usb: gadget: f_ncm: validate datagram bounds in ncm_unwrap_ntb()

When unpacking host-supplied NTBs, ncm_unwrap_ntb() checks datagram length
against frame_max but does not verify that the datagram fits within the
declared block length. Additionally, when decoding multiple NTBs from a
single socket buffer, subsequent block lengths are not checked against the
actual remaining buffer data.

With these checks missing, a malicious USB host can specify datagram
offsets and lengths that point beyond the block, or supply secondary NTB
headers declaring lengths larger than the buffer. skb_put_data() then
copies adjacent kernel memory from skb_shared_info into the network skb.

Fix this by verifying that sufficient buffer space remains for the NTB
header before parsing, handling zero-length block declarations, ensuring
that block lengths never exceed the remaining buffer space, and verifying
that each datagram payload stays strictly within the block boundary.

Fixes: 427694cfaa ("usb: gadget: ncm: Handle decoding of multiple NTB's in unwrap call")
Fixes: 2b74b0a04d ("USB: gadget: f_ncm: add bounds checks to ncm_unwrap_ntb()")
Cc: stable <stable@kernel.org>
Assisted-by: Jetski:Gemini-2.5-Pro
Signed-off-by: Sonali Pradhan <sonalipradhan@google.com>
Link: https://patch.msgid.link/20260703083725.1903850-1-sonalipradhan@google.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
This commit is contained in:
Sonali Pradhan 2026-07-03 08:37:24 +00:00 committed by Greg Kroah-Hartman
parent f05847a216
commit 1febec7e47

View File

@ -1189,6 +1189,10 @@ static int ncm_unwrap_ntb(struct gether *port,
frame_max = ncm_opts->max_segment_size;
parse_ntb:
if (to_process < (int)opts->nth_size) {
INFO(port->func.config->cdev, "Packet too small for headers\n");
goto err;
}
tmp = (__le16 *)ntb_ptr;
/* dwSignature */
@ -1209,8 +1213,12 @@ static int ncm_unwrap_ntb(struct gether *port,
tmp++; /* skip wSequence */
block_len = get_ncm(&tmp, opts->block_length);
if (block_len == 0)
block_len = to_process;
/* (d)wBlockLength */
if ((block_len < opts->nth_size + opts->ndp_size) || (block_len > ntb_max)) {
if ((block_len < opts->nth_size + opts->ndp_size) || (block_len > ntb_max) ||
(block_len > to_process)) {
INFO(port->func.config->cdev, "Bad block length: %#X\n", block_len);
goto err;
}
@ -1273,7 +1281,7 @@ static int ncm_unwrap_ntb(struct gether *port,
index = index2;
/* wDatagramIndex[0] */
if ((index < opts->nth_size) ||
(index > block_len - opts->dpe_size)) {
(index > block_len)) {
INFO(port->func.config->cdev,
"Bad index: %#X\n", index);
goto err;
@ -1285,7 +1293,8 @@ static int ncm_unwrap_ntb(struct gether *port,
* ethernet hdr + crc or larger than max frame size
*/
if ((dg_len < 14 + crc_len) ||
(dg_len > frame_max)) {
(dg_len > frame_max) ||
(dg_len > block_len - index)) {
INFO(port->func.config->cdev,
"Bad dgram length: %#X\n", dg_len);
goto err;
@ -1310,7 +1319,7 @@ static int ncm_unwrap_ntb(struct gether *port,
dg_len2 = get_ncm(&tmp, opts->dgram_item_len);
/* wDatagramIndex[1] */
if (index2 > block_len - opts->dpe_size) {
if (index2 > block_len) {
INFO(port->func.config->cdev,
"Bad index: %#X\n", index2);
goto err;