summaryrefslogtreecommitdiff
path: root/net/mac80211
AgeCommit message (Collapse)Author
11 hoursMerge branch 'main' of ↵Mark Brown
https://git.kernel.org/pub/scm/linux/kernel/git/netdev/net-next.git # Conflicts: # drivers/net/ethernet/realtek/r8169_main.c # net/mac80211/ieee80211_i.h # net/mac80211/tx.c
15 hoursMerge tag 'nf-26-09-30' of ↵Paolo Abeni
git://git.kernel.org/pub/scm/linux/kernel/git/netfilter/nf Pablo Neira Ayuso says: ==================== Netfilter/IPVS fixes for net The following batch contains Netfilter fixes for net. This batch fixes crashes as recent feature regression, one of the due to a dependency that has been pulled into -stable: 1) Expand existing ipset fix for bitmap sets to disallow comments updates from kernel-side adds, from Florian Westphal. 2) Drop flowtable reference if nf_ct_netns_get() fails, otherwise flowtable cannot ever be removed, from Aohan Mei. 3) nft_rbtree GC should collect end elements that contained in this transaction batch, new or deleted elements are never expired. From Weiming Shi. 4) Restrict nf_nat_bpf so it does not set unknown NF_NAT_MANIP_* values, from Fernando F. Mancera. 5) Flowtable GC must skip flows that are pending hardware updates, generalize the PENDING flag and use it to inhibit GC. 6) Restore flowtable with ieee80211 which broke due to a relatively recent commit, which was pulled in by -stable, causing a regression in 6.18 kernels. And the following IPVS fixes: 1) Fix accounting of cache entries in IPVS LBLC for destinations, which eventually fills up the table and trigger recurrent resizing, from Julian Anastasov. 2) Limit IPVS cache growth for LBLCR and LBLC schedulers, from Zhiling Zou. 3) Restrict IP_VS_CONN_F_ONE_PACKET for normal connections, do not allow to use it with templates. Also from Julian. 4) Sanitize flags in IPVS sync messages received in the backup. From Julian Anastasov. netfilter pull request 26-09-30 * tag 'nf-26-09-30' of git://git.kernel.org/pub/scm/linux/kernel/git/netfilter/nf: netfilter: flowtable: restore ieee80211 forward path netfilter: flowtable: generalize pending status bit netfilter: bpf: reject invalid NAT manipulation types netfilter: nft_set_rbtree: skip transaction elements during GC ipvs: filter some flags received in the backup server ipvs: do not create invisible templates ipvs: bound LBLCR and LBLC cache growth ipvs: fix missing counter decrement in lblc netfilter: nft_flow_offload: drop flowtable reference on init error path netfilter: ipset: do not update comments from kernel-side adds ==================== Link: https://patch.msgid.link/20260930074142.298353-1-pablo@netfilter.org Signed-off-by: Paolo Abeni <pabeni@redhat.com>
41 hoursnetfilter: flowtable: restore ieee80211 forward pathPablo Neira Ayuso
Before commit 871df5007eda ("netfilter: flowtable: bail out if forward path cannot be discovered"), there was a fallback to set up a forward path in case .ndo_fill_forward_path fails or DEV_PATH_MTK_WDMA was used. Such fallback was used by commit d787a3e38f01 ("mac80211: add support for .ndo_fill_forward_path"). One possibility is to handle DEV_PATH_MTK_WDMA from the flowtable forward path discovery. However, this is only used internally by drivers to retrieve mtk_wdma information to set up hardware offload. Felix decided to use the .fill_forward_path interface for this purpose due to the lack of a better interface at that time. Add a new DEV_PATH_IEEE80211 path which is offered if the new ieee80211 flag is set on in the struct net_device_path_ctx to restore the flowtable with a ieee80211 netdevice. Handle this new DEV_PATH_IEEE80211 path just like DEV_PATH_ETHERNET and DEV_PATH_DSA, ie. this is the last netdevice in the stack. This new ieee80211 flag is implicitly unset for mtk_ppe and airoha which call dev_fill_forward_path() to retrieve a DEV_PATH_MTK_WDMA path. Fixes: 871df5007eda ("netfilter: flowtable: bail out if forward path cannot be discovered") Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
4 dayswifi: mac80211: Gracefully deauthenticate on association timeoutIlan Peer
When an association with AP times out, and the connection is an Enhanced Privacy Protection (EPP) connection where the TK is already installed, send an explicit deauthentication frame to the AP so it would clear its local state. Not doing so might impact (fail) future connection attempts with this AP (that might think that the station is still connected). This cannot be done by user space, since as part of the association timeout flow, the station and corresponding keys are removed. Assisted-by: GithubCopilot:claude-opus-5.0 Signed-off-by: Ilan Peer <ilan.peer@intel.com> Reviewed-by: Johannes Berg <johannes.berg@intel.com> Signed-off-by: Miri Korenblit <miriam.rachel.korenblit@intel.com> Link: https://patch.msgid.link/20260926212249.736b01b4a76d.Ie528ea57d4d8dc8abfca406f8bae55a3902ff740@changeid Signed-off-by: Johannes Berg <johannes.berg@intel.com>
4 dayswifi: mac80211: start next ROC after purging an interfaceRuide Cao
When an interface owning the active hardware ROC is purged, a ROC queued for another interface can become the head of roc_list without being started. Subsequent requests only append to the non-empty list, so no driver work is scheduled and the entries are never freed. Flush pending ROC start work and cancel pending completion work before handing the remaining queue to the normal next-ROC path. This preserves the existing software ROC handling and avoids stale workers operating on the newly started ROC. Reported-by: Vega <vega@nebusec.ai> Assisted-by: LLM Signed-off-by: Ruide Cao <caoruide123@gmail.com> Signed-off-by: Ren Wei <weir@nebusec.ai> Link: https://patch.msgid.link/6975ce9d8e9a153e8319d10e6e7c7be004d6df88.1787220252.git.vega.cover-letter@nebusec.ai Signed-off-by: Johannes Berg <johannes.berg@intel.com>
4 dayswifi: mac80211: fix potential ack-skb leak on error pathJohannes Berg
In case this warning hits, which shouldn't but could at least due to an unrelated mesh bug, an ack SKB will not be freed correctly if present. Fix that. Reported-by: syzbot+ac648b0525be1feba506@syzkaller.appspotmail.com Link: https://patch.msgid.link/20260922144845.729cf61a017b.Iabf0248920a1e70c9f6f321fbf163fc10e5f0884@changeid Signed-off-by: Johannes Berg <johannes.berg@intel.com>
