nfc: nfcmrvl: validate helper command length before pull

The firmware download receive path removes the NCI data header and
reads the helper command before validating the remaining packet length.
A short frame can therefore reach the data access before the malformed
packet is rejected.

Validate the complete helper command length before stripping the NCI
data header.

Fixes: 3194c68701 ("NFC: nfcmrvl: add firmware download support")
Signed-off-by: Pengpeng Hou <pengpeng@iscas.ac.cn>
Link: https://patch.msgid.link/20260715084325.40276-1-pengpeng@iscas.ac.cn
Signed-off-by: David Heidelberg <david@ixit.cz>
This commit is contained in:
Pengpeng Hou 2026-07-15 16:43:25 +08:00 committed by David Heidelberg
parent fd73f4a665
commit 686f942332
No known key found for this signature in database
GPG Key ID: 60023FC4D3492072

View File

@ -263,9 +263,14 @@ static int process_state_fw_dnld(struct nfcmrvl_private *priv,
* B8..N: payload
*/
/* Remove NCI HDR */
skb_pull(skb, 3);
if (skb->data[0] != HELPER_CMD_PACKET_FORMAT || skb->len != 5) {
if (skb->len != NCI_DATA_HDR_SIZE + 5) {
nfc_err(priv->dev, "bad command");
return -EINVAL;
}
/* Remove NCI header */
skb_pull(skb, NCI_DATA_HDR_SIZE);
if (skb->data[0] != HELPER_CMD_PACKET_FORMAT) {
nfc_err(priv->dev, "bad command");
return -EINVAL;
}