Re: [PATCH v3 1/5] staging: rtl8723bs: fix heap buffer overflow in recvframe_defrag()
From: Luka Gejak
Date: Wed Apr 15 2026 - 09:57:27 EST
On Sun Apr 5, 2026 at 12:15 PM CEST, Delene Tchio Romuald wrote:
> In recvframe_defrag(), a memcpy() copies fragment data into the
> reassembly buffer before recvframe_put() validates that the buffer
> has sufficient space. If the total reassembled payload exceeds the
> receive buffer capacity, this results in a heap buffer overflow.
>
> An attacker within WiFi radio range can exploit this by sending
> crafted 802.11 fragmented frames. No authentication is required.
>
> Add a bounds check before the memcpy() to verify that the fragment
> payload fits within the remaining buffer space, using the same error
> handling pattern already present in the function.
>
> Found by reviewing memory operations in the driver and tracing
> buffer pointer manipulation through rtw_recv.h inline helpers.
> Not tested on hardware.
>
> Signed-off-by: Delene Tchio Romuald <delenetchior1@xxxxxxxxx>
> ---
> v3:
> - Rebased on staging-next
> - Sent as numbered series with proper Cc from get_maintainer.pl
> v2:
> - Rebased on staging-next (v1 was based on v7.0-rc6 and did not apply)
> - Removed Cc: stable (will be added by maintainer)
>
> drivers/staging/rtl8723bs/core/rtw_recv.c | 8 +++++++-
> 1 file changed, 7 insertions(+), 1 deletion(-)
>
> diff --git a/drivers/staging/rtl8723bs/core/rtw_recv.c b/drivers/staging/rtl8723bs/core/rtw_recv.c
> index f78194d508dfc..717e0594d983a 100644
> --- a/drivers/staging/rtl8723bs/core/rtw_recv.c
> +++ b/drivers/staging/rtl8723bs/core/rtw_recv.c
> @@ -1132,7 +1132,13 @@ static union recv_frame *recvframe_defrag(struct adapter *adapter,
> /* append to first fragment frame's tail (if privacy frame, pull the ICV) */
> recvframe_pull_tail(prframe, pfhdr->attrib.icv_len);
>
> - /* memcpy */
> + /* Verify the receiving buffer has enough space for the fragment */
> + if (pnfhdr->len > (uint)(pfhdr->rx_end - pfhdr->rx_tail)) {
> + rtw_free_recvframe(prframe, pfree_recv_queue);
> + rtw_free_recvframe_queue(defrag_q, pfree_recv_queue);
> + return NULL;
> + }
> +
> memcpy(pfhdr->rx_tail, pnfhdr->rx_data, pnfhdr->len);
>
> recvframe_put(prframe, pnfhdr->len);
LGTM.
Reviewed-by: Luka Gejak <luka.gejak@xxxxxxxxx>
Best regards,
Luka Gejak