4 dayswifi: mac80211: mesh: don't send peering close in listenJohannes Berg
In listen state, nothing has been sent, so there's no need to send a WLAN_SP_MESH_PEERING_CLOSE frame. Also, in case the station just failed to insert, e.g. due to a missing channel context, it might not be possible to transmit the frame at all, leading to a warning. Reported-by: syzbot+8bd4574e8c52c48c2595@syzkaller.appspotmail.com Link: https://patch.msgid.link/20260922144838.b1b35f44b069.I80ab9ad25eb48d291807ca968fcba6b64d8fb6ab@changeid Signed-off-by: Johannes Berg <johannes.berg@intel.com>
4 dayswifi: mac80211: Restrict probe request rates for minimal contentIlan Peer
When IEEE80211_PROBE_FLAG_MIN_CONTENT is set, restrict the probe request supported rates per Draft P802.11bi D5.0 specification: - 2 GHz: only include 1, 2, 5.5, 6, 11, 12, 24 Mb/s - 5/6 GHz: only include 6, 12, 24 Mb/s Also skip the Extended Supported Rates element for minimal content probes. Signed-off-by: Ilan Peer <ilan.peer@intel.com> Assisted-by: GitHub-Copilot:claude-opus-4-6 Signed-off-by: Miri Korenblit <miriam.rachel.korenblit@intel.com> Link: https://patch.msgid.link/20260922143146.13a6fab60516.I3ebb1fa5d41622b1a0ddf9d008328fc19ad980a1@changeid [drop strange comment about extended element] Signed-off-by: Johannes Berg <johannes.berg@intel.com>
4 dayswifi: mac80211: Fix a race when expiring a mesh pathGinger Li
My static analyzer identified a potential issue in 'net/mac80211/mesh_pathtbl.c': mpath_expired() reads mpath->flags and mpath->exp_time without holding mpath->state_lock, while mesh_path_fix_nexthop() and the other writers update both fields under that lock. In mpath_lookup() and __mesh_path_lookup_by_idx() the unlocked check is followed by taking the lock and clearing MESH_PATH_ACTIVE, so the check and the update are not atomic: CPU0 (mpath_lookup) CPU1 (mesh_path_fix_nexthop) mpath_expired() reads the stale flags/exp_time and returns true spin_lock_bh(&mpath->state_lock) mpath->exp_time = 0; mpath->flags = FIXED|SN_VALID; mesh_path_activate(mpath); spin_unlock_bh(&mpath->state_lock) spin_lock_bh(&mpath->state_lock) mpath->flags &= ~MESH_PATH_ACTIVE; spin_unlock_bh(&mpath->state_lock) A path which mesh_path_fix_nexthop() has just set up as MESH_PATH_FIXED and MESH_PATH_ACTIVE then has MESH_PATH_ACTIVE cleared again, and forwarding to that destination silently stops. Take mpath->state_lock before evaluating mpath_expired() so that the check and the clearing of MESH_PATH_ACTIVE are atomic with respect to the writers. Fixes: 60854fd94573 ("mac80211: mesh: convert path table to rhashtable") Signed-off-by: Ginger Li <ginger.jzllee@gmail.com> Link: https://patch.msgid.link/20260922054253.11976-1-ginger.jzllee@gmail.com Signed-off-by: Johannes Berg <johannes.berg@intel.com>
4 dayswifi: mac80211: implement NAN non-evacuable channelsAndrei Otcheretianski
Implement the nan_set_non_evac_channels operation in mac80211. It marks the provided channels as non-evacuable in the current local schedule and clears the flag on all other channels. All provided channels must exist in the current schedule, otherwise -ENOENT is returned. ieee80211_nan_find_evac_chan() skips channels marked as non-evacuable when selecting a channel to evacuate for concurrent operations. Fixes: 42c9de58d990 ("wifi: mac80211: add NAN channel evacuation support") Signed-off-by: Andrei Otcheretianski <andrei.otcheretianski@intel.com> Reviewed-by: Johannes Berg <johannes.berg@intel.com> Signed-off-by: Miri Korenblit <miriam.rachel.korenblit@intel.com> Link: https://patch.msgid.link/20260921215936.ef5884349253.I38b685378c3557679ed6387922a94a7da821555c@changeid Signed-off-by: Johannes Berg <johannes.berg@intel.com>
4 dayswifi: mac80211: add Control Integrity Protocol handlingBenjamin Berg
Add the handling of CIP during association, when adding a station in AP mode and also add some checks whether the keys are being installed correctly. For internal use, add a new key flag CIP that is used for both the pairwise key and CIGTK. The CIGTK will then have the MCAST_KEY and CIP flags set. As the CIGTK uses key indices 0 and 1, add a new variable to track it separately from the other GTKs. Signed-off-by: Benjamin Berg <benjamin.berg@intel.com> Link: https://patch.msgid.link/20260921144048.f032c70e0bc2.I30cf9ae29629188b8674e2268a6b592c1a63128b@changeid Signed-off-by: Johannes Berg <johannes.berg@intel.com>
4 dayswifi: mac80211: add helpers to parse/generate CIP CapabilitiesBenjamin Berg
The Control Integrity Protocol (CIP) Capabilities need to be added to and parsed from the association request and response. Signed-off-by: Benjamin Berg <benjamin.berg@intel.com> Link: https://patch.msgid.link/20260921144048.a3249c0b78ad.Ia3ea929dd6381cf8b04e3dd0c38e709e335113c2@changeid Signed-off-by: Johannes Berg <johannes.berg@intel.com>
4 dayswifi: mac80211: add cigtk parameter to ieee80211_gtk_rekey_addBenjamin Berg
The CIGTK keys use a key index of 0 or 1, which is not unique. As such, a new parameter is needed to differentiate the key type. Add the parameter to prepare for handling the CIGTK in the future. Signed-off-by: Benjamin Berg <benjamin.berg@intel.com> Link: https://patch.msgid.link/20260921144048.8bfea7df6b06.I3d046fbe7dfb3883471773f84e7a791b5b97000e@changeid Signed-off-by: Johannes Berg <johannes.berg@intel.com>
4 dayswifi: cfg80211: add Control Integrity Protocol (CIP) APIsBenjamin Berg
The Control Integrity Protocol consists of a set of capabilities for the MIC padding as well as a new CIGTK that can be installed. The CIGTK uses a fixed GMAC-256 cipher for which no RSN extension is defined as it is bound to the pairwise cipher being GCMP-256. The CIGTK uses the key index 0 and 1, making it necessary to add a new key type for it. Add a new CIP feature flag and attributes for CIP Capabilities and enabling the feature for stations and the association. Also extend the cfg80211 API to pass the key type rather than a single pairwise boolean. Signed-off-by: Benjamin Berg <benjamin.berg@intel.com> Link: https://patch.msgid.link/20260921144048.aa7939493375.I49c0be0a1b05d625cc307e9bdd13c32a6c18667f@changeid Signed-off-by: Johannes Berg <johannes.berg@intel.com>
