Re: [PATCH wireless] wifi: brcmfmac: validate msgbuf flowring IDs before use

From: Arend van Spriel

Date: Sun Aug 02 2026 - 04:43:08 EST


On Thu, 23 Jul 2026 13:56:17 +0800, Can Peng <pengcan@xxxxxxxxxx> wrote:
> Firmware messages carry flow_ring_id values which brcmfmac converts
> to an internal flowid by subtracting
> BRCMF_H2D_MSGRING_FLOWRING_IDSTART. The resulting value is used as
> a bit index in txstatus_done_map and as an array index into
> msgbuf->flowrings and the flowring state.
>
> Validate the firmware supplied flow_ring_id before using it. This
> prevents flow_ring_id values below BRCMF_H2D_MSGRING_FLOWRING_IDSTART
> from underflowing and rejects values outside msgbuf->max_flowrings.
>
> In the tx status path, complete the packet with an error after
> removing a valid packet id so the skb is not leaked when the flow
> ring id is invalid.
>
> Fixes: 9a1bb60250d2 ("brcmfmac: Adding msgbuf protocol.")
> Cc: stable@xxxxxxxxxxxxxxx
> Signed-off-by: Can Peng <pengcan@xxxxxxxxxx>
> ---
> .../wireless/broadcom/brcm80211/brcmfmac/msgbuf.c | 46 +++++++++++++++++++---
> 1 file changed, 40 insertions(+), 6 deletions(-)

One nit: there is a double blank line between brcmf_msgbuf_get_flowid()
and brcmf_msgbuf_dequeue_work() in the resulting code. This comes from
the pre-existing double blank line that was between
brcmf_msgbuf_remove_flowring() and brcmf_msgbuf_dequeue_work() -- worth
cleaning up to a single blank line.

Minor enough that I will take care of it while applying if you do not
send a v2.

To be applied to wireless tree.

Acked-by: Arend van Spriel <arend.vanspriel@xxxxxxxxxxxx>

Regards,
Arend