Received: by 2002:a05:6358:3188:b0:123:57c1:9b43 with SMTP id q8csp1276818rwd; Thu, 25 May 2023 10:14:15 -0700 (PDT) X-Google-Smtp-Source: ACHHUZ56zdUjptQ1Y8fae9FiP/m//ZDu5TFErdk3jVCef93BWmn61tFkNRrqRITNXZYgO7MUSoSB X-Received: by 2002:a17:90b:1291:b0:255:f397:448d with SMTP id fw17-20020a17090b129100b00255f397448dmr2688069pjb.25.1685034855194; Thu, 25 May 2023 10:14:15 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1685034855; cv=none; d=google.com; s=arc-20160816; b=0cuqGyTQpIiprdgxraTlFNyRSeT6K+kUWMaVVbThNqurEsqkxklEnKGJpKGxaexHeN +S/KTpf0wPf50KMsaEvUfKvpIvKzwUxvJ+pswDZ2u0GI7afvMIlDWd56NWzBMUMfNnzR thi7uOzuJjjTAmuBUZkTO2fFLIu+zelErlTUpt++j/WrkzXxQWrOlczPTahKvUG9Vd4h 38hCE3bNZaypViFM6oejRk4u/E0OqguN6l+2czDeQaFavO9Oj2XgR3B2B4TE5OuwgwKY BL6rzFlr5wrENpfQzfHAvC2jkcjdnBWXVKl9Vol5Krc1/mAG0qDlXNIYDwUUcN6axW8Y faYw== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:date:message-id:user-agent:cc:to:references :in-reply-to:from:subject:content-transfer-encoding:mime-version :dkim-signature; bh=66fngy8dWzDrsg5bLx7jARgb+8a16HrxSNqWDvSnQO0=; b=rJB9E5PiOEzrnBtKABWc3iuh59A4Jkbsm+OqccL/fPjUjQq2+BbUSU+Q01bbzTytjH CYMExM4PDdO+cEyI+gI7OAy9MV3UB3YyxFjibwMBOSX7GGZtCE1iBsTZTFWtqiz1UUqI XQQDBc6GkcyLFndwIws//Fw5dzQN9W2Q0JKcMoR521xxwA4bel6dWlABrwDpT63pxUnb Qp+wmOt426QBu7a+gvjhksPlmiJq7+6PG0bLgCIr01ggL1imW0DUxazvb2uN6kimUaPC qQsSuyEgd3oQmj0wG2G2XX+xF0YGHIXeM0CBGNDQhxVDVC0g6/3BLfq1xco4kGd25IEs 25bA== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@kernel.org header.s=k20201202 header.b=pio0Er+l; spf=pass (google.com: domain of linux-wireless-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) smtp.mailfrom=linux-wireless-owner@vger.kernel.org; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=kernel.org Return-Path: Received: from out1.vger.email (out1.vger.email. [2620:137:e000::1:20]) by mx.google.com with ESMTP id u75-20020a63794e000000b0053f26bf15ccsi1484994pgc.82.2023.05.25.10.14.07; Thu, 25 May 2023 10:14:15 -0700 (PDT) Received-SPF: pass (google.com: domain of linux-wireless-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) client-ip=2620:137:e000::1:20; Authentication-Results: mx.google.com; dkim=pass header.i=@kernel.org header.s=k20201202 header.b=pio0Er+l; spf=pass (google.com: domain of linux-wireless-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) smtp.mailfrom=linux-wireless-owner@vger.kernel.org; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=kernel.org Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S240206AbjEYRE4 (ORCPT + 62 others); Thu, 25 May 2023 13:04:56 -0400 Received: from lindbergh.monkeyblade.net ([23.128.96.19]:57146 "EHLO lindbergh.