Received: by 2002:a05:6358:1087:b0:cb:c9d3:cd90 with SMTP id j7csp723565rwi; Thu, 20 Oct 2022 04:37:44 -0700 (PDT) X-Google-Smtp-Source: AMsMyM7VuynvobUIGNmkx/6eygz1seD2f9eKpni6skSVDUjEItRZpjVErtUZ89aymCQu2A4VybtV X-Received: by 2002:a17:90a:e548:b0:211:2c0c:cb74 with SMTP id ei8-20020a17090ae54800b002112c0ccb74mr5183081pjb.69.1666265864626; Thu, 20 Oct 2022 04:37:44 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1666265864; cv=none; d=google.com; s=arc-20160816; b=yF7X5YdJKNoXdHxmLxCX7aTkfu1+TgsswtZ3zNJZmfeFpYjjT3uqlcMGYy/fsCakFY MMkJNY4bRo8x7jthXuP7XzAtEjxv3axEW0aLpRiPMbaVjTPcyMuviolA5+Czgr0fHdpv TAnIXANb3sc4xy5Xo6u8ueMa3a8Z6CAWkGZqvGkMPb/3t9ewDmZc8e1s9aufS2GTBoFR QcT89MrgbTxnNfWXIfD+66J8BnJecIYdAB/tEPqYPoIYdFkTcdA/hy0w5eADgiEwqXaY xO0YOTtO8GeTQYpr4t3V870Gy4FCWe9GTMT2+WSlzg5WtO1WDza+YmIV7kdzCSvc75SQ GR4Q== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:content-transfer-encoding:in-reply-to:from :references:cc:to:content-language:subject:user-agent:mime-version :date:message-id:dkim-signature; bh=90wiFngH1+zfXrSTTOx8+fdGzM6IhOrpFDU4dB9LYfU=; b=hwAWknJ70q04E0Wdpu+Uvi8CUqGKfW7dP6Kf67AP+DX+gsQTgpVOSig4Ph3BBNnD3e jL5/52p02wcoYz/y7fqA3L3vUeNl1/d0nsYpOwFMIWEyzQqXdtZQ5IrPhQYQzLvrnuoD ZipJffW/JD1IrX54pXz03Wl0KG8cET7+FdSFkE3TpdY2y+mzVFmyMicBSd7gCx5RDhtb DqCSRcD/IqSDMSX3gvkgy2Ug0NjVKjqUUU3g845CkT9vCnWuU6lpzktJ1QJjJGVH2mbc K/O8lO/prTEt0gLD6iAa8GUOMKz+anEd7dW6FfLcV4zU1BUYdHiBbXJTKNvOHMk9T9p3 RYdw== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@gmail.com header.s=20210112 header.b="S5PC/bn5"; spf=pass (google.com: domain of linux-wireless-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) smtp.mailfrom=linux-wireless-owner@vger.kernel.org; dmarc=pass (p=NONE sp=QUARANTINE dis=NONE) header.from=gmail.com Return-Path: Received: from out1.vger.email (out1.vger.email. [2620:137:e000::1:20]) by mx.google.com with ESMTP id y31-20020a056a00181f00b00562a1693523si22336580pfa.20.2022.10.20.04.37.33; Thu, 20 Oct 2022 04:37:44 -0700 (PDT) Received-SPF: pass (google.com: domain of linux-wireless-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) client-ip=2620:137:e000::1:20; Authentication-Results: mx.google.com; dkim=pass header.i=@gmail.com header.s=20210112 header.b="S5PC/bn5"; spf=pass (google.com: domain of linux-wireless-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) smtp.mailfrom=linux-wireless-owner@vger.kernel.org; dmarc=pass (p=NONE sp=QUARANTINE dis=NONE) header.from=gmail.com Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S231350AbiJTL3N (ORCPT + 64 others); Thu, 20 Oct 2022 07:29:13 -0400 Received: from lindbergh.monkeyblade.net ([23.128.96.19]:46544 "EHLO lindbergh.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S231347AbiJTL3L (ORCPT ); Thu, 20 Oct 2022 07:29:11 -0400 Received: from mail-qk1-x72a.google.com (mail-qk1-x72a.google.com [IPv6:2607:f8b0:4864:20::72a]) by lindbergh.monkeyblade.net (Postfix) with ESMTPS id 2630211CB68 for ; Thu, 20 Oct 2022 04:29:10 -0700 (PDT) Received: by mail-qk1-x72a.google.com with SMTP id t25so12543007qkm.2 for ; Thu, 20 Oct 2022 04:29:10 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20210112; h=content-transfer-encoding:in-reply-to:from:references:cc:to :content-language:subject:user-agent:mime-version:date:message-id :from:to:cc:subject:date:message-id:reply-to; bh=90wiFngH1+zfXrSTTOx8+fdGzM6IhOrpFDU4dB9LYfU=; b=S5PC/bn5n9QDNPOQQlCu4/szd2WD1GwdrzV+nmHBkoT5XV/PicvlUy+egD5O+9PKd1 ycxPeS0DUlOl4/FMi4wndekMAjXboJFXRfeXo9BgqvUa7NGvbPuE/fIPkU7msH8pyq4s tD/7gj+mtQS8rfJeHLbiqmeZ8YRhoqOvtj6T1WM+mWZuOdKC/LJilD44L4FelLT5J9oM Ze/WjdUEw9c+ZDLcm4Jjf2NKDTNXYp2YUkYrefjmVF/6R04adFyGTeCq3B1dmFsAs1gG YbjwIUewlpAhszdbpXiPiHORRUAPF8V9ItYvcoMuuA+Os8xBvY8V7S0rkQNLWzwPWZti h/+g== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20210112; h=content-transfer-encoding:in-reply-to:from:references:cc:to :content-language:subject:user-agent:mime-version:date:message-id :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to; bh=90wiFngH1+zfXrSTTOx8+fdGzM6IhOrpFDU4dB9LYfU=; b=X8FjFTETNADpmBndZWKYo7cQ6+MExVYe6SHRIZPZYLEfLR+BNUK72VLLLnTVTlrQib us321zuTN/goRNjyWs2Nbu8KQphjwHl0Gy5lmf9INo5Hpxos+bICJGls4S3Biuw5++79 3/csFsffS1quTe4URo4cLa+FzgzjrafqBndSH+5VFfkml6M3UkA1aKceixbKFOGLpRBP Rki9iVwuHFUyIOnx2lkT7ebdJx9uZTILiodB8+GRT1IfTF7U0mw+p6RYf8q5EVtEWXxQ rIM0twYnWXlu83wz0WMpYD0cN0Kulzni4EJrv1mFyP1mvHiQLKv0iGJvKfg+WnF0Vb2H 9N4A== X-Gm-Message-State: ACrzQf2y6yRUkAUIo8OtoN07pIMpYhnhTEcNfK/15/iEA1i2zahUsIy8 FrTJkpY5XLnTaJwgYoLsjAQ= X-Received: by 2002:a05:620a:2699:b0:6cf:3ee4:5657 with SMTP id c25-20020a05620a269900b006cf3ee45657mr8621558qkp.475.1666265349220; Thu, 20 Oct 2022 04:29:09 -0700 (PDT) Received: from [10.176.68.61] ([192.19.148.250]) by smtp.gmail.com with ESMTPSA id j5-20020ac874c5000000b0039ccd7a0e10sm5766830qtr.62.2022.10.20.04.29.07 (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Thu, 20 Oct 2022 04:29:08 -0700 (PDT) Message-ID: <1cbd1d8e-8dc5-052b-118a-0c546d5edad6@gmail.com> Date: Thu, 20 Oct 2022 13:29:06 +0200 MIME-Version: 1.0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:91.0) Gecko/20100101 Thunderbird/91.13.1 Subject: Re: [PATCH v2] brcmfmac: Fixes potential buffer overflow in 'brcmf_fweh_event_worker' Content-Language: en-US To: Dokyung Song , linux-wireless@vger.kernel.org, Kalle Valo Cc: Jisoo Jang , Minsuk Kang References: <20221020104954.GA461052@laguna> From: Arend Van Spriel In-Reply-To: <20221020104954.GA461052@laguna> Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: 7bit X-Spam-Status: No, score=-2.1 required=5.0 tests=BAYES_00,DKIM_SIGNED, DKIM_VALID,DKIM_VALID_AU,DKIM_VALID_EF,FREEMAIL_FROM,NICE_REPLY_A, RCVD_IN_DNSWL_NONE,SPF_HELO_NONE,SPF_PASS autolearn=ham autolearn_force=no version=3.4.6 X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on lindbergh.monkeyblade.net Precedence: bulk List-ID: X-Mailing-List: linux-wireless@vger.kernel.org + Kalle On 10/20/2022 12:49 PM, Dokyung Song wrote: > This patch fixes an intra-object buffer overflow in brcmfmac that occurs > when the device provides a 'bsscfgidx' equal to or greater than the > buffer size. The patch adds a check that leads to a safe failure if that > is the case. Thanks for the updated patch. The subject for all linux-wireless patches should begin with 'wifi:'. Sorry for noticing it not earlier. Maybe Kalle can correct it when applying the patch. Regards, Arend