Hi all, I can confirm that this problem also occurs for me at an older
802.11ac upgraded iMac6,1 and iMac8,1 computer. This is the case for
kernel 6.11.0-17 as well as kernel 6.8.0-54. The used WiFi card is an
Apple Broadcom BCM94360CSAX.

This problem is present since the upgrade to Kubuntu 24.04 LTS. On
Kubuntu 22.04 LTS and older 5.x based kernels the WiFi card worked
mostly without any problems.

However, it looks that this doesn't occur on every 802.11ac upgraded
iMac. At least for an iMac5,1 computer the BCM94360CSAX card seems to
work fine under Lubuntu 24.04 LTS and newer 6.8 and 6.11 kernels.

[  110.352437] ------------[ cut here ]------------
[  110.352447] UBSAN: array-index-out-of-bounds in 
/var/lib/dkms/broadcom-sta/6.30.223.271/build/src/wl/sys/wl_linux.c:1935:4
[  110.352455] index 2 is out of range for type 'ether_addr [1]'
[  110.352461] CPU: 0 UID: 0 PID: 35 Comm: kworker/u8:2 Tainted: P        W  OE 
     6.11.0-17-generic #17~24.04.2-Ubuntu
[  110.352467] Tainted: [P]=PROPRIETARY_MODULE, [W]=WARN, [O]=OOT_MODULE, 
[E]=UNSIGNED_MODULE
[  110.352470] Hardware name: Apple Computer, Inc. iMac6,1/Mac-F4218FC8, BIOS   
  IM61.88Z.0093.B07.0706281250 06/28/07
[  110.352472] Workqueue: ipv6_addrconf addrconf_dad_work
[  110.352483] Call Trace:
[  110.352486]  <TASK>
[  110.352491]  dump_stack_lvl+0x76/0xa0
[  110.352502]  dump_stack+0x10/0x20
[  110.352506]  __ubsan_handle_out_of_bounds+0xcb/0x110
[  110.352512]  _wl_set_multicast_list+0x126/0x230 [wl]
[  110.352647]  wl_set_multicast_list+0x3a/0xa0 [wl]
[  110.352739]  __dev_set_rx_mode+0x79/0xe0
[  110.352745]  __dev_mc_add+0x94/0xa0
[  110.352750]  dev_mc_add+0x10/0x20
[  110.352755]  igmp6_group_added+0xe0/0x100
[  110.352762]  __ipv6_dev_mc_inc+0x27d/0x400
[  110.352767]  ipv6_dev_mc_inc+0x10/0x20
[  110.352772]  addrconf_dad_work+0xaa/0x500
[  110.352777]  process_one_work+0x17b/0x3d0
[  110.352785]  worker_thread+0x2de/0x410
[  110.352788]  ? __pfx_worker_thread+0x10/0x10
[  110.352792]  kthread+0xe4/0x110
[  110.352796]  ? __pfx_kthread+0x10/0x10
[  110.352800]  ret_from_fork+0x47/0x70
[  110.352805]  ? __pfx_kthread+0x10/0x10
[  110.352808]  ret_from_fork_asm+0x1a/0x30
[  110.352816]  </TASK>
[  110.352818] ---[ end trace ]---

-- 
You received this bug notification because you are a member of Kernel
Packages, which is subscribed to broadcom-sta in Ubuntu.
https://bugs.launchpad.net/bugs/2065839

