[PATCH v3] staging: rtl8723bs: fix ie_length bound check in rtw_cfg80211_inform_bss

From: Adi Prasan

Date: Fri Oct 02 2026 - 10:10:38 EST


The buffer bound check in rtw_cfg80211_inform_bss() checked bssinf_len
(ie_length + header size) against MAX_BSSINFO_LEN (1000 bytes), but
network.ies[] is only MAX_IE_SZ (768) bytes. This allowed ie_length
values up to ~976 bytes to pass the check while a subsequent memcpy()
from network.ies still only has 768 valid bytes, and other paths that
write to network.ies consistently cap ie_length to MAX_IE_SZ.

Check ie_length against MAX_IE_SZ directly, which is the actual size
of network.ies, and drop the now-unused bssinf_len/MAX_BSSINFO_LEN
comparison.

Signed-off-by: Adi Prasan <itsadi2409@xxxxxxxxx>
Fixes: 554c0a3abf216 ("staging: Add rtl8723bs sdio wifi driver")
---
drivers/staging/rtl8723bs/os_dep/ioctl_cfg80211.c | 5 ++---
1 file changed, 2 insertions(+), 3 deletions(-)

diff --git a/drivers/staging/rtl8723bs/os_dep/ioctl_cfg80211.c b/drivers/staging/rtl8723bs/os_dep/ioctl_cfg80211.c
index 27e7b8442d7b..7e964b15ae6d 100644
--- a/drivers/staging/rtl8723bs/os_dep/ioctl_cfg80211.c
+++ b/drivers/staging/rtl8723bs/os_dep/ioctl_cfg80211.c
@@ -210,7 +210,7 @@ struct cfg80211_bss *rtw_cfg80211_inform_bss(struct adapter *padapter, struct wl
u64 notify_timestamp;
s32 notify_signal;
u8 *buf = NULL, *pbuf;
- size_t len, bssinf_len = 0;
+ size_t len;
struct ieee80211_hdr *pwlanhdr;
__le16 *fctrl;

@@ -218,8 +218,7 @@ struct cfg80211_bss *rtw_cfg80211_inform_bss(struct adapter *padapter, struct wl
struct wiphy *wiphy = wdev->wiphy;
struct mlme_priv *pmlmepriv = &(padapter->mlmepriv);

- bssinf_len = pnetwork->network.ie_length + sizeof(struct ieee80211_hdr_3addr);
- if (bssinf_len > MAX_BSSINFO_LEN || pnetwork->network.ie_length > MAX_IE_SZ)
+ if (pnetwork->network.ie_length > MAX_IE_SZ)
goto exit;

{
--
2.43.0