4 dayswifi: mac80211: add key link_id to debugfsBenjamin Berg
Add the link_id to the debugfs. This is useful for hwsim tests to validate the per-link keys in multi-link tests. Signed-off-by: Benjamin Berg <benjamin.berg@intel.com> Link: https://patch.msgid.link/20260921144048.fee6216d4a22.I262f6ee5af944970707e1d4e6607020fcfe6ba89@changeid Signed-off-by: Johannes Berg <johannes.berg@intel.com>
4 dayswifi: mac80211: add key flags to debugfsJohannes Berg
Since there are two sets of key flags, one for the driver and one internal to mac80211, add the first set in debugfs as well. This will be used by hwsim tests to determine if a key is pairwise or not, since the next changes will make mac80211 use only per-STA GTKs. Link: https://patch.msgid.link/20260921144048.641cb1492f2e.I3a7d6912def9ba2623b41cc672704cbe3beb0bf3@changeid Signed-off-by: Johannes Berg <johannes.berg@intel.com>
4 dayswifi: mac80211: fix slab-out-of-bounds read in ieee80211_monitor_select_queue()Cen Zhang (Microsoft)
ieee80211_monitor_select_queue() validates the skb length using skb->len before dereferencing pointers into skb->data to access the 802.11 header. However, skb->len includes data in both the linear head buffer and non-linear fragments/pages. When AF_PACKET sends a packet large enough to become non-linear, the 802.11 header at skb->data + len_rthdr may extend past the linear head buffer even though skb->len appears sufficient. This leads to a slab-out-of-bounds read when accessing hdr->frame_control, as the kernel reads beyond the allocated skb head buffer: BUG: KASAN: slab-out-of-bounds in ieee80211_monitor_select_queue+0x1ed/0x220 syzbot has hit the same issues. Fix this by checking skb_headlen(skb) (which gives the length of the linear data region) instead of skb->len before dereferencing skb->data pointers. This ensures the required bytes are actually present in the linear portion of the skb. Apply the same fix to ieee80211_validate_radiotap_len() which has the same class of bug: it uses skb->len to validate accesses to skb->data, and to the corresponding checks in ieee80211_monitor_start_xmit(): for drivers advertising NETIF_F_SG the skb is not linearized before ndo_start_xmit, so the 802.11 header can be read past the linear buffer there as well. Fixes: cf0277e714a0 ("mac80211: fix skb buffering issue") Fixes: 9b8a74e3482f ("[MAC80211]: Improve sanity checks on injected packets") Reported-by: AutonomousCodeSecurity@microsoft.com Reported-by: syzbot+610e40369bc02181bad0@syzkaller.appspotmail.com Closes: https://syzkaller.appspot.com/bug?extid=610e40369bc02181bad0 Reported-by: syzbot+878643e0580bc580f883@syzkaller.appspotmail.com Closes: https://syzkaller.appspot.com/bug?extid=878643e0580bc580f883 Assisted-by: GitHub-Copilot:claude-opus-4.6 Signed-off-by: Cen Zhang (Microsoft) <cenzhang@linux.microsoft.com> Reviewed-by: Francis Perron <francis@akrites.dev> Link: https://patch.msgid.link/20260925024408.32143-1-cenzhang@linux.microsoft.com Signed-off-by: Johannes Berg <johannes.berg@intel.com>
4 dayswifi: mac80211: reject invalid 320 MHz CSA bandwidthRuide Cao
The HT/VHT channel definition validator can receive a 320 MHz bandwidth indication from a received CSA frame on a non-6 GHz link. It warns for this unsupported width but continues with an uninitialized vht_operation.chan_width, which is then read by ieee80211_chandef_vht_oper(). With panic_on_warn enabled, this lets a received frame panic the kernel. Reject the channel definition before entering the VHT operation conversion. This preserves the existing CSA fallback while avoiding both the warning and the uninitialized read. Fixes: 21c3f8f95554 ("wifi: mac80211: refactor STA CSA parsing flows") Cc: stable@vger.kernel.org Reported-by: Vega <vega@nebusec.ai> Assisted-by: LLM Signed-off-by: Ruide Cao <caoruide123@gmail.com> Signed-off-by: Ren Wei <weir@nebusec.ai> Link: https://patch.msgid.link/bd68e360e06135c750397cb6be003a01a834a179.1787222001.git.vega.cover-letter@nebusec.ai Signed-off-by: Johannes Berg <johannes.berg@intel.com>
4 dayswifi: mac80211: set info->band for 802.3 encap offload framesFelix Fietkau
Unlike the 802.11 TX paths, ieee80211_8023_xmit() does not set info->band from the channel context on non-MLD interfaces. It stays at 0, so ieee80211_get_tx_rates() uses the wrong band for these frames. Set it the same way as ieee80211_build_hdr(): drop the frame if there is no channel context, and leave the band at 0 on MLD interfaces. Reported-by: Andrea Pesaresi <andreapesaresi82@gmail.com> Fixes: 50ff477a8639 ("mac80211: add 802.11 encapsulation offloading support") Cc: stable@vger.kernel.org Signed-off-by: Felix Fietkau <nbd@nbd.name> Link: https://patch.msgid.link/20260926120216.4054712-1-nbd@nbd.name Signed-off-by: Johannes Berg <johannes.berg@intel.com>
10 dayswifi: mac80211: prevent AP VLAN tx from other interfacesFelix Fietkau
Since the station lookup was factored out of ieee80211_build_hdr(), ieee80211_lookup_ra_sta() uses sta_info_get_bss() for all AP and AP VLAN frames, not only for control port frames. A unicast frame sent on one interface thus matches a station of a different VLAN of the same BSS and is transmitted to it. Only match stations of the interface the frame is sent on, except for control port frames, since those may be sent for VLAN stations directly on the BSS interface. Fixes: 97ffe75791b3 ("mac80211: factor out station lookup from ieee80211_build_hdr()") Signed-off-by: Felix Fietkau <nbd@nbd.name> Link: https://patch.msgid.link/20260916094833.164219-1-nbd@nbd.name Signed-off-by: Johannes Berg <johannes.berg@intel.com>
10 dayswifi: mac80211: keep fallback association elements aliveZhao Li
