From nobody Mon Jun 15 21:42:08 2026 Received: from mail-pj1-f50.google.com (mail-pj1-f50.google.com [209.85.216.50]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id E7C911DF27D for ; Tue, 14 Apr 2026 01:07:59 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.216.50 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1776128881; cv=none; b=kBOVYMrsBmlwkQ33epBlkcRvk8PmOKN3buG4dwtWOYcN5s0e0942T/iudAyL6hqH1lVaP0UUv7EMd67Yi/1wKM+rviKzI1DWAaXDDxsPlITy4U4ZnWKaojCJXU83NJ/Xtsi44P2SF2S2BIOovG1LKISnS1AhNiA2kWd8LZZrNno= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1776128881; c=relaxed/simple; bh=X2stRK6BzVJ6STaMrFyFvTkg+1K5bRk267jpYZn6laQ=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=inJ72DvaGrHfSmLCnY3OqsVDgVqncYO8sweX1WcnwgUUnBjEpY22HsWOmALrszrYZ679p/lWqqmcf+zzVz9RjCS/W8yhvoorPy6LR5BCC9kSTinFwrF2nFpFD3wZHcjLGSwWnrVC3IOvHK0VhftEan4MfAYCFkSF8oJxQQdabAI= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=sKV8UhPC; arc=none smtp.client-ip=209.85.216.50 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="sKV8UhPC" Received: by mail-pj1-f50.google.com with SMTP id 98e67ed59e1d1-35fb7c1a455so631444a91.3 for ; Mon, 13 Apr 2026 18:07:59 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1776128879; x=1776733679; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to; bh=fSOBQXbJwd+/LjKElFzLkgeeqFY61/pHJa45E1A6Tmg=; b=sKV8UhPCKDYiWb+MK/iqayWPNp8aFtJ9CZdpaOkkSgrcHmTb4qkDul+qcEsSwIz7Ie NKS6mZ1NsLHDe1zNVaRsFq4uj92imNi/uWTnA9fB9Xz8jG4q0qr0JsHUQivQ7qy0GB0/ k3Y0hb9G2u4DtWbGh88vL16SHByx7O6J6ZYCXj7UvXarG5d2+r5op5h0QWtla1fUHawg wNyXc5OMmGT6LjaY+BH2RjucpWQpFn8Y5GlsWx8cEuazAokhD8oEnNteHmMbvpMGeZK3 r6yf/oGYkxupRS9P+eKk4qGTnnyu4MZ5XOB4GcAEVyt7nupfA8ciBP17oH4gyOuwJ/ER afDQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1776128879; x=1776733679; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to; bh=fSOBQXbJwd+/LjKElFzLkgeeqFY61/pHJa45E1A6Tmg=; b=YNd6Gcbw+eVGZyQmC/rLS/YgAJ0q0pX88I3DALyly0rXdrD0xSo6bgaYKnwKnzN1gp 83oyosQisJqOrX39nLngkNDNoLz32IhavBnCUGN9hNnR3DHZ02MNerIfmcr7DLFmUPAW exYn6WGS7Lf79St832Hk14jPOR7cSj5ifTzTJLtvs0IoTi1L3o+KRYSYm0xuwh8wEllu ou5zdNAzINdipbHGW8TxkY3v8iNxW71jGvmDjTzbvjcBQrKqSUko0m8uSNsePZxc70DM g05nOK3034SG19K2SDFKsZEH5gGXgUIUCiDLCLVaybUXoeH2V9Wpqa0tDEARfVCxQQqK vS9A== X-Forwarded-Encrypted: i=1; AFNElJ+TMpQ6jbpWeyfdh0o8Nrbo8mpkrauwin6nY/zZ996DtpqR9TpIvb2gORFNn/dWmLRCyqHwKMRbjyispdE=@vger.kernel.org X-Gm-Message-State: AOJu0YygWv6fGn+0Mk6HVgSRerKzMPJcQx+aZJY/3uqTuSBKdyT30qLD 2cRGPVxx85RuTFEz/5Pe7vSS6vnpLzfwF4H3db4f2DRHXreacpWtWIeW X-Gm-Gg: AeBDievQyRcRFxuQdHdzEn7GNqHCMM71YdRC9BVr2FHfOlMjl1dlKJa8uIjUTK/Jg1x NG2nx67qoAAany3fqq8KruRRNMB4P4Yu/RpksCOMJdbW+SrVh1yuxxN+S8rbj/bxxIDbWYU9K4L nAhXwObkc7jlhHYiyCkQ3fXs50plgBnnekRpsPyhXq2O2/JagofTudVeth7WvE8f5KXuWvSG40C ZRhm0LI+fI0GQ06pIhSIFm76tBxPLjTxaKKIl0PGLzmhHEi4zFRuCKj2Nw9xV2rPZegsjrtf29L VGhz6dSc8SShwGamH0vdkCUUfVD2s71PpIp4sk3z50/onjpieu/BqWSBMWQ4vBU0NZasqSpaO2Y yWqaDhAASst7Q2GEldUoz8P/w+OcYfdq4tUIp460VjKFx0v++cLwgXJ/PVqODdRc3/A0SKz5+Df fAmbi15gKutaijt41gi2lH2RAJyB9eZaaSIdATiEPk4vJvWfQ= X-Received: