mirror of
https://github.com/torvalds/linux.git
synced 2026-10-05 02:39:02 +02:00
nfc: st21nfca: validate ISO15693 inventory length
The ISO15693 inventory helper removes a two-byte prefix without checking
that it exists, then accepts a one-byte remainder before reading data[1] as
the DSFID.
Require the prefix and at least two remaining bytes before copying the UID
data and reading the DSFID.
Fixes: 7974728094 ("NFC: st21nfca: Add ISO15693 Reader/Writer support")
Signed-off-by: Pengpeng Hou <pengpeng@iscas.ac.cn>
Link: https://patch.msgid.link/20260830132958.6397-1-pengpeng@iscas.ac.cn
Signed-off-by: David Heidelberg <david@ixit.cz>
This commit is contained in:
parent
dcab71a701
commit
7f2ea5ed58
|
|
@ -577,9 +577,7 @@ static int st21nfca_get_iso15693_inventory(struct nfc_hci_dev *hdev,
|
|||
if (r < 0)
|
||||
goto exit;
|
||||
|
||||
skb_pull(inventory_skb, 2);
|
||||
|
||||
if (inventory_skb->len == 0 ||
|
||||
if (!skb_pull(inventory_skb, 2) || inventory_skb->len < 2 ||
|
||||
inventory_skb->len > NFC_ISO15693_UID_MAXSIZE) {
|
||||
r = -EPROTO;
|
||||
goto exit;
|
||||
|
|
|
|||
Loading…
Reference in New Issue
Block a user