[PATCH 5.15] wifi: wcn36xx: fix heap overflow from oversized firmware HAL response
From: Roman Demidov
Date: Fri Sep 18 2026 - 11:05:47 EST
From: Tristan Madani <tristan@xxxxxxxxxxxxxxxxxxx>
commit 88a240d86d3d64521f9194abe185ac71cc74d0bd upstream.
The firmware response dispatcher copies all synchronous HAL responses
into the 4096-byte hal_buf without validating the response length. A
response exceeding WCN36XX_HAL_BUF_SIZE causes a heap buffer overflow
with firmware-controlled content.
Add a bounds check on the response length.
Fixes: 8e84c2582169 ("wcn36xx: mac80211 driver for Qualcomm WCN3660/WCN3680 hardware")
Signed-off-by: Tristan Madani <tristan@xxxxxxxxxxxxxxxxxxx>
Reviewed-by: Loic Poulain <loic.poulain@xxxxxxxxxxxxxxxx>
Link: https://patch.msgid.link/20260421135018.352774-2-tristmd@xxxxxxxxx
Signed-off-by: Jeff Johnson <jeff.johnson@xxxxxxxxxxxxxxxx>
Signed-off-by: Sasha Levin <sashal@xxxxxxxxxx>
Signed-off-by: Roman Demidov <roman.demidov.nn@xxxxxxxxx>
---
Backport fix for CVE-2026-74341
drivers/net/wireless/ath/wcn36xx/smd.c | 4 ++++
1 file changed, 4 insertions(+)
diff --git a/drivers/net/wireless/ath/wcn36xx/smd.c b/drivers/net/wireless/ath/wcn36xx/smd.c
index a778e3e0599e..6ab91ff8338c 100644
--- a/drivers/net/wireless/ath/wcn36xx/smd.c
+++ b/drivers/net/wireless/ath/wcn36xx/smd.c
@@ -3174,6 +3174,10 @@ int wcn36xx_smd_rsp_process(struct rpmsg_device *rpdev,
case WCN36XX_HAL_GTK_OFFLOAD_GETINFO_RSP:
case WCN36XX_HAL_HOST_RESUME_RSP:
case WCN36XX_HAL_UPDATE_CHANNEL_LIST_RSP:
+ if (len > WCN36XX_HAL_BUF_SIZE) {
+ wcn36xx_warn("HAL response too large: %d\n", len);
+ break;
+ }
memcpy(wcn->hal_buf, buf, len);
wcn->hal_rsp_len = len;
complete(&wcn->hal_rsp_compl);
--
2.53.0