From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.129.124]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id D97B03AE6FA for ; Tue, 28 Apr 2026 13:46:35 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=170.10.129.124 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1777383997; cv=none; b=nETvKMwKQ/jhHK0sBOKoscB4ErF42Ge83m8oueCaBTxRDWspPfCrswtpCnL2aMzmiGWJOVezxF4vc07ugLSObV97yQINSiprqvS9JM3yYp/XVxtWR/nBiqR15r8r8fcmyJaAszvvXeoAXfB5+DK+s8IjKJdBJRih9/liKqRUIpQ= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1777383997; c=relaxed/simple; bh=ISx7idAXFVml7pFBtXS5rUkfsRUGFlW6Ayw82sBvLBw=; h=Message-ID:Date:MIME-Version:Subject:To:Cc:References:From: In-Reply-To:Content-Type; b=EGzTSWTSy2wgYJctoSpkUpQzKC1jV96gn4pGZJ9Wkp7tW7Wdxod/WKhokO8Rbq7JRn0j3c0l6mY8GCSL7QIxEVfwRvoKwPnxev+0rwLeTCBulTl1s9+Bi1q/ilknbhVGjw2yyYaJ0Va5ZguHGPNcbXFMypqwI7+oZdX8IBOKO/w= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com; spf=pass smtp.mailfrom=redhat.com; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b=FjCa111d; dkim=pass (2048-bit key) header.d=redhat.com header.i=@redhat.com header.b=NgBl7ncg; arc=none smtp.client-ip=170.10.129.124 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=redhat.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b="FjCa111d"; dkim=pass (2048-bit key) header.d=redhat.com header.i=@redhat.com header.b="NgBl7ncg" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1777383994; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=/HxwQoc27jCWUPEYETiGXOCCxkg0A85sch0NHG8e6eE=; b=FjCa111dQKqUCRxKL/OIH0v4B/4sksYNNESo9vTd5JfdQzjByb7XnAydddkgyB4pov0cL/ kGm2WzmwySXAYjbw3TEbzaDc2evudLPdNssPRCImhGfN06CtkabC4H8hVIC/UlEiHf9JGn tHPyKtOV7DVU2iT0vCDSikScre5fK80= Received: from mail-wm1-f71.google.com (mail-wm1-f71.google.com [209.85.128.71]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-553-Bc2e_19jMO6ZmCZKBtJPUA-1; Tue, 28 Apr 2026 09:46:30 -0400 X-MC-Unique: Bc2e_19jMO6ZmCZKBtJPUA-1 X-Mimecast-MFC-AGG-ID: Bc2e_19jMO6ZmCZKBtJPUA_1777383990 Received: by mail-wm1-f71.google.com with SMTP id 5b1f17b1804b1-488c2a4e257so87897645e9.3 for ; Tue, 28 Apr 2026 06:46:30 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=google; t=1777383989; x=1777988789; darn=vger.kernel.org; h=content-transfer-encoding:in-reply-to:from:content-language :references:cc:to:subject:user-agent:mime-version:date:message-id :from:to:cc:subject:date:message-id:reply-to; bh=/HxwQoc27jCWUPEYETiGXOCCxkg0A85sch0NHG8e6eE=; b=NgBl7ncgAo52Z0zFZIja2GJqL/3tGHQyRKJfhsObsO/68NE8ZhbTH8N8ZiLSbSTB+H HvV6GNTLJGeT4olyuRcR9qp2tnzV31qpvazzFgUgzullGeirxOeBzA9REvf9/eZZ4Yxu ELxHsuedeeLWxiWYwy67R42HnWXUa+ccdjHynCe18AhPXNKr8puWPjyrdtq2+SP/qvKe CRXoMki42QSQgufUd+xJm5Sh25jJpSJL7QgLXGrZtqur0P2taH+TUNubP4R6IdSWty6m LqeZ9qZMS2ebgNChQCk5YLmzxoUdXulGcJKWNAzpUZjlHRf/zY5cLLlTT/c4XASKQi85 4hLw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1777383989; x=1777988789; h=content-transfer-encoding:in-reply-to:from:content-language :references:cc:to:subject:user-agent:mime-version:date:message-id :x-gm-gg:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to; bh=/HxwQoc27jCWUPEYETiGXOCCxkg0A85sch0NHG8e6eE=; b=FDQvq++PZBnM2aGHW/au5fZcaDMieRIvU5rW2PybC17w0jYlQO6ZTwz8I8WVFR8VMN oR2Njq/pa30DdccST380kThxe2Mr0ANDYqOJJtHCsTC4RiQtn0GmJTGR2aLvH7Fn65u5 ous6ycNr/uCHVQxkPebTOL/BfUSHbxTcFadDzn3Lihr+7LNKOyGUpTm2c9gHhoMO8X/a wlf4bqqVO4yL+zCu/ooNhHFFS/Djgj+3B8TEK9vxGFSBHl5cjsUukyJF1wjdszbmlfiW XGxBk8iGGV2sulylEy/bzjyNeWKvER+4k1bhm14JL1CJajmnns8O4hz5Cf3ffTLfUnc+ Y8rw== X-Forwarded-Encrypted: i=1; AFNElJ9BgMp+z/vQTPUh/ruVZ5/ZHzI8JjWI4auU6R95RyGVm7lO6wUyKodx/yBfRLkEeXAM+mnpiuOWGcAEvGM=@vger.kernel.org X-Gm-Message-State: AOJu0YwcMRSN0z8m2F1I1tZ/NZzdVxweapgYQvRHS7FOmmxZZA6N8uo0 NSScsMnxgD0fgnaAvI1+vqk3DdNzbWR3YnpnJFxaAcrEOKGGV+6awkzTmSGmTyiwy25UglwXuMc v2NA97AJzSWY7Ty4u4ceiJUQ7kPvp0AM+zFz2XfxErXobvfGdukfceCcXEBrpf/tIXw== X-Gm-Gg: AeBDieunAsW0AThjjZui4Zyijr8RJrcU1ylwAwDloVggkpsOezDxk3jjE+rMJv1o3zM