Title:
  UBSAN: array-index-out-of-bounds

Status in broadcom-sta package in Ubuntu:
  Confirmed

Bug description:
  [   43.991642] ------------[ cut here ]------------
  [   43.991650] UBSAN: array-index-out-of-bounds in 
/var/lib/dkms/broadcom-sta/6.30.223.271/build/src/wl/sys/wl_cfg80211_hybrid.c:2394:26
  [   43.991659] index 1 is out of range for type 'uint8 [1]'
  [   43.991663] CPU: 1 PID: 763 Comm: wl_event_handle Tainted: P           OE  
    6.8.0-31-generic #31-Ubuntu
  [   43.991668] Hardware name: Apple Inc. MacBookAir4,2/Mac-742912EFDBEE19B3, 
BIOS 135.0.0.0.0 06/14/2019
  [   43.991670] Call Trace:
  [   43.991674]  <TASK>
  [   43.991678]  dump_stack_lvl+0x48/0x70
  [   43.991692]  dump_stack+0x10/0x20
  [   43.991697]  __ubsan_handle_out_of_bounds+0xc6/0x110
  [   43.991703]  wl_update_bss_info+0x10f/0x370 [wl]
  [   43.991807]  wl_bss_connect_done.isra.0+0x170/0x2a0 [wl]
  [   43.991901]  wl_notify_connect_status+0xdf/0x450 [wl]
  [   43.991998]  wl_event_handler+0x7b/0x240 [wl]
  [   43.992077]  ? __pfx_wl_event_handler+0x10/0x10 [wl]
  [   43.992147]  kthread+0xf2/0x120
  [   43.992151]  ? __pfx_kthread+0x10/0x10
  [   43.992154]  ret_from_fork+0x47/0x70
  [   43.992158]  ? __pfx_kthread+0x10/0x10
  [   43.992160]  ret_from_fork_asm+0x1b/0x30
  [   43.992165]  </TASK>
  [   43.992166] ---[ end trace ]---

  ProblemType: Bug
  DistroRelease: Ubuntu 24.04
  Package: linux-image-6.8.0-31-generic 6.8.0-31.31
  ProcVersionSignature: Ubuntu 6.8.0-31.31-generic 6.8.1
  Uname: Linux 6.8.0-31-generic x86_64
  NonfreeKernelModules: wl
  ApportVersion: 2.28.1-0ubuntu3
  Architecture: amd64
  AudioDevicesInUse:
   USER        PID ACCESS COMMAND
   /dev/snd/seq:        js1        1135 F.... pipewire
   /dev/snd/controlC0:  js1        1137 F.... wireplumber
  CRDA: N/A
  CasperMD5CheckResult: unknown
  CurrentDesktop: KDE
  Date: Wed May 15 22:42:50 2024
  InstallationDate: Installed on 2024-03-01 (75 days ago)
  InstallationMedia: Kubuntu 23.10 "Mantic Minotaur" - Release amd64 (20231010)
  MachineType: Apple Inc. MacBookAir4,2
  ProcFB: 0 i915drmfb
  ProcKernelCmdLine: BOOT_IMAGE=/vmlinuz-6.8.0-31-generic 
root=/dev/mapper/vgkubuntu-root ro ipv6.disable=1 quiet splash vt.handoff=7
  RelatedPackageVersions:
   linux-restricted-modules-6.8.0-31-generic N/A
   linux-backports-modules-6.8.0-31-generic  N/A
   linux-firmware                            20240318.git3b128b60-0ubuntu2
  SourcePackage: linux
  UpgradeStatus: No upgrade log present (probably fresh install)
  dmi.bios.date: 06/14/2019
  dmi.bios.release: 0.1
  dmi.bios.vendor: Apple Inc.
  dmi.bios.version: 135.0.0.0.0
  dmi.board.asset.tag: Base Board Asset Tag#
  dmi.board.name: Mac-742912EFDBEE19B3
  dmi.board.vendor: Apple Inc.
  dmi.board.version: MacBookAir4,2
  dmi.chassis.type: 10
  dmi.chassis.vendor: Apple Inc.
  dmi.chassis.version: Mac-742912EFDBEE19B3
  dmi.modalias: 
dmi:bvnAppleInc.:bvr135.0.0.0.0:bd06/14/2019:br0.1:svnAppleInc.:pnMacBookAir4,2:pvr1.0:rvnAppleInc.:rnMac-742912EFDBEE19B3:rvrMacBookAir4,2:cvnAppleInc.:ct10:cvrMac-742912EFDBEE19B3:skuSystemSKU#:
  dmi.product.family: MacBook Air
  dmi.product.name: MacBookAir4,2
  dmi.product.sku: System SKU#
  dmi.product.version: 1.0
  dmi.sys.vendor: Apple Inc.

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/broadcom-sta/+bug/2065839/+subscriptions


-- 
Mailing list: https://launchpad.net/~kernel-packages
Post to     : kernel-packages@lists.launchpad.net
Unsubscribe : https://launchpad.net/~kernel-packages
More help   : https://help.launchpad.net/ListHelp

Reply via email to