From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-pj1-f44.google.com (mail-pj1-f44.google.com [209.85.216.44]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id DC6E53EFFA1 for ; Thu, 2 Jul 2026 08:51:35 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.216.44 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1782982297; cv=none; b=ZGh/Ngh2uPoZJ6JD3268hWjiPNae/tM5RYfBwBP+OxlgbiLXoBxE6eI+ImsIkC+YRoZKgHsMsAO5DgnZhmySZZutIQRRjVI5ZVxzlEnJC8ndlf0Ryxri0F1OJS+MMiSngTMJqyjnG6S4btZUv/TwlGHzn0jHzu0FZ7oYKZBeUmU= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1782982297; c=relaxed/simple; bh=qe4m9kw473joCvnL0Oc6jS1LxFslgCQn3adScesdl7w=; h=From:To:Subject:Date:Message-ID:Content-Type:MIME-Version; b=LAMrEabxqcdTmPlEG6dAgAjk6tNaOfxn9lVA87H8HL9iP7V7cqg5Mbz7rS/uwTdh5AZT3PsmhDXqKx+yIgfz3dkHt+FBl3GWA9oRSe0m7d5lgP0gQulsNxDgfGv8NymTqaWsYuPhDMLtbhjTkcVW/CVXPN6DK4p2tIdoJ4uclu0= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=bugqore.com; spf=fail smtp.mailfrom=bugqore.com; dkim=pass (2048-bit key) header.d=bugqore.com header.i=@bugqore.com header.b=MVzKtVTS; arc=none smtp.client-ip=209.85.216.44 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=bugqore.com Authentication-Results: smtp.subspace.kernel.org; spf=fail smtp.mailfrom=bugqore.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=bugqore.com header.i=@bugqore.com header.b="MVzKtVTS" Received: by mail-pj1-f44.google.com with SMTP id 98e67ed59e1d1-37dedd62b90so380939a91.1 for ; Thu, 02 Jul 2026 01:51:35 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=bugqore.com; s=google; t=1782982295; x=1783587095; darn=vger.kernel.org; h=mime-version:content-transfer-encoding:message-id:date:subject:to :from:from:to:cc:subject:date:message-id:reply-to; bh=lpc6rDqUvlrWZnj4WgyBFP5lyh/r6mU5D1MSCDuEM/k=; b=MVzKtVTScNDUkywUAm8D/gy7NiCiv948lVBJzsK6YayXHUWRVw9+/j9LbZdQtDlgzZ Taan6zJ7cGSKvL9vcorZHacnttVln3iD0L4OkRDFZABSlmEXYurbh8ROTnVbkUbBx/4h rrV8600Nf0pORPXPmHht1xQIYXp8AuosJ1BJ3m7hluFH4KBRtn/5+81KcyRMcQloP12b kh0P+8Cmuj3xP15qnQ+2Tv3kXpYX29KrWRzy8ezinayOznAA8gBzJTqfRTWbGprOV7Fu 2pdsiaIyvc62hWmSKMO206I6OnA/jCAwIT917uvYbJhq3Ek8KWXNixz2k05uCBTXNDFT iy8A== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1782982295; x=1783587095; h=mime-version:content-transfer-encoding:message-id:date:subject:to :from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to; bh=lpc6rDqUvlrWZnj4WgyBFP5lyh/r6mU5D1MSCDuEM/k=; b=mf8FpHYIXZWItcZ9XWRusmXI1DrdPwHaEvd2Kv/B9iPl8TTJYFgHGvAciR1Icn7jcE Z4P0SeTS4pARczOca+jA+oMyJpYMqLuoMryhbcyGbIlXawhP4VscVsCXpo5F8wp+vRVw 2r1365PBvJMaUYKgjyhj4J9BXnzDuln+9+GpVqnKoGCVY/RwqmhEWHeZ+NF7LHJOjJFz VYAj6oKKzG4EFMPSDOLnSimmxwkouDzlKGavwlNgO1U5vrczbn0XowA5fzS8AuYg0A9R cFYRlXlqHnUwTieueWI2lpenFF/1VBaSTqCZhG/QAjTVwy7Bwmy/EXBfeTiEJKXVJEVn lJwQ== X-Gm-Message-State: AOJu0YzF50vxE2zMSkOsXpKSVYoxyvDkcnLEoaKAyadH3XgrMzbv+D8Q n2Sz+V7XNzAt+fBek5trLyWTspCW8mxYSsCXLoC+6jypxPS8QcU+4SsMEjzbtI7XRoplzNymjmy Ewy/uyFsWCf8Oqw== X-Gm-Gg: AfdE7ckIhiUKd0WCwwZSYjrepRRQB8an6ev/ZyXlb0pLKfd/TUIaE06B+i97Da1X4BX XCGFzx1I/rvHpQA6Sb7PYqyjaCx3Rt8l+Ktf/SetHYsDGTKjIpnJCYw/8DLz0SE126V5bgwEk6i xdRGO5Jj+5N/j53tWtNh29I+rKkbYuCcQPrHngQVmzJLHqrhIm6ixd96sPSizuytBLGBmWuPF7n 