mirror of
https://github.com/torvalds/linux.git
synced 2026-10-05 19:34:02 +02:00
nfc: nfcmrvl: validate helper command length before pull
The firmware download receive path removes the NCI data header and
reads the helper command before validating the remaining packet length.
A short frame can therefore reach the data access before the malformed
packet is rejected.
Validate the complete helper command length before stripping the NCI
data header.
Fixes: 3194c68701 ("NFC: nfcmrvl: add firmware download support")
Signed-off-by: Pengpeng Hou <pengpeng@iscas.ac.cn>
Link: https://patch.msgid.link/20260715084325.40276-1-pengpeng@iscas.ac.cn
Signed-off-by: David Heidelberg <david@ixit.cz>
This commit is contained in:
parent
fd73f4a665
commit
686f942332
|
|
@ -263,9 +263,14 @@ static int process_state_fw_dnld(struct nfcmrvl_private *priv,
|
|||
* B8..N: payload
|
||||
*/
|
||||
|
||||
/* Remove NCI HDR */
|
||||
skb_pull(skb, 3);
|
||||
if (skb->data[0] != HELPER_CMD_PACKET_FORMAT || skb->len != 5) {
|
||||
if (skb->len != NCI_DATA_HDR_SIZE + 5) {
|
||||
nfc_err(priv->dev, "bad command");
|
||||
return -EINVAL;
|
||||
}
|
||||
|
||||
/* Remove NCI header */
|
||||
skb_pull(skb, NCI_DATA_HDR_SIZE);
|
||||
if (skb->data[0] != HELPER_CMD_PACKET_FORMAT) {
|
||||
nfc_err(priv->dev, "bad command");
|
||||
return -EINVAL;
|
||||
}
|
||||
|
|
|
|||
Loading…
Reference in New Issue
Block a user