| From stable+bounces-206080-greg=kroah.com@vger.kernel.org Wed Jan 7 03:37:44 2026 |
| From: Sasha Levin <sashal@kernel.org> |
| Date: Tue, 6 Jan 2026 21:34:39 -0500 |
| Subject: wifi: mac80211: Discard Beacon frames to non-broadcast address |
| To: stable@vger.kernel.org |
| Cc: Jouni Malinen <jouni.malinen@oss.qualcomm.com>, Johannes Berg <johannes.berg@intel.com>, Sasha Levin <sashal@kernel.org> |
| Message-ID: <20260107023440.3510800-1-sashal@kernel.org> |
| |
| From: Jouni Malinen <jouni.malinen@oss.qualcomm.com> |
| |
| [ Upstream commit 193d18f60588e95d62e0f82b6a53893e5f2f19f8 ] |
| |
| Beacon frames are required to be sent to the broadcast address, see IEEE |
| Std 802.11-2020, 11.1.3.1 ("The Address 1 field of the Beacon .. frame |
| shall be set to the broadcast address"). A unicast Beacon frame might be |
| used as a targeted attack to get one of the associated STAs to do |
| something (e.g., using CSA to move it to another channel). As such, it |
| is better have strict filtering for this on the received side and |
| discard all Beacon frames that are sent to an unexpected address. |
| |
| This is even more important for cases where beacon protection is used. |
| The current implementation in mac80211 is correctly discarding unicast |
| Beacon frames if the Protected Frame bit in the Frame Control field is |
| set to 0. However, if that bit is set to 1, the logic used for checking |
| for configured BIGTK(s) does not actually work. If the driver does not |
| have logic for dropping unicast Beacon frames with Protected Frame bit |
| 1, these frames would be accepted in mac80211 processing as valid Beacon |
| frames even though they are not protected. This would allow beacon |
| protection to be bypassed. While the logic for checking beacon |
| protection could be extended to cover this corner case, a more generic |
| check for discard all Beacon frames based on A1=unicast address covers |
| this without needing additional changes. |
| |
| Address all these issues by dropping received Beacon frames if they are |
| sent to a non-broadcast address. |
| |
| Cc: stable@vger.kernel.org |
| Fixes: af2d14b01c32 ("mac80211: Beacon protection using the new BIGTK (STA)") |
| Signed-off-by: Jouni Malinen <jouni.malinen@oss.qualcomm.com> |
| Link: https://patch.msgid.link/20251215151134.104501-1-jouni.malinen@oss.qualcomm.com |
| Signed-off-by: Johannes Berg <johannes.berg@intel.com> |
| [ adapted RX_DROP return value to RX_DROP_MONITOR ] |
| Signed-off-by: Sasha Levin <sashal@kernel.org> |
| Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org> |
| --- |
| net/mac80211/rx.c | 5 +++++ |
| 1 file changed, 5 insertions(+) |
| |
| --- a/net/mac80211/rx.c |
| +++ b/net/mac80211/rx.c |
| @@ -3299,6 +3299,11 @@ ieee80211_rx_h_mgmt_check(struct ieee802 |
| if (!ieee80211_is_mgmt(mgmt->frame_control)) |
| return RX_DROP_MONITOR; |
| |
| + /* Drop non-broadcast Beacon frames */ |
| + if (ieee80211_is_beacon(mgmt->frame_control) && |
| + !is_broadcast_ether_addr(mgmt->da)) |
| + return RX_DROP_MONITOR; |
| + |
| if (rx->sdata->vif.type == NL80211_IFTYPE_AP && |
| ieee80211_is_beacon(mgmt->frame_control) && |
| !(rx->flags & IEEE80211_RX_BEACON_REPORTED)) { |