[PATCH] wifi: cfg80211: validate WEXT station BSSID

From: Eduard Zateev

Date: Wed Oct 07 2026 - 10:35:46 EST


WEXT IBSS and managed mode store the BSSID in the same
wdev->wext.bssid buffer. cfg80211_ibss_wext_siwap() keeps a pointer to
that buffer in wext.ibss.bssid. After changing to station mode,
cfg80211_mgd_wext_siwap() accepts a multicast AP address and copies it
to the buffer. Switching back to IBSS then follows that pointer and
uses the multicast address as a fixed BSSID.

mac80211 can create a beacon with that address, but cfg80211_get_bss()
rejects it, causing WARN_ON(!bss) in cfg80211_ibss_joined() after the
join has been reported.

Reject invalid station BSSIDs before copying them. A mac80211_hwsim WEXT
ioctl test reproduces the reported BSSID and warning; the original
syzbot report has no reproducer.

Reported-by: syzbot+d0a52209bddfa0948065@xxxxxxxxxxxxxxxxxxxxxxxxx
Link: https://syzkaller.appspot.com/bug?extid=d0a52209bddfa0948065
Signed-off-by: Eduard Zateev <hackerowskiy@xxxxxxxxx>
---
net/wireless/wext-sme.c | 3 +++
1 file changed, 3 insertions(+)

diff --git a/net/wireless/wext-sme.c b/net/wireless/wext-sme.c
index b5914f3658db..3db73a0765c9 100644
--- a/net/wireless/wext-sme.c
+++ b/net/wireless/wext-sme.c
@@ -245,6 +245,9 @@ int cfg80211_mgd_wext_siwap(struct net_device *dev,
if (is_zero_ether_addr(bssid) || is_broadcast_ether_addr(bssid))
bssid = NULL;

+ if (bssid && !is_valid_ether_addr(bssid))
+ return -EINVAL;
+
if (wdev->conn) {
/* both automatic */
if (!bssid && !wdev->wext.connect.bssid)
--
2.55.0