z5ebQyqM09/YvKQ9GWIyi8PpONV4u0nVuqooRLmZITT/+uU0SPP8v2B0NEt5DfYO6qLsnk11ujY yfjiRjS8V6kb0wEcYMl+X8eTLGX1eT0uW5Fq+shrWFoYJCWlx6RPqrkzjUqsYgj6FMFX+ZndZjE MyEzcq/d5IYzZkCKS8BjI+uT28rpZXxN3GKpwcKdat8UAT8uQ6YXDKfXm7JWesz56HC9U9t8465 JUnYdefL/Z3styvQqw+PiB5i4BgE2vRSq6d8WuHJY+rZiSeBdaVBevAwlQiRC2/pNucRGfBualq /a9FkKN38ZiGL6vlHkXVeu4/hWanAmn16GT/f6O/aGJ5ct2BPYI6nNeaXUHYYi4lJkg== X-Received: by 2002:a05:600c:1d0a:b0:48a:5342:36b5 with SMTP id 5b1f17b1804b1-48a77b1e8b0mr53199195e9.21.1777383989446; Tue, 28 Apr 2026 06:46:29 -0700 (PDT) X-Received: by 2002:a05:600c:1d0a:b0:48a:5342:36b5 with SMTP id 5b1f17b1804b1-48a77b1e8b0mr53198675e9.21.1777383988888; Tue, 28 Apr 2026 06:46:28 -0700 (PDT) Received: from [192.168.88.32] ([216.128.9.114]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-48a773a870asm64053465e9.1.2026.04.28.06.46.27 (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Tue, 28 Apr 2026 06:46:28 -0700 (PDT) Message-ID: <3f34146d-f719-4a65-8906-4fc08bc91c22@redhat.com> Date: Tue, 28 Apr 2026 15:46:26 +0200 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 User-Agent: Mozilla Thunderbird Subject: Re: [PATCH net v4 0/5] nfc: fix multiple OOB reads in NCI and LLCP parsing paths To: Simon Horman , =?UTF-8?B?TGVrw6sgSGFww6dpdQ==?= Cc: netdev@vger.kernel.org, davem@davemloft.net, edumazet@google.com, kuba@kernel.org, krzk@kernel.org, linux-kernel@vger.kernel.org, stable@vger.kernel.org, David Heidelberg References: <20260424180151.3808557-1-snowwlake@icloud.com> <20260428125523.GQ900403@horms.kernel.org> Content-Language: en-US From: Paolo Abeni In-Reply-To: <20260428125523.GQ900403@horms.kernel.org> Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit On 4/28/26 2:55 PM, Simon Horman wrote: > On Fri, Apr 24, 2026 at 08:01:46PM +0200, Lekë Hapçiu wrote: >> This series fixes five out-of-bounds / underflow bugs in the kernel NFC >> stack. All are reachable from a remote NFC peer that the local stack >> has already associated with; in the LLCP cases the peer only needs to >> send a malformed frame. >> >> 1/5 nci: u8 underflow in nci_store_general_bytes_nfc_dep() lets the >> attacker-controlled atr_res_len skip the GT-offset subtraction >> and cause an OOB read/write against general_bytes[]. >> 2/5 llcp: parse_gb_tlv() / parse_connection_tlv() trust the TLV >> length byte without checking remaining buffer, and the tlv16 >> accessors read past the end when length < 2. >> 3/5 llcp: nfc_llcp_recv_snl() has the same TLV-length trust bug, and >> its SDRES handler uses an unbounded "%.16s" pr_debug() that >> walks past service_name_len. >> 4/5 llcp: nfc_llcp_recv_dm() reads skb->data[3] without checking >> skb->len, giving a 1-byte heap OOB read. >> 5/5 llcp: nfc_llcp_connect_sn() walks the TLV array with no length >> validation; a crafted CONNECT frame drops it into OOB reads / >> an unbounded service-name pointer. >> >> The series applies on top of net/main. >> >> Lekë Hapçiu (5): >> nfc: nci: fix u8 underflow in nci_store_general_bytes_nfc_dep >> nfc: llcp: fix TLV parsing in parse_gb_tlv and parse_connection_tlv >> nfc: llcp: fix TLV parsing OOB in nfc_llcp_recv_snl >> nfc: llcp: fix OOB read of DM reason byte in nfc_llcp_recv_dm >> nfc: llcp: fix TLV parsing OOB in nfc_llcp_connect_sn > > Hi, > > My only feedback on v4 of this patchset is that somehow the > threading is broken: each of patch 1/5 - 5/5 should be a reply > to the cover letter - 0/5 - but that does not seem to be the case. > And some tooling, notably Sashiko, seems to rely on the > entire patchset being contained in a single email thread. Given the above, I suggest re-posting. Also note that we are moving NFC to a specific subtree, see: https://lore.kernel.org/netdev/938496c6-84c1-4d53-bb56-73bbd7b2bdd7@ixit.cz/ please wait a bit for resubmission, possibly David will be already ready to catch them. Thanks, Paolo