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S231964AbjEYREz (ORCPT ); Thu, 25 May 2023 13:04:55 -0400 Received: from dfw.source.kernel.org (dfw.source.kernel.org [139.178.84.217]) by lindbergh.monkeyblade.net (Postfix) with ESMTPS id 28702189; Thu, 25 May 2023 10:04:54 -0700 (PDT) Received: from smtp.kernel.org (relay.kernel.org [52.25.139.140]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by dfw.source.kernel.org (Postfix) with ESMTPS id B8C51647B1; Thu, 25 May 2023 17:04:53 +0000 (UTC) Received: by smtp.kernel.org (Postfix) with ESMTPSA id 3BB65C433D2; Thu, 25 May 2023 17:04:50 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kernel.org; s=k20201202; t=1685034293; bh=gBgpG9vTwOaMKv/+/eY1oC9MAIfEaLOfyfZw8B7xYrs=; h=Subject:From:In-Reply-To:References:To:Cc:Date:From; b=pio0Er+luZrzNM1SJ2AttAghtZM4LVeBGEhQJeM8Btg85aqeZ7C0Uk0WtKDGG48Hh 3SvpKa7OJKD21AzpxfUrxY0K6PiIbpIG2Cd1EidA3FOwdiYMtDsgP8c3SnaoTyDCDL Oth+XHrdB2RPFdHB9gRJXFxYMD8tTQsG6iL+PvNWZrcwn22p4nktAuZOzgSkPimdPP huP2sDOiV5QXSqeEwmdAHnJEqY6wOR4r41JG04UUpZQGMabslLkYHOfui+rP+xmMF1 vmSqg+dYqpgXHSHm4Abtsp/KplIC8kVbOGMHywkQCNCCSvMycqmrifBux7tTi59mFm oYEmkyuR07H3g== Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 8bit Subject: Re: [PATCH v2] wifi: ath9k: don't allow to overwrite ENDPOINT0 attributes From: Kalle Valo In-Reply-To: <20230516150427.79469-1-pchelkin@ispras.ru> References: <20230516150427.79469-1-pchelkin@ispras.ru> To: Fedor Pchelkin Cc: =?utf-8?q?Toke_H=C3=B8iland-J=C3=B8rgensen?= , Fedor Pchelkin , "David S. Miller" , Eric Dumazet , Jakub Kicinski , Paolo Abeni , linux-wireless@vger.kernel.org, netdev@vger.kernel.org, linux-kernel@vger.kernel.org, Takeshi Misawa , Alexey Khoroshilov , lvc-project@linuxtesting.org, syzbot+b68fbebe56d8362907e8@syzkaller.appspotmail.com User-Agent: pwcli/0.1.1-git (https://github.com/kvalo/pwcli/) Python/3.7.3 Message-ID: <168503428836.19957.620283860814904448.kvalo@kernel.org> Date: Thu, 25 May 2023 17:04:50 +0000 (UTC) X-Spam-Status: No, score=-7.1 required=5.0 tests=BAYES_00,DKIMWL_WL_HIGH, DKIM_SIGNED,DKIM_VALID,DKIM_VALID_AU,DKIM_VALID_EF,RCVD_IN_DNSWL_HI, SPF_HELO_NONE,SPF_PASS,T_SCC_BODY_TEXT_LINE autolearn=ham autolearn_force=no version=3.4.6 X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on lindbergh.monkeyblade.net Precedence: bulk List-ID: X-Mailing-List: linux-wireless@vger.kernel.org Fedor Pchelkin wrote: > A bad USB device is able to construct a service connection response > message with target endpoint being ENDPOINT0 which is reserved for > HTC_CTRL_RSVD_SVC and should not be modified to be used for any other > services. > > Reject such service connection responses. > > Found by Linux Verification Center (linuxtesting.org) with Syzkaller. > > Fixes: fb9987d0f748 ("ath9k_htc: Support for AR9271 chipset.") > Reported-by: syzbot+b68fbebe56d8362907e8@syzkaller.appspotmail.com > Signed-off-by: Fedor Pchelkin > Acked-by: Toke Høiland-Jørgensen > Signed-off-by: Kalle Valo Patch applied to ath-next branch of ath.git, thanks. 061b0cb9327b wifi: ath9k: don't allow to overwrite ENDPOINT0 attributes -- https://patchwork.kernel.org/project/linux-wireless/patch/20230516150427.79469-1-pchelkin@ispras.ru/ https://wireless.wiki.kernel.org/en/developers/documentation/submittingpatches