Associating to a non-transmitted MBSSID profile reads freed memory while determining the operating channel and applying HT capabilities. When an association response omits WMM, HT, or VHT information, ieee80211_assoc_config_link() parses the cached BSS IEs and copies the missing element pointers out of that fallback parse. For a non-transmitted MBSSID profile those pointers refer to merged-profile storage owned by the parse object, and the fallback block frees that object at its end. The copied pointers are used afterwards to determine the operating channel, configure bandwidth, and apply HT capabilities. Keep the fallback parse result alive until association setup finishes. Fixes: 5023b14cf4df ("mac80211: support profile split between elements") Cc: stable@kernel.org Assisted-by: LLM sparse kasan [reorder variable declaration] Signed-off-by: Zhao Li <enderaoelyther@gmail.com> Signed-off-by: Johannes Berg <johannes.berg@intel.com>
10 dayswifi: mac80211: shut down RX BA session timer on teardownZhao Li
Tearing down an RX BA session can leave the session timer queued on a freed tid_rx. Later timer-wheel processing and the timer callback itself then run against freed memory. An RX BAR handler can dereference tid_rx under RCU before teardown unpublishes it and stay in its read-side critical section while teardown deletes the session timer. The stale handler can then rearm the timer after timer_delete_sync() returns and before the RCU callback frees tid_rx. Use timer_shutdown_sync() so rearm attempts become ineffective once teardown starts. Keep reorder_timer unchanged: teardown marks the session removed under reorder_lock and its release path checks that state before rearming. session_timer has no equivalent guard because ieee80211_rx_h_ctrl() rearms it before taking reorder_lock. Fixes: a87f736d942c ("mac80211: use RCU for RX aggregation") Cc: stable@kernel.org # 5.15+ Assisted-by: LLM sparse kasan Signed-off-by: Zhao Li <enderaoelyther@gmail.com> Signed-off-by: Johannes Berg <johannes.berg@intel.com>
10 dayswifi: mac80211: validate TX status rate metadataYuqi Xu
minstrel_ht_tx_status() converts the HT/VHT rate reported in a TX status into a group and rate index and uses those to index the minstrel_ht rate tables. The existing validation only checked that an entry was present and had tries recorded; it did not check that the reported MCS, spatial stream count and bandwidth are representable by the tables, so malformed metadata passed to minstrel_ht_get_stats() or minstrel_ht_ri_get_stats() could be used as an out-of-bounds index. Validate the rate metadata in the common TX status path instead of only in minstrel_ht, since the values are used by more than rate control. The legacy ieee80211_tx_rate array and the rate_info based entries are sanitized in ieee80211_tx_status_ext() and ieee80211_tx_rate_update() before any consumer runs: an entry that does not describe a valid rate for its encoding is dropped. minstrel_ht keeps the checks that depend on its own tables, i.e. the supported number of spatial streams, the MCS group size and the supported bandwidths. This does not take away the driver's responsibility to report sane values, it only prevents a single bad report from corrupting mac80211 state. No WARN_ON() is added: with panic_on_warn a driver bug would otherwise turn into a denial of service. Fixes: a5f69d94d8e2 ("mac80211: Get rid of search loop for rate group index") Fixes: 9208247d74bc ("mac80211: minstrel_ht: add basic support for VHT rates <= 3SS@80MHz") Reported-by: Vega <vega@nebusec.ai> Assisted-by: LLM Signed-off-by: Yuqi Xu <xuyuqiabc@gmail.com> Reviewed-by: Ren Wei <weir@nebusec.ai> Link: https://patch.msgid.link/607e985d71fbbe63ebfc182a37f882f04f980f7f.1789958876.git.xuyuqiabc@gmail.com Signed-off-by: Johannes Berg <johannes.berg@intel.com>
10 daysMerge tag 'wireless-next-2026-09-21' of ↵Jakub Kicinski
https://git.kernel.org/pub/scm/linux/kernel/git/wireless/wireless-next Johannes Berg says: ==================== More changes, including drivers: - brcmfmac: FT/OKC roaming offload - ath12k: IPQ5332 platform infrastructure - cfg80211/mac80211: non-STA TX/RX infrastructure for MLO to fix address translation bugs - the rest is mostly minor cleanups etc. * tag 'wireless-next-2026-09-21' of https://git.kernel.org/pub/scm/linux/kernel/git/wireless/wireless-next: (101 commits) dt-bindings: net: wireless: Convert WL1251 to DT schema libertas: mesh: remove unused and undocumented sysfs attribute groups wifi: mac80211: fix multi-link UHR association wifi: nl80211: rename no-ACK bitmap to TID bitmap wifi: radiotap: correct EHT TB U-SIG 1 B20:25 wifi: ieee80211: fix FTM bufferable check wifi: mac80211: allow advertising 20 MHz-only non-AP STA wifi: mac80211: WARN on 40 MHz HT/HE mismatch wifi: mac80211: tests: fix memory leak wifi: mac80211: use assign_bit() where applicable wifi: mac80211: pass error station if non-STA transmit was requested wifi: mac80211: pass station to ieee80211_tx_skb_tid wifi: mac80211: report to cfg80211 when no STA is known for a frame wifi: cfg80211: add attribute for TX/RX denoting there is no station wifi: mac80211: rework RX packet handling wifi: mac80211: refactor RX link_id and station handling wifi: mac80211: change public RX API to use link stations wifi: iwlwifi: use link_sta internally to the driver MAINTAINERS: Replace wireless.wiki.kernel.org links wifi: brcmfmac: log the firmware status when a connect fails ... ==================== Link: https://patch.msgid.link/20260921121635.195723-3-johannes@sipsolutions.net Signed-off-by: Jakub Kicinski <kuba@kernel.org>
10 dayswifi: mac80211: handle empty FILS association request payloadYuqi Xu
fils_encrypt_assoc_req() accepts a (Re)Association Request frame whose last element is the FILS Session element. crypt_len is then zero and aes_siv_encrypt() is called with an empty plaintext. kmemdup() returns ZERO_SIZE_PTR for a zero-length allocation, so the unconditional sg_init_one() puts an invalid page into the scatterlist. With CONFIG_DEBUG_SG this triggers a kernel BUG in sg_set_buf(); without the debug check the bogus page is handed to the crypto backend. AES-SIV is defined for empty plaintext and the S2V result is then the complete output, so handle this case before the CTR step, which has nothing to encrypt. Fixes: 39404feee691 ("mac80211: FILS AEAD protection for station mode association frames") Cc: stable@vger.kernel.org Reported-by: Vega <vega@nebusec.ai> Assisted-by: LLM Signed-off-by: Yuqi Xu <xuyuqiabc@gmail.com> Reviewed-by: Ren Wei <weir@nebusec.ai> Link: https://patch.msgid.link/325c048982d637a3af80d74ac5b36e9369b93f1e.1789751126.git.xuyuqiabc@gmail.com Signed-off-by: Johannes Berg <johannes.berg@intel.com>
