[<prev] [next>] [day] [month] [year] [list]
Message-ID: <20250715230904.661092-2-moonhee.lee.ca@gmail.com>
Date: Tue, 15 Jul 2025 16:09:05 -0700
From: Moon Hee Lee <moonhee.lee.ca@...il.com>
To: johannes@...solutions.net
Cc: linux-kernel@...r.kernel.org,
linux-wireless@...r.kernel.org,
linux-kernel-mentees@...ts.linux.dev,
netdev@...r.kernel.org,
syzkaller-bugs@...glegroups.com,
syzbot+f73f203f8c9b19037380@...kaller.appspotmail.com,
skhan@...uxfoundation.org,
david.hunter.linux@...il.com,
Moon Hee Lee <moonhee.lee.ca@...il.com>
Subject: [PATCH wireless-next] wifi: mac80211: reject TDLS operations when station is not associated
syzbot triggered a WARN in ieee80211_tdls_oper() by sending
NL80211_TDLS_ENABLE_LINK immediately after NL80211_CMD_CONNECT,
before association completed and without prior TDLS setup.
This left internal state like sdata->u.mgd.tdls_peer uninitialized,
leading to a WARN_ON() in code paths that assumed it was valid.
Reject the operation early if not in station mode or not associated.
Reported-by: syzbot+f73f203f8c9b19037380@...kaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=f73f203f8c9b19037380
Fixes: 81dd2b882241 ("mac80211: move TDLS data to mgd private part")
Tested-by: syzbot+f73f203f8c9b19037380@...kaller.appspotmail.com
Signed-off-by: Moon Hee Lee <moonhee.lee.ca@...il.com>
---
net/mac80211/tdls.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/net/mac80211/tdls.c b/net/mac80211/tdls.c
index 94714f8ffd22..ba5fbacbeeda 100644
--- a/net/mac80211/tdls.c
+++ b/net/mac80211/tdls.c
@@ -1422,7 +1422,7 @@ int ieee80211_tdls_oper(struct wiphy *wiphy, struct net_device *dev,
if (!(wiphy->flags & WIPHY_FLAG_SUPPORTS_TDLS))
return -EOPNOTSUPP;
- if (sdata->vif.type != NL80211_IFTYPE_STATION)
+ if (sdata->vif.type != NL80211_IFTYPE_STATION || !sdata->vif.cfg.assoc)
return -EINVAL;
switch (oper) {
--
2.43.0
Powered by blists - more mailing lists