[PATCH] wifi: ath11k: Reject short management RX frames

Jiale Yao yaojiale02 at 163.com
Sat Sep 26 04:40:37 PDT 2026


ath11k_pull_mgmt_rx_params_tlv() verifies that the firmware-reported frame
length fits in the WMI event, but does not ensure that it can hold an IEEE
802.11 management header. It then sets skb->len to that reported length.

ath11k_mgmt_rx_event() subsequently reads frame_control and other header
fields without another length check. A firmware event with a short buf_len
can therefore cause an out-of-bounds read.

Reject frames shorter than a three-address IEEE 802.11 header before
adjusting the skb to expose the frame.

Fixes: d5c65159f289 ("ath11k: driver for Qualcomm IEEE 802.11ax devices")
Signed-off-by: Jiale Yao <yaojiale02 at 163.com>
---
 drivers/net/wireless/ath/ath11k/wmi.c | 3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

diff --git a/drivers/net/wireless/ath/ath11k/wmi.c b/drivers/net/wireless/ath/ath11k/wmi.c
index bbca275a8289..02cd9764b6fc 100644
--- a/drivers/net/wireless/ath/ath11k/wmi.c
+++ b/drivers/net/wireless/ath/ath11k/wmi.c
@@ -5995,7 +5995,8 @@ static int ath11k_pull_mgmt_rx_params_tlv(struct ath11k_base *ab,
 	hdr->tsf_delta =  ev->tsf_delta;
 	memcpy(hdr->rssi_ctl, ev->rssi_ctl, sizeof(hdr->rssi_ctl));
 
-	if (skb->len < (frame - skb->data) + hdr->buf_len) {
+	if (hdr->buf_len < sizeof(struct ieee80211_hdr_3addr) ||
+	    skb->len < (frame - skb->data) + hdr->buf_len) {
 		ath11k_warn(ab, "invalid length in mgmt rx hdr ev");
 		return -EPROTO;
 	}
-- 
2.34.1




More information about the ath11k mailing list