* [PATCH net] nfc: nci: fix out-of-bounds read in nci_core_reset_rsp_packet()
@ 2026-09-30 22:47 Ömer Mete Kaya
2026-09-30 22:54 ` netdev-bot+sinfo
0 siblings, 1 reply; 2+ messages in thread
From: Ömer Mete Kaya @ 2026-09-30 22:47 UTC (permalink / raw)
To: oe-linux-nfc
Cc: david, davem, edumazet, kuba, pabeni, horms, netdev,
linux-kernel, Ömer Mete Kaya
nci_core_reset_rsp_packet() guards with skb->len != 1 before reading
rsp->nci_ver (offset 1) and rsp->config_status (offset 2), but this
admits a 2-byte payload where config_status lies one byte past skb->len.
Fix by replacing the != 1 guard with an explicit >= 3 check before
accessing those fields. The 1-byte (NCI 1.x status-only) case is
handled first with an early return so nci_req_complete() is always
called regardless of payload length. nci_valid_size() in the caller
guarantees skb->len >= 1, so a zero-length payload never reaches this
handler.
Fixes: bcd684aace34 ("net/nfc/nci: Support NCI 2.x initial sequence")
Signed-off-by: Ömer Mete Kaya <omermetekaya0@gmail.com>
---
net/nfc/nci/rsp.c | 22 ++++++++++++++--------
1 file changed, 14 insertions(+), 8 deletions(-)
diff --git a/net/nfc/nci/rsp.c b/net/nfc/nci/rsp.c
index b0ab4f5ac..e52956bf3 100644
--- a/net/nfc/nci/rsp.c
+++ b/net/nfc/nci/rsp.c
@@ -32,16 +32,22 @@ static void nci_core_reset_rsp_packet(struct nci_dev *ndev,
pr_debug("status 0x%x\n", rsp->status);
- /* Handle NCI 1.x ver */
- if (skb->len != 1) {
- if (rsp->status == NCI_STATUS_OK) {
- ndev->nci_ver = rsp->nci_ver;
- pr_debug("nci_ver 0x%x, config_status 0x%x\n",
- rsp->nci_ver, rsp->config_status);
- }
-
+ /* NCI 2.x reset response carries nci_ver and config_status;
+ * a 1-byte response is the NCI 1.x status-only form.
+ * Require at least 3 bytes before reading those fields.
+ */
+ if (skb->len == 1) {
nci_req_complete(ndev, rsp->status);
+ return;
}
+
+ if (skb->len >= 3 && rsp->status == NCI_STATUS_OK) {
+ ndev->nci_ver = rsp->nci_ver;
+ pr_debug("nci_ver 0x%x, config_status 0x%x\n",
+ rsp->nci_ver, rsp->config_status);
+ }
+
+ nci_req_complete(ndev, rsp->status);
}
static u8 nci_core_init_rsp_packet_v1(struct nci_dev *ndev,
--
2.55.0
^ permalink raw reply [flat|nested] 2+ messages in thread* Re: [PATCH net] nfc: nci: fix out-of-bounds read in nci_core_reset_rsp_packet()
2026-09-30 22:47 [PATCH net] nfc: nci: fix out-of-bounds read in nci_core_reset_rsp_packet() Ömer Mete Kaya
@ 2026-09-30 22:54 ` netdev-bot+sinfo
0 siblings, 0 replies; 2+ messages in thread
From: netdev-bot+sinfo @ 2026-09-30 22:54 UTC (permalink / raw)
To: Ömer Mete Kaya
Cc: oe-linux-nfc, david, davem, edumazet, kuba, pabeni, horms,
netdev, linux-kernel
Hi!
This is an automated message. This series looks like a fix, but its
commit messages seem to be missing some information:
- How the issue was discovered, e.g. hit in production, hit during
development, syzbot report, manual code inspection, LLM or static
analysis tool scan.
- Whether the issue was actually triggered, or is only theoretical
(e.g. found by code inspection). If it was triggered please include
the symptoms, like the stack trace or error messages.
Please do not repost the series just to address the above. Instead,
reply to this email with the missing information, so that reviewers
can take it into account. If the series needs another revision for
other reasons, please include the information in the commit messages
then.
The evaluation is done by an LLM so it may be wrong, if you think
that is the case please reply and explain.
^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2026-09-30 22:54 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-09-30 22:47 [PATCH net] nfc: nci: fix out-of-bounds read in nci_core_reset_rsp_packet() Ömer Mete Kaya
2026-09-30 22:54 ` netdev-bot+sinfo
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®