10 dayswifi: mac80211: minstrel_ht: validate fixed rate indexYuqi Xu
The fixed_rate_idx debugfs file is a plain u32 attribute, so any value can be written to it. minstrel_ht_update_stats() then copies the value into mi->max_tp_rate[] and mi->max_prob_rate, and minstrel_ht_set_rate() uses MI_RATE_GROUP()/MI_RATE_IDX() to index minstrel_mcs_groups[] (42 entries) and mi->groups[].rates[] (10 entries) with it. Writing e.g. 65535 selects group 4095 and rate index 15, far outside both arrays. The out-of-bounds entries are dereferenced and updated as struct minstrel_rate_stats (retry counts, etc.), so the invalid index corrupts adjacent kernel memory. With CONFIG_UBSAN_BOUNDS the access is reported as an array-index-out-of-bounds in minstrel_ht_set_rate(). Only a valid group/rate pair, or U32_MAX to disable fixed rate processing, can be used safely, so reject any other value when the debugfs file is written. The file is only reachable through a root-only debugfs mount, so this is not a privilege boundary. The out-of-bounds access is still a bug that must not be reachable through a writable debugfs attribute. Fixes: 24f7580e852b ("minstrel_ht: fixed rate mode through debugfs") Cc: stable@vger.kernel.org Reported-by: Vega <vega@nebusec.ai> Assisted-by: LLM Signed-off-by: Yuqi Xu <xuyuqiabc@gmail.com> Reviewed-by: Ren Wei <weir@nebusec.ai> Link: https://patch.msgid.link/288e6f6d30dc82ff40da502755e6666982f6b735.1789798000.git.xuyuqiabc@gmail.com Signed-off-by: Johannes Berg <johannes.berg@intel.com>
10 dayswifi: mac80211: fix mesh fast xmit path deletion UAFZihan Xi
mesh_fast_tx_cache() stores raw mesh_path pointers. Path deletion flushes the cache and then frees the path with kfree_rcu(), but a lookup that already holds the path can insert a new cache entry after the flush. The cache then points at freed memory. Set MESH_PATH_DELETED before flushing, and skip inserting a cache entry if the path or MPP path is already deleted. Check this under the cache walk lock so it is ordered with the flush. Use WRITE_ONCE() for the deletion flag updates because the cache check reads flags without taking state_lock. Fixes: d5edb9ae8d56 ("wifi: mac80211: mesh fast xmit support") Cc: stable@vger.kernel.org Reported-by: Vega <vega@nebusec.ai> Assisted-by: LLM Co-developed-by: Luxing Yin <root@tr0jan.top> Signed-off-by: Luxing Yin <root@tr0jan.top> Signed-off-by: Zihan Xi <zihanx@nebusec.ai> Link: https://patch.msgid.link/1daa7a98199fe6965c2da7c42717073a6fd39a0b.1789615568.git.zihanx@nebusec.ai Signed-off-by: Johannes Berg <johannes.berg@intel.com>
10 dayswifi: mac80211: drop oversized fragments to avoid extra_len overflowYuchao Zhang
In ieee80211_rx_h_defragment(), fragment payloads are accumulated into entry->extra_len as subsequent fragments arrive: entry->extra_len += rx->skb->len; When the final fragment arrives, the head fragment is dequeued, and pskb_expand_head() is called with entry->extra_len to ensure sufficient tailroom for all queued fragments before copying: if (skb_tailroom(rx->skb) < entry->extra_len) { if (unlikely(pskb_expand_head(rx->skb, 0, entry->extra_len, GFP_ATOMIC))) { ... } } while ((skb = __skb_dequeue(&entry->skb_list))) { skb_put_data(rx->skb, skb->data, skb->len); dev_kfree_skb(skb); } In commit 69f132236827 ("mac80211: shrink struct ieee80211_fragment_entry"), entry->extra_len was narrowed from unsigned int to u16 in order to reduce structure memory footprint. However, an IEEE 802.11 frame sequence can contain up to 16 fragments (frag numbers 0..15). If a sequence of large fragments arrives (e.g. from a malicious peer or rogue AP), the sum of fragment lengths can exceed 65535 bytes (for example, 15 fragments of 4400 bytes total 66000 bytes). Because extra_len is a u16, this addition overflows and wraps around modulo 65536 (e.g. 66000 wraps to 464). Consequently, pskb_expand_head() allocates only the truncated amount of tailroom (or is skipped entirely if the head fragment already has >= 464 bytes of tailroom). When skb_put_data() subsequently iterates through the queued skb list, it appends the full payload into the undersized buffer, causing skb_put() to trigger skb_over_panic() and crash the kernel in softirq context. A legitimate MSDU in IEEE 802.11 is at most 2304 bytes (or up to 7935/11454 bytes for A-MSDU, which is not fragmented), well below U16_MAX. Fix this without increasing the size of struct ieee80211_fragment_entry by checking whether adding the incoming fragment length would exceed U16_MAX. If so, purge the queued fragments and drop the frame. Fixes: 69f132236827 ("mac80211: shrink struct ieee80211_fragment_entry") Signed-off-by: Yuchao Zhang <ndaugoing@gmail.com> Link: https://patch.msgid.link/20260918034004.85078-2-ndaugoing@gmail.com [assign a separate drop reason] Signed-off-by: Johannes Berg <johannes.berg@intel.com>
10 dayswifi: mac80211: drain PS delivery work during station teardownZhao Li
Removing an AP or mesh station can notify the driver and wake TXQs after the station has already been removed from the driver, and can update num_sta_ps and the power-save queues after station cleanup has purged them. sta_deliver_ps_frames() tests sta->dead only before it starts delivery. A worker that passes that test can be delayed while teardown sets sta->dead and removes the station from the driver; when it resumes it still runs the full delivery. The existing cancel_work_sync() sits near the end of __cleanup_single_sta(), after the final driver state transition and after PS accounting and queue purging, so it drains the worker only once the state it has to protect has already changed. Before commit d34ba2168a3c ("mac80211: don't delay station destruction") cleanup was deferred through the same ordered workqueue as the delivery work, which kept the two ordered. Cancel the work after setting sta->dead and before moving the driver state, and move the existing cancellation to the start of __cleanup_single_sta(). The first drain closes the driver-lifetime window; driver callbacks during the remaining state transitions can still queue drv_deliver_wk through ieee80211_sta_block_awake(), so retain the second drain at the start of __cleanup_single_sta(). That drain also covers insertion failures, which reach cleanup without setting sta->dead. Fixes: d34ba2168a3c ("mac80211: don't delay station destruction") Cc: stable@vger.kernel.org Assisted-by: LLM sparse smatch coccinelle kasan Signed-off-by: Zhao Li <enderaoelyther@gmail.com> Link: https://patch.msgid.link/20260916113735.31029-1-enderaoelyther@gmail.com Signed-off-by: Johannes Berg <johannes.berg@intel.com>
