[PATCH net] nfc: llcp: guard against short PDUs in nfc_llcp_rx_skb()

Doruk Tan Ozturk posted 1 patch 2 weeks ago
net/nfc/llcp_core.c | 3 +++
1 file changed, 3 insertions(+)
[PATCH net] nfc: llcp: guard against short PDUs in nfc_llcp_rx_skb()
Posted by Doruk Tan Ozturk 2 weeks ago
nfc_llcp_recv_connect() and nfc_llcp_recv_cc() pass
skb->len - LLCP_HEADER_SIZE to nfc_llcp_parse_connection_tlv() as a
size_t. When skb->len < LLCP_HEADER_SIZE the subtraction wraps around
to a huge value and the TLV walk runs past the skb.

nfc_llcp_rx_skb() applied no minimum-length check before dispatching,
so a PDU shorter than the 2-byte LLCP header reached these call sites.
Drop such PDUs up front; every LLCP PDU carries the header, so no valid
frame is shorter (a SYMM PDU is exactly LLCP_HEADER_SIZE bytes).

Found by 0sec (https://0sec.ai) using automated source analysis.

Fixes: d646960f7986 ("NFC: Initial LLCP support")
Cc: stable@vger.kernel.org
Assisted-by: 0sec:claude-opus-4-8
Signed-off-by: Doruk Tan Ozturk <doruk@0sec.ai>
---
 net/nfc/llcp_core.c | 3 +++
 1 file changed, 3 insertions(+)

diff --git a/net/nfc/llcp_core.c b/net/nfc/llcp_core.c
index aed5fe1afef0..e3b3077e0e83 100644
--- a/net/nfc/llcp_core.c
+++ b/net/nfc/llcp_core.c
@@ -1481,6 +1481,9 @@ static void nfc_llcp_rx_skb(struct nfc_llcp_local *local, struct sk_buff *skb)
 {
 	u8 dsap, ssap, ptype;
 
+	if (skb->len < LLCP_HEADER_SIZE)
+		return;
+
 	ptype = nfc_llcp_ptype(skb);
 	dsap = nfc_llcp_dsap(skb);
 	ssap = nfc_llcp_ssap(skb);
-- 
2.43.0
Re: [PATCH net] nfc: llcp: guard against short PDUs in nfc_llcp_rx_skb()
Posted by Doruk Tan Ozturk 2 weeks ago
Hi David,

Sorry, two copies of this went out by mistake. Please take the earlier
"reject PDUs shorter than the LLCP header" and disregard the
near-identical "guard against short PDUs in nfc_llcp_rx_skb()" that
followed. Same one-line fix.

Doruk