by 2002:a17:90b:5292:b0:35c:29ba:bf92 with SMTP id 98e67ed59e1d1-35e4278b94bmr16069292a91.5.1776128879162; Mon, 13 Apr 2026 18:07:59 -0700 (PDT) Received: from fedora ([61.74.238.173]) by smtp.gmail.com with ESMTPSA id 98e67ed59e1d1-35fc6eabb29sm222009a91.6.2026.04.13.18.07.56 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 13 Apr 2026 18:07:58 -0700 (PDT) From: SeungJu Cheon To: linux-bluetooth@vger.kernel.org Cc: marcel@holtmann.org, luiz.dentz@gmail.com, pmenzel@molgen.mpg.de, kees@kernel.org, kuba@kernel.org, me@brighamcampbell.com, skhan@linuxfoundation.org, linux-kernel-mentees@lists.linux.dev, linux-kernel@vger.kernel.org, SeungJu Cheon Subject: [PATCH v2] Bluetooth: RFCOMM: validate skb length in MCC handlers Date: Tue, 14 Apr 2026 10:07:41 +0900 Message-ID: <20260414010741.233892-1-suunj1331@gmail.com> X-Mailer: git-send-email 2.52.0 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" The RFCOMM MCC handlers cast skb->data to various protocol structs without validating skb->len first. A malicious remote device can send short MCC frames to trigger out-of-bounds reads in these handlers. Fix this by using skb_pull_data() to safely validate and access the required data in each handler. Return -EINVAL if the skb does not contain enough data. rfcomm_recv_rpn() requires special handling since 1-byte RPN requests are valid per ETSI TS 07.10. Handle this by first pulling a single byte for the DLCI field, and only validating the full struct when len > 1. Also add a length check in rfcomm_recv_mcc() before accessing the MCC header fields. Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2") Signed-off-by: SeungJu Cheon --- v2: - Use skb_pull_data() instead of manual length checks (Luiz) - Add a length check in rfcomm_recv_mcc() before accessing the MCC header= (Paul) - Allow 1-byte RPN requests in rfcomm_recv_rpn() as per ETSI TS 07.10 (Pa= ul) --- net/bluetooth/rfcomm/core.c | 66 ++++++++++++++++++++++++++++--------- 1 file changed, 50 insertions(+), 16 deletions(-) diff --git a/net/bluetooth/rfcomm/core.c b/net/bluetooth/rfcomm/core.c index 611a9a94151e..a2dfbff816d3 100644 --- a/net/bluetooth/rfcomm/core.c +++ b/net/bluetooth/rfcomm/core.c @@ -1431,10 +1431,15 @@ static int rfcomm_apply_pn(struct rfcomm_dlc *d, in= t cr, struct rfcomm_pn *pn) =20 static int rfcomm_recv_pn(struct rfcomm_session *s, int cr, struct sk_buff= *skb) { - struct rfcomm_pn *pn =3D (void *) skb->data; + struct rfcomm_pn *pn; struct rfcomm_dlc *d; - u8 dlci =3D pn->dlci; + u8 dlci; + + pn =3D skb_pull_data(skb, sizeof(*pn)); + if (!pn) + return -EINVAL; =20 + dlci =3D pn->dlci; BT_DBG("session %p state %ld dlci %d", s, s->state, dlci); =20 if (!dlci) @@ -1483,8 +1488,8 @@ static int rfcomm_recv_pn(struct rfcomm_session *s, i= nt cr, struct sk_buff *skb) =20 static int rfcomm_recv_rpn(struct rfcomm_session *s, int cr, int len, stru= ct sk_buff *skb) { - struct rfcomm_rpn *rpn =3D (void *) skb->data; - u8 dlci =3D __get_dlci(rpn->dlci); + struct rfcomm_rpn *rpn; + u8 dlci; =20 u8 bit_rate =3D 0; u8 data_bits =3D 0; @@ -1495,15 +1500,16 @@ static int rfcomm_recv_rpn(struct rfcomm_session *s= , int cr, int len, struct sk_ u8 xoff_char =3D 0; u16 rpn_mask =3D RFCOMM_RPN_PM_ALL; =20 - BT_DBG("dlci %d cr %d len 0x%x bitr 0x%x line 0x%x flow 0x%x xonc 0x%x xo= ffc 0x%x pm 0x%x", - dlci, cr, len, rpn->bit_rate, rpn->line_settings, rpn->flow_ctrl, - rpn->xon_char, rpn->xoff_char, rpn->param_mask); + if (len =3D=3D 1) { + rpn =3D skb_pull_data(skb, 1); + if (!rpn) + return -EINVAL; =20 - if (!cr) - return 0; + dlci =3D __get_dlci(rpn->dlci); + + if (!cr) + return 0; =20 - if (len =3D=3D 1) { - /* This is a request, return default (according to ETSI TS 07.10) settin= gs */ bit_rate =3D RFCOMM_RPN_BR_9600; data_bits =3D RFCOMM_RPN_DATA_8; stop_bits =3D RFCOMM_RPN_STOP_1; @@ -1514,6 +1520,19 @@ static int rfcomm_recv_rpn(struct rfcomm_session *s,= int cr, int len, struct sk_ goto rpn_out; } =20 + rpn =3D skb_pull_data(skb, sizeof(*rpn)); + if (!rpn) + return -EINVAL; + + dlci =3D __get_dlci(rpn->dlci); + + BT_DBG("dlci %d cr %d len 0x%x bitr 0x%x line 0x%x flow 0x%x xonc 0x%x xo= ffc 0x%x pm 0x%x", + dlci, cr, len, rpn->bit_rate, rpn->line_settings, rpn->flow_ctrl, + rpn->xon_char, rpn->xoff_char, rpn->param_mask); + + if (!cr) + return 0; + /* Check for sane values, ignore/accept bit_rate, 8 bits, 1 stop bit, * no parity, no flow control lines, normal XON/XOFF chars */ =20 @@ -1589,9 +1608,14 @@ static int rfcomm_recv_rpn(struct rfcomm_session *s,= int cr, int len, struct sk_ =20 static int rfcomm_recv_rls(struct rfcomm_session *s, int cr, struct sk_buf= f *skb) { - struct rfcomm_rls *rls =3D (void *) skb->data; - u8 dlci =3D __get_dlci(rls->dlci); + struct rfcomm_rls *rls; + u8 dlci; + + rls =3D skb_pull_data(skb, sizeof(*rls)); + if (!rls) + return -EINVAL; =20 + dlci =3D __get_dlci(rls->dlci); BT_DBG("dlci %d cr %d status 0x%x", dlci, cr, rls->status); =20 if (!cr) @@ -1608,10 +1632,15 @@ static int rfcomm_recv_rls(struct rfcomm_session *s= , int cr, struct sk_buff *skb =20 static int rfcomm_recv_msc(struct rfcomm_session *s, int cr, struct sk_buf= f *skb) { - struct rfcomm_msc *msc =3D (void *) skb->data; + struct rfcomm_msc *msc; struct rfcomm_dlc *d; - u8 dlci =3D __get_dlci(msc->dlci); + u8 dlci; + + msc =3D skb_pull_data(skb, sizeof(*msc)); + if (!msc) + return -EINVAL; =20 + dlci =3D __get_dlci(msc->dlci); BT_DBG("dlci %d cr %d v24 0x%x", dlci, cr, msc->v24_sig); =20 d =3D rfcomm_dlc_get(s, dlci); @@ -1644,9 +1673,14 @@ static int rfcomm_recv_msc(struct rfcomm_session *s,= int cr, struct sk_buff *skb =20 static int rfcomm_recv_mcc(struct rfcomm_session *s, struct sk_buff *skb) { - struct rfcomm_mcc *mcc =3D (void *) skb->data; + struct rfcomm_mcc *mcc; u8 type, cr, len; =20 + if (skb->len < sizeof(*mcc)) + return -EINVAL; + + mcc =3D (void *) skb->data; + cr =3D __test_cr(mcc->type); type =3D __get_mcc_type(mcc->type); len =3D __get_mcc_len(mcc->len); --=20 2.52.0