In the Linux kernel, the following vulnerability has been resolved:
wifi: rtw88: sdio: Honor the host max_req_size in the RX path
Lukas reports skb_over_panic errors on his Banana Pi BPI-CM4 which comes with an Amlogic A311D (G12B) SoC and a RTL8822CS SDIO wifi/Bluetooth combo card. The error he observed is identical to what has been fixed in commit e967229ead0e ("wifi: rtw88: sdio: Check the HISR RX_REQUEST bit in rtw_sdio_rx_isr()") but that commit didn't fix Lukas' problem.
Lukas found that disabling or limiting RX aggregation works around the problem for some time (but does not fully fix it). In the following discussion a few key topics have been discussed which have an impact on this problem: - The Amlogic A311D (G12B) SoC has a hardware bug in the SDIO controller which prevents DMA transfers. Instead all transfers need to go through the controller SRAM which limits transfers to 1536 bytes - rtw88 chips don't split incoming (RX) packets, so if a big packet is received this is forwarded to the host in it's original form - rtw88 chips can do RX aggregation, meaning more multiple incoming packets can be pulled by the host from the card with one MMC/SDIO transfer. This Depends on settings in the REG_RXDMA_AGG_PG_TH register (BIT_RXDMA_AGG_PG_TH limits the number of packets that will be aggregated, BIT_DMA_AGG_TO_V1 configures a timeout for aggregation and BIT_EN_PRE_CALC makes the chip honor the limits more effectively)
Use multiple consecutive reads in rtw_sdio_read_port() and limit the number of bytes which are copied by the host from the card in one MMC/SDIO transfer. This allows receiving a buffer that's larger than the hosts max_req_size (number of bytes which can be transferred in one MMC/SDIO transfer). As a result of this the skb_over_panic error is gone as the rtw88 driver is now able to receive more than 1536 bytes from the card (either because the incoming packet is larger than that or because multiple packets have been aggregated).
In case of an receive errors (-EILSEQ has been observed by Lukas) we need to drain the remaining data from the card's buffer, otherwise the card will return corrupt data for the next rtw_sdio_read_port() call.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade linux | Jul 27, 2026 | Jul 27, 2026 |
| Ubuntu | — | Upgrade linux-image-6.5.0-1024-oracleUpgrade linux-image-lowlatency-64kUpgrade linux-image-6.5.0-1021-awsUpgrade linux-image-nvidia-6.5Upgrade linux-image-lowlatencyUpgrade linux-image-generic-lpaeUpgrade linux-image-lowlatency-hwe-22.04Upgrade linux-image-azureUpgrade linux-image-6.5.0-1022-azure-fdeUpgrade linux-image-virtual-hwe-22.04Upgrade linux-image-6.5.0-1018-raspiUpgrade linux-image-kvmUpgrade linux-image-nvidia-64k-hwe-22.04Upgrade linux-image-oem-22.04Upgrade linux-image-starfiveUpgrade linux-image-6.5.0-41-genericUpgrade linux-image-oem-22.04aUpgrade linux-image-raspiUpgrade linux-image-6.5.0-1015-starfiveUpgrade linux-image-generic-hwe-22.04Upgrade linux-image-6.5.0-1021-nvidia-64kUpgrade linux-image-oem-22.04bUpgrade linux-image-azure-fdeUpgrade linux-image-6.5.0-1017-laptopUpgrade linux-image-generic-64kUpgrade linux-image-genericUpgrade linux-image-oem-22.04cUpgrade linux-image-oracleUpgrade linux-image-6.5.0-41-generic-64kUpgrade linux-image-6.5.0-1021-nvidiaUpgrade linux-image-6.5.0-1024-oracle-64kUpgrade linux-image-gcpUpgrade linux-image-virtualUpgrade linux-image-awsUpgrade linux-image-6.5.0-1022-gcpUpgrade linux-image-6.5.0-41-lowlatency-64kUpgrade linux-image-nvidia-64k-6.5Upgrade linux-image-oracle-64kUpgrade linux-image-6.5.0-41-lowlatencyUpgrade linux-image-6.5.0-1022-azureUpgrade linux-image-6.5.0-1024-oemUpgrade linux-image-oem-22.04dUpgrade linux-image-nvidia-hwe-22.04Upgrade linux-image-generic-64k-hwe-22.04Upgrade linux-image-lowlatency-64k-hwe-22.04Upgrade linux-image-laptop-23.10Upgrade linux-image-raspi-nolpae | May 17, 2024 | Mar 18, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub