mirror of
https://github.com/torvalds/linux.git
synced 2026-09-26 10:02:02 +02:00
nfc: pn533: fix OOB read in pn533_acr122_is_rx_frame_valid()
frame->ccid.datalen is read directly from the USB response frame
and used, unchecked, as an index into frame->data[]. A malicious or
malfunctioning device can set this field to an arbitrary value,
causing the driver to read far outside the received buffer.
Bound ccid.datalen against the maximum possible ACR122 frame size
before using it. This replaces the existing datalen == 0 check,
since datalen < 2 already covers that case and additionally
rejects datalen == 1, which would still underflow the
"datalen - 2" offset used below.
Fixes: 9815c7cf22 ("NFC: pn533: Separate physical layer from the core implementation")
Reported-by: syzbot+1853daab1a47603d4678@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=1853daab1a47603d4678
Tested-by: syzbot+1853daab1a47603d4678@syzkaller.appspotmail.com
Assisted-by: LLM
Signed-off-by: Deepanshu Kartikey <kartikey406@gmail.com>
Link: https://patch.msgid.link/20260923035627.6210-1-kartikey406@gmail.com
Signed-off-by: David Heidelberg <david@ixit.cz>
This commit is contained in:
parent
7dcf371a35
commit
b61732f473
|
|
@ -319,7 +319,9 @@ static bool pn533_acr122_is_rx_frame_valid(void *_frame, struct pn533 *dev)
|
|||
if (frame->ccid.type != 0x83)
|
||||
return false;
|
||||
|
||||
if (!frame->ccid.datalen)
|
||||
if (frame->ccid.datalen < 2 ||
|
||||
frame->ccid.datalen > PN533_ACR122_FRAME_MAX_PAYLOAD_LEN +
|
||||
PN533_ACR122_RX_FRAME_TAIL_LEN)
|
||||
return false;
|
||||
|
||||
if (frame->data[frame->ccid.datalen - 2] == 0x63)
|
||||
|
|
|
|||
Loading…
Reference in New Issue
Block a user