Page MenuHomeFreeBSD

rsu: add a runtime TX buffer bound check for a kernel buffer overflow
ClosedPublic

Authored by markj on Aug 17 2026, 8:17 PM.
Tags
None
Referenced Files
Unknown Object (File)
Thu, Oct 1, 3:31 AM
Unknown Object (File)
Thu, Sep 24, 4:37 PM
Unknown Object (File)
Thu, Sep 24, 7:32 AM
Unknown Object (File)
Wed, Sep 23, 8:35 AM
Unknown Object (File)
Wed, Sep 16, 1:08 PM
Unknown Object (File)
Fri, Sep 11, 5:05 AM
Unknown Object (File)
Thu, Sep 10, 11:04 PM
Unknown Object (File)
Tue, Sep 8, 11:05 PM
Subscribers

Details

Summary

The rsu driver currently relies on a KASSERT to prove that the mbuf payload
plus TX descriptor fits in the per-transfer USB TX buffer. On production
kernels without INVARIANTS, an oversized raw 802.11 frame can reach
m_copydata() and overwrite past that buffer, causing local kernel memory
corruption.

This suggested patch replaces the assertion-only guard with a runtime size
check before the copy. Oversized frames return EMSGSIZE, leaving the existing
caller cleanup paths responsible for freeing m0, ni, and the unused
transfer buffer.

Reachable via root / bpf access

Diff Detail

Repository
rG FreeBSD src repository
Lint
Lint Not Applicable
Unit
Tests Not Applicable