10 dayswifi: mac80211: account proxy paths against the mesh path limitZhao Li
Proxy-path churn can drive the interface path counter negative and let later mesh path additions exceed MESH_MAX_MPATHS. mesh_path_free_rcu() decrements the interface mpaths counter for entries from both the mesh and proxy path tables, but mpp_path_add() never reserves a slot in that counter. Removing or expiring a proxy path therefore returns a slot that was never charged. mesh_path_add() uses the same counter to enforce MESH_MAX_MPATHS, so once it falls below the number of installed paths the limit no longer holds. Reserve the shared quota before allocating a proxy path and release it on every unsuccessful addition. Mesh and proxy paths now share one 1024-entry budget, so mpp_path_add() can return -ENOSPC at that limit. Fixes: ece1a2e7e860 ("mac80211: Remove mesh paths when an interface is removed") Cc: stable@vger.kernel.org Assisted-by: LLM sparse kasan Signed-off-by: Zhao Li <enderaoelyther@gmail.com> Link: https://patch.msgid.link/20260916113649.28315-3-enderaoelyther@gmail.com Signed-off-by: Johannes Berg <johannes.berg@intel.com>
10 dayswifi: mac80211: release mesh path quota on failed additionsZhao Li
Repeated failed or duplicate mesh path additions can exhaust MESH_MAX_MPATHS while the path table holds fewer paths, which stops new paths to reachable destinations from being created. mesh_path_add() reserves a slot before allocating and inserting a path. If allocation fails, the function returns without releasing the slot. If the rhashtable insertion reports an error or an existing destination, the function discards its candidate but retains the reservation. No new path is installed in any of these cases. Release the reservation whenever the candidate is not installed. Fixes: ae76eef027f7 ("mac80211: return new mpath from mesh_path_add()") Fixes: 60854fd94573 ("mac80211: mesh: convert path table to rhashtable") Cc: stable@vger.kernel.org Assisted-by: LLM sparse kasan Signed-off-by: Zhao Li <enderaoelyther@gmail.com> Link: https://patch.msgid.link/20260916113649.28315-2-enderaoelyther@gmail.com Signed-off-by: Johannes Berg <johannes.berg@intel.com>
11 dayswifi: mac80211: keep paired old chanctx aliveZhiling Zou
An in-place replacement keeps reciprocal replace_ctx pointers between the old WILL_BE_REPLACED chanctx and the new REPLACES_OTHER chanctx. However, the early free paths only consider assigned and reserved link users when deciding whether to free the old chanctx. That lets the old chanctx be freed too early while the replacement partner still points back to it, either when the last assigned link is released or when that link successfully reassigns to another existing context. Later unreserve and switch-finalization paths can then follow a stale replace_ctx pointer. Keep a paired old chanctx alive until the replacement pair has been torn down. Apply the same check to both __ieee80211_link_release_channel() and ieee80211_link_use_reserved_reassign(). If the replacement is later abandoned, ieee80211_link_unreserve_chanctx() already tears down the pairing before freeing the old chanctx once no users remain. Fixes: 5bcae31d9cb1 ("mac80211: implement multi-vif in-place reservations") Cc: stable@vger.kernel.org Reported-by: Vega <vega@nebusec.ai> Signed-off-by: Zhiling Zou <zhilinz@nebusec.ai> Link: https://patch.msgid.link/b9b582b0db3814f641648b8886bb50f9d68f93ac.1785730815.git.zhilinz@nebusec.ai Signed-off-by: Johannes Berg <johannes.berg@intel.com>
11 dayswifi: mac80211: count only matching reservations in reserved switchZhiling Zou
ieee80211_vif_use_reserved_switch() validates a replacement by counting assigned links on ctx->replace_ctx and treating reservations too broadly. A link can still be assigned to the old channel context while holding a reservation that belongs to a different replacement operation. That can make the current replacement appear complete too early. If another link finalizes first, the function can free the WILL_BE_REPLACED chanctx while the unmatched link and driver still use it, leading to a use-after-free in later beacon generation. Require an in-place reservation to point at the current replacement context, and require the reserved and assigned contexts to be the matching replacement pair, before counting or moving the link. Fixes: 5bcae31d9cb1 ("mac80211: implement multi-vif in-place reservations") Cc: stable@vger.kernel.org Reported-by: Vega <vega@nebusec.ai> Signed-off-by: Zhiling Zou <zhilinz@nebusec.ai> Link: https://patch.msgid.link/4b6c4b8648ab1920c38a40be32c0b1a2797b4ac6.1785726007.git.zhilinz@nebusec.ai Signed-off-by: Johannes Berg <johannes.berg@intel.com>
11 dayswifi: mac80211: fix multi-link UHR associationJohannes Berg
The maximum connection mode is still set to EHT, and in particular in multi-link this matters, the second link and further links are otherwise limited to EHT. Fix that. Link: https://patch.msgid.link/20260916120708.8ddea0cea883.I72e7fc58d65aca620a05a07b759755e5896f068f@changeid Signed-off-by: Johannes Berg <johannes.berg@intel.com>
11 dayswifi: mac80211: allow advertising 20 MHz-only non-AP STAJohannes Berg
