mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH net v2] nfc: nci: fix out-of-bounds read in nci_core_reset_rsp_packet()
@ 2026-10-05 13:26 Ömer Mete Kaya
  2026-10-05 13:33 ` netdev-bot+sinfo
  0 siblings, 1 reply; 2+ messages in thread
From: Ömer Mete Kaya @ 2026-10-05 13:26 UTC (permalink / raw)
  To: oe-linux-nfc
  Cc: david, davem, edumazet, kuba, pabeni, horms, netdev,
	linux-kernel, Ömer Mete Kaya

The skb->len != 1 guard admits a 2-byte payload where config_status
at offset 2 lies one byte past skb->len.

Fix by guarding the nci_ver and config_status accesses with an explicit
skb->len >= 3 check, and restoring the original skb->len != 1 condition
around nci_req_complete() so the NCI 2.x reset request stays pending
until CORE_RESET_NTF arrives.

Fixes: bcd684aace34 ("net/nfc/nci: Support NCI 2.x initial sequence")
Signed-off-by: Ömer Mete Kaya <omermetekaya0@gmail.com>
---
Changes in v2:
  - Preserve the original skb->len != 1 condition around
    nci_req_complete() so the NCI 2.x reset request stays
    pending until CORE_RESET_NTF arrives (reported by sashiko).
  - Fix NCI version labels in comment (NCI 1.x = 3-byte RSP,
    NCI 2.x = 1-byte RSP + NTF).

 net/nfc/nci/rsp.c | 13 +++----------
 1 file changed, 3 insertions(+), 10 deletions(-)

diff --git a/net/nfc/nci/rsp.c b/net/nfc/nci/rsp.c
index e20df7fa0829..8226d09c99a5 100644
--- a/net/nfc/nci/rsp.c
+++ b/net/nfc/nci/rsp.c
@@ -32,22 +32,15 @@ static void nci_core_reset_rsp_packet(struct nci_dev *ndev,

 	pr_debug("status 0x%x\n", rsp->status);

-	/* NCI 2.x reset response carries nci_ver and config_status;
-	 * a 1-byte response is the NCI 1.x status-only form.
-	 * Require at least 3 bytes before reading those fields.
-	 */
-	if (skb->len == 1) {
-		nci_req_complete(ndev, rsp->status);
-		return;
-	}
-
+	/* NCI 1.x: 3-byte RSP; NCI 2.x: 1-byte RSP, request completed by NTF. */
 	if (skb->len >= 3 && rsp->status == NCI_STATUS_OK) {
 		ndev->nci_ver = rsp->nci_ver;
 		pr_debug("nci_ver 0x%x, config_status 0x%x\n",
 			 rsp->nci_ver, rsp->config_status);
 	}

-	nci_req_complete(ndev, rsp->status);
+	if (skb->len != 1)
+		nci_req_complete(ndev, rsp->status);
 }

 static u8 nci_core_init_rsp_packet_v1(struct nci_dev *ndev,
--
2.55.0


^ permalink raw reply	[flat|nested] 2+ messages in thread

* Re: [PATCH net v2] nfc: nci: fix out-of-bounds read in nci_core_reset_rsp_packet()
  2026-10-05 13:26 [PATCH net v2] nfc: nci: fix out-of-bounds read in nci_core_reset_rsp_packet() Ömer Mete Kaya
@ 2026-10-05 13:33 ` netdev-bot+sinfo
  0 siblings, 0 replies; 2+ messages in thread
From: netdev-bot+sinfo @ 2026-10-05 13:33 UTC (permalink / raw)
  To: Ömer Mete Kaya
  Cc: oe-linux-nfc, david, davem, edumazet, kuba, pabeni, horms,
	netdev, linux-kernel

Hi!

This is an automated message. This series looks like a fix, but its
commit messages seem to be missing some information:

 - How the issue was discovered, e.g. hit in production, hit during
   development, syzbot report, manual code inspection, LLM or static
   analysis tool scan.

 - Whether the issue was actually triggered, or is only theoretical
   (e.g. found by code inspection). If it was triggered please include
   the symptoms, like the stack trace or error messages.

Please do not repost the series just to address the above. Instead,
reply to this email with the missing information, so that reviewers
can take it into account. If the series needs another revision for
other reasons, please include the information in the commit messages
then.

The evaluation is done by an LLM so it may be wrong, if you think
that is the case please reply and explain.

^ permalink raw reply	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2026-10-05 13:33 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-10-05 13:26 [PATCH net v2] nfc: nci: fix out-of-bounds read in nci_core_reset_rsp_packet() Ömer Mete Kaya
2026-10-05 13:33 ` netdev-bot+sinfo

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®