From: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
To: pip-izony <eeodqql09@gmail.com>
Cc: "Heikki Krogerus" <heikki.krogerus@linux.intel.com>,
"Pooja Katiyar" <pooja.katiyar@intel.com>,
"Uwe Kleine-König" <u.kleine-koenig@baylibre.com>,
"Randy Dunlap" <rdunlap@infradead.org>,
"Fan Wu" <fanwu01@zju.edu.cn>, "Johan Hovold" <johan@kernel.org>,
"Ajay Gupta" <ajayg@nvidia.com>,
"Kyungtae Kim" <Kyungtae.Kim@dartmouth.edu>,
"Nathan Rebello" <nathan.c.rebello.27@dartmouth.edu>,
linux-usb@vger.kernel.org, linux-kernel@vger.kernel.org,
stable@vger.kernel.org
Subject: Re: [PATCH] usb: typec: ucsi: ccg: Validate altmode index in GET_CURRENT_CAM response
Date: Tue, 29 Sep 2026 15:33:30 +0200 [thread overview]
Message-ID: <2026092918-evolution-modulator-3a97@gregkh> (raw)
In-Reply-To: <20260928053759.533956-3-eeodqql09@gmail.com>
On Mon, Sep 28, 2026 at 01:38:01AM -0400, pip-izony wrote:
> From: Seungjin Bae <eeodqql09@gmail.com>
>
> When the PPM reports more than one DisplayPort alternate mode for a
> connector, ucsi_ccg_update_altmodes() merges them into a single entry
> in uc->updated[] and sets uc->has_multiple_dp. In that case,
> ucsi_ccg_update_get_current_cam_cmd() rewrites the response of the
> GET_CURRENT_CAM command. The response is a single byte holding the
> index of the currently active alternate mode, and it is provided by
> the PPM firmware.
>
> The function uses this byte directly as an index into uc->orig[], and
> then uses the linked_idx read from that entry as the translated index
> into uc->updated[]. Both arrays have UCSI_MAX_ALTMODES entries, but
> neither index is checked against that size.
>
> If a malicious or buggy PPM reports a value of UCSI_MAX_ALTMODES or
> larger, e.g. 0xFF, uc->orig[cam].linked_idx reads over the end of
> uc->orig[]. The byte read from there is then used as the index for
> writing cam into uc->updated[new_cam].active_idx, so the out-of-bounds
> read is followed by an out-of-bounds write. This happens without any
> userspace action, since the UCSI core issues GET_CURRENT_CAM on its own
> when handling connector changes.
>
> Fix this by ignoring responses whose index is out of range and leaving
> the original value in place. The UCSI core only uses the value as an
> index into con->port_altmode[] when it is below UCSI_MAX_ALTMODES, and
> otherwise treats it as no active alternate mode. Also check linked_idx
> before using it as an index, so that the write into uc->updated[] is
> always within bounds.
>
> Fixes: 170a6726d0e2 ("usb: typec: ucsi: add support for separate DP altmode devices")
> Cc: stable@vger.kernel.org
> Reported-by: Nathan Rebello <nathan.c.rebello.27@dartmouth.edu>
> Signed-off-by: Seungjin Bae <eeodqql09@gmail.com>
> ---
> The issue was found through code audit and was reported privately,
> so there is no public report to link to.
>
> drivers/usb/typec/ucsi/ucsi_ccg.c | 6 ++++++
> 1 file changed, 6 insertions(+)
Did you forget an Assisted-by: tag?
thanks,
greg k-h
prev parent reply other threads:[~2026-09-29 13:33 UTC|newest]
Thread overview: 3+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-28 5:38 pip-izony
2026-09-28 14:43 ` Heikki Krogerus
2026-09-29 13:33 ` Greg Kroah-Hartman [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=2026092918-evolution-modulator-3a97@gregkh \
--to=gregkh@linuxfoundation.org \
--cc=Kyungtae.Kim@dartmouth.edu \
--cc=ajayg@nvidia.com \
--cc=eeodqql09@gmail.com \
--cc=fanwu01@zju.edu.cn \
--cc=heikki.krogerus@linux.intel.com \
--cc=johan@kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-usb@vger.kernel.org \
--cc=nathan.c.rebello.27@dartmouth.edu \
--cc=pooja.katiyar@intel.com \
--cc=rdunlap@infradead.org \
--cc=stable@vger.kernel.org \
--cc=u.kleine-koenig@baylibre.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®