802.11 Clause 27 (HE) already defined a 20 MHz-only non-AP HE STA in the 5 GHz band, where VHT is required, although VHT in Clause 21 requires 20, 40 and 80 MHz support. The VHT requirement is implemented in mac80211, but the later allowance for 20 MHz-only since HE wasn't. Allow a device to be a 20 MHz-only non-AP STA and require that it support VHT, but not that it has 80 MHz support, if it's HE as well. Link: https://patch.msgid.link/20260916120127.6e74579d46db.I628aed79ec7f9bf2f8e770b4866ed98cf1ddbe60@changeid Signed-off-by: Johannes Berg <johannes.berg@intel.com>
11 dayswifi: mac80211: WARN on 40 MHz HT/HE mismatchJohannes Berg
This happened to me and was tricky to debug, of course it shouldn't happen with correct drivers, WARN in this case. Link: https://patch.msgid.link/20260916120127.efa58d51d11f.Ie29dc83578893945231db3badfcb7b4a2e2775ba@changeid Signed-off-by: Johannes Berg <johannes.berg@intel.com>
11 dayswifi: mac80211: tests: fix memory leakJohannes Berg
The code allocates the bitrates twice, but really only should do that once. Remove the unconditional allocation even though it's the same in both branches of the switch, since the cleanup only handles those two branches explicitly. Link: https://patch.msgid.link/20260916115759.2cd8a91ed99d.I89c5068a3472e6296baf5a2d6832b733282d2b24@changeid Signed-off-by: Johannes Berg <johannes.berg@intel.com>
11 dayswifi: mac80211: use assign_bit() where applicablePeng Fan
Convert open-coded if/else with set_bit/clear_bit the assign_bit API. Done with Coccinelle semantic patch: // set_bit -> clear_bit => assign_bit @@ expression cond, bit, addr; @@ -if (cond) - set_bit(bit, addr); -else - clear_bit(bit, addr); +assign_bit(bit, addr, cond); @@ expression cond, bit, addr; @@ -if (cond) - clear_bit(bit, addr); -else - set_bit(bit, addr); +assign_bit(bit, addr, !cond); Signed-off-by: Peng Fan <peng.fan@nxp.com> Link: https://patch.msgid.link/20260920022822.3145944-1-peng.fan@oss.nxp.com Signed-off-by: Johannes Berg <johannes.berg@intel.com>
2026-09-16Merge tag 'wireless-2026-09-16' of ↵Jakub Kicinski
https://git.kernel.org/pub/scm/linux/kernel/git/wireless/wireless Johannes Berg says: ==================== Many fixes: - mac80211: S1G TIM bitmap fix - ath12k: remove undocumented DT ABI implementation - various firmware API and over-the-air hardening changes - fixes for most cfg80211/mac80211 syzbot reports * tag 'wireless-2026-09-16' of https://git.kernel.org/pub/scm/linux/kernel/git/wireless/wireless: (67 commits) wifi: brcmsmac: fix UAF in brcms_free_timer() wifi: brcmfmac: fix lost 802.1x TX completion wakeup wifi: ath11k: cleanup arsta in ath11k_mac_peer_cleanup_all() wifi: wcn36xx: Fix potential use-after-free in TX ack timer teardown wifi: ath12k: ahb: Revert undocumented ABI and dead code wifi: mac80211: refuse to make a monitor active when it has no queue wifi: libipw: reject TKIP frames without a full MIC wifi: virt_wifi: don't transfer operstate before register wifi: cfg80211: check if AP has been started or joined a mesh before adding new station wifi: cfg80211: move link_id validation earlier in nl80211_new_station() wifi: cfg80211: do not support direct add of station to AP_VLAN interfaces wifi: cfg80211: verify if AP_VLAN belongs to the correct AP wifi: mac80211: set up the TX info early to fix failure paths wifi: mac80211: mesh: release the channel if start fails wifi: mac80211: mesh: reset the CSA state when leaving wifi: mac80211: add HE 6 GHz capability in the scan elems len wifi: mac80211: don't access the TSF of a down interface wifi: mac80211: don't RCU-dereference the mesh CSA settings we just set wifi: mac80211: don't allow link changes when iface is down wifi: mac80211: require a peer station for TDLS setup confirm ... ==================== Link: https://patch.msgid.link/20260916083642.110609-3-johannes@sipsolutions.net Signed-off-by: Jakub Kicinski <kuba@kernel.org>
2026-09-16wifi: mac80211: pass error station if non-STA transmit was requestedBenjamin Berg
When cfg80211 requested a transmit without a station, pass an error station to ieee80211_tx_skb_tid instead of the correct one. Signed-off-by: Benjamin Berg <benjamin.berg@intel.com> Link: https://patch.msgid.link/20260915151925.92499fb21e4a.I5ffe7bc0d4ccefca5c1e506d5d3d482e13989cda@changeid Signed-off-by: Johannes Berg <johannes.berg@intel.com>
2026-09-16wifi: mac80211: pass station to ieee80211_tx_skb_tidBenjamin Berg
The station may be relevant for queuing and will also generally be resolved in some cases. However, we want to be able to prevent looking up the station based on the address. Add a station parameter, which can be set to the correct station, to an error value to prevent station lookup or to NULL to get the old behaviour where the address is used to find the appropriate station. Also disable the station lookup for ieee80211_tx_skb_tid_band already as it does not make any sense to find a station when doing an off-channel transmit. Signed-off-by: Benjamin Berg <benjamin.berg@intel.com> Link: https://patch.msgid.link/20260915151925.759b6144ddf9.Ib7be90db0d3712d14e7a292023ff3d922baef860@changeid Signed-off-by: Johannes Berg <johannes.berg@intel.com>
2026-09-16wifi: mac80211: report to cfg80211 when no STA is known for a frameBenjamin Berg
This is relevant for hostapd to know whether address translation was done on a received management frame. Signed-off-by: Benjamin Berg <benjamin.berg@intel.com> Link: https://patch.msgid.link/20260915151925.273a1c7a1ab2.I28d8146b9189c5961411ecb26b44588895de1b56@changeid Signed-off-by: Johannes Berg <johannes.berg@intel.com>
2026-09-16wifi: mac80211: rework RX packet handlingBenjamin Berg
The code has grown over time and it was not correctly handling all cases. Examples of issues are that for management frames we would match the received address against the MLD address even though we should not resolve the station in that case. Another issue was that for data frames we would not correctly fall back to use link addresses when the driver does not provide the pubsta already. The new code still uses the same approach as before. For data frames, assume that a valid station exists and interfaces do not need to be iterated. On the other hand, for non-data frames (or if a data frame without a station is received) all interfaces must be iterated. Note that this rework makes mac80211 slightly more strict. For example, previously mac80211 would have incorrectly accepted a data frame that was transmitted on the wrong link. Signed-off-by: Benjamin Berg <benjamin.berg@intel.com> Link: https://patch.msgid.link/20260915151925.de2fc9a47273.Ie12ec077142c6a7fdbb58cdfc5660497cc75150e@changeid Signed-off-by: Johannes Berg <johannes.berg@intel.com>
