]> exis.tech > repos - linux.git/commitdiff
wifi: mac80211_hwsim: clamp virtio RX length before skb_put
authorBryam Vargas <hexlabsecurity@proton.me>
Sun, 21 Jun 2026 02:45:18 +0000 (21:45 -0500)
committerJohannes Berg <johannes.berg@intel.com>
Mon, 6 Jul 2026 12:11:06 +0000 (14:11 +0200)
hwsim_virtio_rx_work() passes the virtqueue used-ring length reported by
the device straight to skb_put() on a fixed-size receive skb. A backend
reporting a length larger than the skb tailroom drives skb_put() past the
buffer end and hits skb_over_panic() -- a host-triggerable guest panic
(denial of service).

Clamp the length to the skb's available room before skb_put(). A
conforming device never reports more than the posted buffer size, so valid
frames are unaffected; a truncated over-report then fails the
length/header checks in hwsim_virtio_handle_cmd() and is dropped, so
truncating rather than dropping here cannot be turned into a parsing
problem.

Fixes: 5d44fe7c9808 ("mac80211_hwsim: add frame transmission support over virtio")
Signed-off-by: Bryam Vargas <hexlabsecurity@proton.me>
Link: https://patch.msgid.link/20260620-b4-disp-474bee37-v1-1-1a4d37f3e2d4@proton.me
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
drivers/net/wireless/virtual/mac80211_hwsim_main.c

index 0dd8a6c85953446c45cfeb6b23ac05fc837009ca..5c17182775990c2441beda7a77ec97761b5d2adf 100644 (file)
@@ -7289,6 +7289,7 @@ static void hwsim_virtio_rx_work(struct work_struct *work)
 
        skb->data = skb->head;
        skb_reset_tail_pointer(skb);
+       len = min(len, skb_end_offset(skb));
        skb_put(skb, len);
        hwsim_virtio_handle_cmd(skb);