mirror of
https://github.com/torvalds/linux.git
synced 2026-09-26 10:02:02 +02:00
nfc: llcp: fix slab-out-of-bounds reads when logging service names
nfc_llcp_wks_sap() and nfc_llcp_build_sdreq_tlv() pass non-null-
terminated strings to pr_debug() using the %s format specifier.
The buffers are allocated via kmemdup() or come from netlink
attributes and are not guaranteed to be null-terminated, causing
__dynamic_pr_debug() to read beyond the allocated region:
KASAN: slab-out-of-bounds Read in __dynamic_pr_debug
Fix both call sites by using %.*s with the explicit length to limit
the output to the actual length of the string.
Fixes: d9b8d8e19b ("NFC: llcp: Service Name Lookup netlink interface")
Reported-by: syzbot+1e3df0852e82c21ca418@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=1e3df0852e82c21ca418
Signed-off-by: Ömer Mete Kaya <omermetekaya0@gmail.com>
Link: https://patch.msgid.link/20260908161952.731468-1-omermetekaya0@gmail.com
Signed-off-by: David Heidelberg <david@ixit.cz>
This commit is contained in:
parent
408cff6bd6
commit
7dcf371a35
|
|
@ -135,7 +135,7 @@ struct nfc_llcp_sdp_tlv *nfc_llcp_build_sdreq_tlv(u8 tid, const char *uri,
|
|||
{
|
||||
struct nfc_llcp_sdp_tlv *sdreq;
|
||||
|
||||
pr_debug("uri: %s, len: %zu\n", uri, uri_len);
|
||||
pr_debug("uri: %.*s, len: %zu\n", (int)uri_len, uri, uri_len);
|
||||
|
||||
/* sdreq->tlv_len is u8, takes uri_len, + 3 for header, + 1 for NULL */
|
||||
if (WARN_ON_ONCE(uri_len > U8_MAX - 4))
|
||||
|
|
|
|||
|
|
@ -358,7 +358,7 @@ static int nfc_llcp_wks_sap(const char *service_name, size_t service_name_len)
|
|||
{
|
||||
int sap, num_wks;
|
||||
|
||||
pr_debug("%s\n", service_name);
|
||||
pr_debug("%.*s\n", (int)service_name_len, service_name);
|
||||
|
||||
if (service_name == NULL)
|
||||
return -EINVAL;
|
||||
|
|
|
|||
Loading…
Reference in New Issue
Block a user