3YK8ULek4riH+rQIu11HvuqDTQKuwGhiGWX7Y+Blsdu/H0nBAM1teUZFBwgSzd7tGt7m3UCNXtk S72Yd3CnHs78aQpXvqkGpox+R62ezTstcGXhCRNtQHvFssS1mZFYWucpDrMErf5UntlepvUZOJF JH82u6xjXwjDJ13+Q7UW1M1byIsDzI85rMC24LcvDjxcVwxRQlT1HKHQRBgXGjMDD+JzKenTjps dsVPmmEklVe22+plpYqYW8MIXknfkvz+MPEaA= X-Received: by 2002:a17:90a:d44c:b0:380:9052:f4b9 with SMTP id 98e67ed59e1d1-3809052f69cmr7707108a91.11.1782982294586; Thu, 02 Jul 2026 01:51:34 -0700 (PDT) Received: from 9.1.168.192.in-addr.arpa ([2401:4900:1c06:e91:8cec:28c1:f05:4982]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-30f0b816a42sm12055489eec.9.2026.07.02.01.51.33 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 02 Jul 2026 01:51:34 -0700 (PDT) From: Syed Abdul Khaliq To: linux-kernel@vger.kernel.org Subject: [PATCH] nfc: llcp: validate TLV length to prevent out-of-bounds read Date: Thu, 02 Jul 2026 14:21:31 +0530 Message-ID: <178298229140.44037.18255999514826696970@bugqore.com> X-CodeOps-Marker: ef6b2194a9604771acac7688ad3a8ce6 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: 8bit Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 nfc_llcp_parse_gb_tlv() and nfc_llcp_parse_connection_tlv() walk a TLV array taken from an LLCP PDU received from a remote peer. The loop is bounded only by "offset < tlv_array_len", so it reads the length byte tlv[1] and, via llcp_tlv8()/llcp_tlv16(), the value bytes tlv[2] and tlv[3] without checking that the full TLV (2 + length bytes) actually fits inside the array. A truncated or malformed TLV therefore triggers an out-of-bounds read of the received skb data. For example a CONNECT PDU whose payload after the 2-byte LLCP header is a single MIUX type byte gives tlv_array_len == 1: tlv[1] is read one byte past the buffer, and the MIUX handler goes on to read tlv[2]/tlv[3] via llcp_tlv16(). A TLV whose length field runs past the end of the array makes the following iteration dereference tlv well beyond the buffer. nfc_llcp_parse_connection_tlv() parses the data directly out of the received skb (net/nfc/llcp_core.c), so the read runs off the end of the slab allocation. Reject any TLV that does not fully fit in the remaining array before reading its length and value. Signed-off-by: Syed Abdul Khaliq --- diff --git a/net/nfc/llcp_commands.c b/net/nfc/llcp_commands.c index 291f26facb..4e22788f95 100644 --- a/net/nfc/llcp_commands.c +++ b/net/nfc/llcp_commands.c @@ -201,6 +201,13 @@ int nfc_llcp_parse_gb_tlv(struct nfc_llcp_local *local, return -ENODEV; while (offset < tlv_array_len) { + if (tlv_array_len - offset < 2 || + tlv[1] > tlv_array_len - offset - 2) { + pr_err("Malformed TLV, offset %d array length %d\n", + offset, tlv_array_len); + return -EINVAL; + } + type = tlv[0]; length = tlv[1]; @@ -251,6 +258,13 @@ int nfc_llcp_parse_connection_tlv(struct nfc_llcp_sock *sock, return -ENOTCONN; while (offset < tlv_array_len) { + if (tlv_array_len - offset < 2 || + tlv[1] > tlv_array_len - offset - 2) { + pr_err("Malformed TLV, offset %d array length %d\n", + offset, tlv_array_len); + return -EINVAL; + } + type = tlv[0]; length = tlv[1]; -- 2.50.1 (Apple Git-155)