[lvc-project] [PATCH] wifi: iwlwifi: mvm: fix potential out-of-bounds read in iwl_mvm_nd_match_info_handler()

Fedor Pchelkin pchelkin at ispras.ru
Fri Mar 27 23:24:59 MSK 2026


On Sat, 07. Feb 18:03, Alexey Velichayshiy wrote:
> The memcpy function assumes the dynamic array notif->matches is at least
> as large as the number of bytes to copy. Otherwise, results->matches may
> contain unwanted data. To guarantee safety, extend the validation in one
> of the checks to ensure sufficient packet length.
> 
> Found by Linux Verification Center (linuxtesting.org) with SVACE.
> 
> Signed-off-by: Alexey Velichayshiy <a.velichayshiy at ispras.ru>
> ---

Патчик то кстати приняли :)
https://git.kernel.org/pub/scm/linux/kernel/git/wireless/wireless.git/commit/?id=744fabc338e87b95c4d1ff7c95bc8c0f834c6d99

и даже навесили метку Cc: stable.  Confirmed Major вернуть что ли?



More information about the lvc-project mailing list