2026-09-16wifi: mac80211: refactor RX link_id and station handlingBenjamin Berg
The link ID for one frequency may be different between VIFs. As such, the sensible thing is to set the link ID later in the flow once the SKB is duplicated for each VIF. As the link ID is not passed in from outside mac80211 it is always valid and the corresponding bit can be dropped. Also switch a few more places to pass the link STA as that is a natural way to pass the link information around. This fixes the per-link statistics when frames are reordered. Note that this patch deliberately leaves some places unchanged and even incorrect as this will be addressed by further refactorings. Signed-off-by: Benjamin Berg <benjamin.berg@intel.com> Link: https://patch.msgid.link/20260915151925.467593bc1105.I8abe3601d0335dca22d48bcee864817cfccf0de0@changeid Signed-off-by: Johannes Berg <johannes.berg@intel.com>
2026-09-16wifi: mac80211: change public RX API to use link stationsBenjamin Berg
If a station is passed then the link ID also needs to be known. As such, it is a more natural API to simply pass the link station directly rather than pushing the link information into the RX status. Furthermore, having the link ID in the RX status is not actually correct because the link IDs are VIF specific and there may be multiple VIFs. In the case of a station this relationship is clear, but then one may as well use the link station. This patch only changes the API and emulates the old (incorrect) behaviour for now. The mac80211 RX code will be updated in later patches. Signed-off-by: Benjamin Berg <benjamin.berg@intel.com> Link: https://patch.msgid.link/20260915151925.06f41565116a.I4a2d45609e94b52654b10ec572e59a45d09c41f4@changeid Signed-off-by: Johannes Berg <johannes.berg@intel.com>
2026-09-14wifi: mac80211: don't reset the TXQ scheduling round numberJulius Bairaktaris
A round is ended when ieee80211_next_txq() meets a txq whose remembered round number is the current one, meaning it has gone full circle. When the AC exceeds the airtime limit, ieee80211_txq_schedule_start() sets the round number to 0 to close the round. The next open round is 1. A txq from an earlier round 1 still remembers the "1", so the next round stops on it and serves nothing. Fix: use a separate open/closed flag and let the round number keep counting. Testing: ~4200 skipped selections per 20s without the fix and 20 skipped selections per 20s with the fix on ath11k (with my AQL series applied) at BE 500/1000. Fixes: 8e4bac067105 ("wifi: mac80211: add a per-PHY AQL limit to improve fairness") Assisted-by: Claude:claude-opus-5 Signed-off-by: Julius Bairaktaris <julius@bairaktaris.de> Reviewed-by: Toke Høiland-Jørgensen <toke@toke.dk> Link: https://patch.msgid.link/20260908144155.756569-1-julius@bairaktaris.de Signed-off-by: Johannes Berg <johannes.berg@intel.com>
2026-09-14wifi: mac80211: Fix the return value in mesh_path_add() kernel-docKarl Mehltretter
mesh_path_add() has returned the new (or the already existing) struct mesh_path, or an ERR_PTR(), since commit ae76eef027f7 ("mac80211: return new mpath from mesh_path_add()"), but its kernel-doc still says "Returns: 0 on success". Describe the pointer. Fixes: ae76eef027f7 ("mac80211: return new mpath from mesh_path_add()") Assisted-by: LLM Signed-off-by: Karl Mehltretter <kmehltretter@gmail.com> Link: https://patch.msgid.link/20260912072840.50710-1-kmehltretter@gmail.com Signed-off-by: Johannes Berg <johannes.berg@intel.com>
2026-09-14wifi: mac80211: fix stats/preemption in ieee80211_tx_control_port()Deepanshu Kartikey
ieee80211_tx_control_port() can be called from nl80211_tx_control_port() in normal process context via netlink sendmsg(), where BH/preemption is not disabled. dev_sw_netstats_tx_add() uses this_cpu_ptr() internally, which requires preemption to be disabled, triggering a "BUG: using smp_processor_id() in preemptible code" warning. Fix this by moving the local_bh_disable()/local_bh_enable() section to also cover dev_sw_netstats_tx_add() and ieee80211_tpt_led_trig_tx(). Fixes: d5a014204a3b ("wifi: mac80211: tx: simplify control port frame transmission") Reported-by: syzbot+d979bd35c8a76fd1b6f5@syzkaller.appspotmail.com Closes: https://syzkaller.appspot.com/bug?extid=d979bd35c8a76fd1b6f5 Signed-off-by: Deepanshu Kartikey <kartikey406@gmail.com> Link: https://patch.msgid.link/20260910041047.24437-1-kartikey406@gmail.com Signed-off-by: Johannes Berg <johannes.berg@intel.com>
2026-09-14wifi: mac80211: report 900MHz channel for S1G band radiotap headerLachlan Hodges
Currently S1G frames are reported as 2GHz spectrum, use the 900MHz channel flag instead. Signed-off-by: Lachlan Hodges <lachlan.hodges@morsemicro.com> Link: https://patch.msgid.link/20260909073014.53344-3-lachlan.hodges@morsemicro.com Signed-off-by: Johannes Berg <johannes.berg@intel.com>
2026-09-14wifi: mac80211: refuse to make a monitor active when it has no queueDevin Wittmayer
A monitor interface only gets a TXQ if it's created active, and one can't be added later. Setting the flag on a down interface is still allowed, so the driver is handed a monitor with no queue. ath9k dereferences it: BUG: kernel NULL pointer dereference, address: 0000000000000066 RIP: 0010:ath_tx_node_init+0x49/0x170 [ath9k] ath9k_add_interface+0x10c/0x140 [ath9k] drv_add_interface+0x54/0x250 [mac80211] ieee80211_do_open+0x32f/0x800 [mac80211] Reached with CAP_NET_ADMIN by "iw dev X set monitor active" followed by "ip link set X up". RTNL is held, so netlink operations block behind it. Refuse the flag when there is no queue to give. Fixes: 79af1f866193 ("mac80211: avoid allocating TXQs that won't be used") Cc: stable@vger.kernel.org Signed-off-by: Devin Wittmayer <lucid_duck@justthetip.ca> Link: https://patch.msgid.link/20260904200338.10829-1-lucid_duck@justthetip.ca Signed-off-by: Johannes Berg <johannes.berg@intel.com>