nl80211: fix NL80211_ATTR_CHANNEL_WIDTH attribute type
authorJohannes Berg <johannes.berg@intel.com>
Wed, 25 Mar 2020 08:05:32 +0000 (09:05 +0100)
committerJohannes Berg <johannes.berg@intel.com>
Wed, 25 Mar 2020 08:58:43 +0000 (09:58 +0100)
The new opmode notification used this attribute with a u8, when
it's documented as a u32 and indeed used in userspace as such,
it just happens to work on little-endian systems since userspace
isn't doing any strict size validation, and the u8 goes into the
lower byte. Fix this.

Cc: stable@vger.kernel.org
Fixes: 466b9936bf93 ("cfg80211: Add support to notify station's opmode change to userspace")
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Link: https://lore.kernel.org/r/20200325090531.be124f0a11c7.Iedbf4e197a85471ebd729b186d5365c0343bf7a8@changeid
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
net/wireless/nl80211.c

index ec5d67794aab67a2f7c56a880c7fd8510860dada..f0af23c1634a7caaf154330d237f00a3ce3e0e24 100644 (file)
@@ -16416,7 +16416,7 @@ void cfg80211_sta_opmode_change_notify(struct net_device *dev, const u8 *mac,
                goto nla_put_failure;
 
        if ((sta_opmode->changed & STA_OPMODE_MAX_BW_CHANGED) &&
-           nla_put_u8(msg, NL80211_ATTR_CHANNEL_WIDTH, sta_opmode->bw))
+           nla_put_u32(msg, NL80211_ATTR_CHANNEL_WIDTH, sta_opmode->bw))
                goto nla_put_failure;
 
        if ((sta_opmode->changed & STA_OPMODE_N_SS_CHANGED) &&