPQi+WivOB9/c7gaXvn PtyP3Ljv3pxOkmhMUz7/JxdCYskS9h2bkuddyZ+qB1oV4uIzscVkcYZqjKSL3nuy5/ nEdeJizXLDpxg== From: Kalle Valo To: Toke =?utf-8?Q?H=C3=B8iland-J=C3=B8rgensen?= Cc: Dan Carpenter , Oleksij Rempel , Jakub Kicinski , Paolo Abeni , "John W. Linville" , linux-wireless@vger.kernel.org, kernel-janitors@vger.kernel.org Subject: Re: [PATCH] ath9k_htc: fix potential out of bounds access with invalid rxstatus->rs_keyix References: <20220409061225.GA5447@kili> <87tub26ir2.fsf@toke.dk> Date: Tue, 12 Apr 2022 16:26:58 +0300 In-Reply-To: <87tub26ir2.fsf@toke.dk> ("Toke \=\?utf-8\?Q\?H\=C3\=B8iland-J\?\= \=\?utf-8\?Q\?\=C3\=B8rgensen\=22's\?\= message of "Sat, 09 Apr 2022 23:37:21 +0200") Message-ID: <875yneo2jh.fsf@kernel.org> User-Agent: Gnus/5.13 (Gnus v5.13) Emacs/26.1 (gnu/linux) MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: quoted-printable X-Spam-Status: No, score=-2.3 required=5.0 tests=BAYES_00,DKIMWL_WL_HIGH, DKIM_SIGNED,DKIM_VALID,DKIM_VALID_AU,DKIM_VALID_EF,MAILING_LIST_MULTI, RDNS_NONE,SPF_HELO_NONE,T_SCC_BODY_TEXT_LINE autolearn=unavailable autolearn_force=no version=3.4.6 X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on lindbergh.monkeyblade.net Precedence: bulk List-ID: X-Mailing-List: linux-wireless@vger.kernel.org Toke H=C3=B8iland-J=C3=B8rgensen writes: > Dan Carpenter writes: > >> The "rxstatus->rs_keyix" eventually gets passed to test_bit() so we need= to >> ensure that it is within than bitmap. > > s/than/the/ ? > > This I think Kalle can fix up when applying :) Yup, fixed now in the pending branch. --=20 https://patchwork.kernel.org/project/linux-wireless/list/ https://wireless.wiki.kernel.org/en/developers/documentation/submittingpatc= hes