Executive brief
A vulnerability was identified in the Linux kernel's ath9k_htc Wi-Fi driver, which handles communication for certain wireless network adapters. An issue with how the system resets data buffers during error handling could lead to a system crash or instability. This primarily affects the availability of the system and its network connectivity.
Technical details
A vulnerability exists in the ath9k_htc Wi-Fi driver within the Linux kernel due to the use of skb_trim() on buffers with uninitialized lengths. In certain error paths within ath9k_hif_usb_reg_in_cb() and ath9k_hif_usb_rx_cb(), the skb_trim() function performs a sanity check on the existing length of the socket buffer (skb). If this length is uninitialized, the check fails, leading to kernel warnings or crashes (Denial of Service). The fix involves replacing skb_trim() with __skb_set_length(skb, 0) to bypass the unnecessary length check when resetting the buffer for resubmission. This issue was discovered by syzbot and has been patched across multiple stable kernel branches.
Affected products
- Linux Linux Kernel up to 5.10.227, 5.11 to 5.15.168, 5.16 to 6.1.113, 6.2 to 6.6.55, 6.7 to 6.10.14, 6.11 to 6.11.3
Timeline
- 2024-10-21: disclosed
- 2024-10-21: advisory
- 2024-08-16: patched: Mainline kernel patch applied
References
- https://git.kernel.org/stable/c/012ae530afa0785102360de452745d33c99a321b
- https://git.kernel.org/stable/c/2c230210ec0ae6ed08306ac70dc21c24b817bb95
- https://git.kernel.org/stable/c/6a875220670475d9247e576c15dc29823100a4e4
- https://git.kernel.org/stable/c/94745807f3ebd379f23865e6dab196f220664179
- https://git.kernel.org/stable/c/a9f4e28e8adaf0715bd4e01462af0a52ee46b01f
- https://git.kernel.org/stable/c/b02eb7c86ff2ef1411c3095ec8a52b13f68db04f
- https://git.kernel.org/stable/c/d1f2fbc6a769081503f6ffedbb5cd1ac497f0e77