wifi: brcmfmac: Fix oops due to NULL pointer dereference in brcmf_sdiod_sglist_rw()
Published Dec 27, 2024
5.5
MEDIUMCVSS 3.1
EPSS 0.24%
Description
This patch fixes a NULL pointer dereference bug in brcmfmac that occurs when a high 'sd_sgentry_align' value applies (e.g. 512) and a lot of queued SKBs are sent from the pkt queue.
The problem is the number of entries in the pre-allocated sgtable, it is nents = max(rxglom_size, txglom_size) + max(rxglom_size, txglom_size) >> 4 + 1. Given the default [rt]xglom_size=32 it's actually 35 which is too small. Worst case, the pkt queue can end up with 64 SKBs. This occurs when a new SKB is added for each original SKB if tailroom isn't enough to hold tail_pad. At least one sg entry is needed for each SKB. So, eventually the "skb_queue_walk loop" in brcmf_sdiod_sglist_rw may run out of sg entries. This makes sg_next return NULL and this causes the oops.
The patch sets nents to max(rxglom_size, txglom_size) * 2 to be able handle the worst-case. Btw. this requires only 64-35=29 * 16 (or 20 if CONFIG_NEED_SG_DMA_LENGTH) = 464 additional bytes of memory.
Affected products
-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version
-
- Version 3.15StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<3.15
- Version 5.10.231StatusunaffectedConstraints<=5.10.*
- Version 5.15.174StatusunaffectedConstraints<=5.15.*
- Version 5.4.287StatusunaffectedConstraints<=5.4.*
- Version 6.1.120StatusunaffectedConstraints<=6.1.*
- Version 6.12.5StatusunaffectedConstraints<=6.12.*
- Version 6.13StatusunaffectedConstraints<=*
- Version 6.6.66StatusunaffectedConstraints<=6.6.*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Linux | Linux | unaffected |
| ||||||||||||||||||||||||||||||
| Linux | Linux | affected |
|
- < 5.4.287
- ≥ 5.5 · < 5.10.231
- ≥ 5.11 · < 5.15.174
- ≥ 5.16 · < 6.1.120
- ≥ 6.2 · < 6.6.66
- ≥ 6.7 · < 6.12.5
No data.
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Out of support scope
Red Hat Enterprise Linux 7
kernel-rt
Out of support scope
Red Hat Enterprise Linux 8
kernel
Out of support scope
Red Hat Enterprise Linux 8
kernel-rt
Out of support scope
Red Hat Enterprise Linux 9
kernel
Fix deferred
Red Hat Enterprise Linux 9
kernel-rt
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Out of support scope | n/a |
| Red Hat Enterprise Linux 8 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Out of support scope | n/a |
| Red Hat Enterprise Linux 9 | kernel | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (14)
- https://access.redhat.com/security/cve/CVE-2024-56593 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2334453 Issue Tracking
- https://git.kernel.org/stable/c/07c020c6d14d29e5a3ea4e4576b8ecf956a80834 Patch
- https://git.kernel.org/stable/c/342f87d263462c2670b77ea9a32074cab2ac6fa1 Patch
- https://git.kernel.org/stable/c/34941321b516bd7c6103bd01287d71a1804d19d3 Patch
- https://git.kernel.org/stable/c/67a25ea28f8ec1da8894f2f115d01d3becf67dc7 Patch
- https://git.kernel.org/stable/c/7522d7d745d13fbeff3350fe6aa56c8dae263571 Patch
- https://git.kernel.org/stable/c/857282b819cbaa0675aaab1e7542e2c0579f52d7 Patch
- https://git.kernel.org/stable/c/dfb3f9d3f602602de208da7bdcc0f6d5ee74af68 Patch
- https://lists.debian.org/debian-lts-announce/2025/03/msg00001.html
- https://lists.debian.org/debian-lts-announce/2025/03/msg00002.html
- https://lore.kernel.org/linux-cve-announce/2024122700-CVE-2024-56593-3974@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2024-56593
- https://www.cve.org/CVERecord?id=CVE-2024-56593
Change history (0)
No recorded changes yet.