From nobody Sat Jul 25 23:42:05 2026 Received: from mail-wr1-f45.google.com (mail-wr1-f45.google.com [209.85.221.45]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id C2A083C2782 for ; Sat, 11 Jul 2026 12:36:54 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.221.45 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783773416; cv=none; b=JMfseIkqbheKli7Yx4/a/RGhOtaRjui2K1eWmLMnA7Ujn0rQaTi96IZV45Qlu0birO8Ua10J3HY3UUlNqJBnWVlZaM9J5/OSy/OFJuSZdSpfY0bknnchhsAdquLyP3n0JV2xen2UfiBzRG996hTwZCe2quZXUbeMWw/GZJRBkYs= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783773416; c=relaxed/simple; bh=yuIVmBPzTzrv2Dm30aECT2hNK8SzBGa9AOom3Qlk6Is=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=YI138VR/9N47t0iroFQhfQtyPp1Kt8TjMj6iTkVYQmG2ksYQzog3YPv43hND3b1Rp37gFi4Y7ptMFQMuZQqee+XNEZraFIC5U8mkRZGCkO8mdTGMR/IOMbWIA4cR1JaSJGeVZ4mw1Dg5/l1zPuvHr9Viw6Dp4FTzjcLExnRvMSo= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=0sec.ai; spf=pass smtp.mailfrom=0sec.ai; dkim=temperror (0-bit key) header.d=0sec.ai header.i=@0sec.ai header.b=oD4I3hle; arc=none smtp.client-ip=209.85.221.45 Authentication-Results: smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=0sec.ai Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=0sec.ai Authentication-Results: smtp.subspace.kernel.org; dkim=temperror (0-bit key) header.d=0sec.ai header.i=@0sec.ai header.b="oD4I3hle" Received: by mail-wr1-f45.google.com with SMTP id ffacd0b85a97d-47df4e62d2bso222297f8f.2 for ; Sat, 11 Jul 2026 05:36:54 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=0sec.ai; s=google; t=1783773413; x=1784378213; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=TKxklP1jarkRVxjcZK6OwpDBv6NsE5WBXhYoYNX2yBM=; b=oD4I3hleSwky7wC8lEMH0NoEXAcjtj/ecd+gaCHQmDFZQ/l2HkgeypDZDIlX5AgGUC UrEDyWXqxXe4Z6PNVPoYN/uBfiZe8uWMSRP82yNLZJ6uH7OWc1/sKmDIziM3mkEgaI2E OchUdmz2JKAkSGwMa+BIxar+zICyEUvXml9PG1aWHQKzVeT/9vsGZd/YzFxy2TNRNrn8 SmGURwjDiD86+zb2FRfaC4WCJGq6GYIhq0mI+m3U33rRrfnk8YFthPSpA87xcrLQRtbt ZPxF//Q59i3kKhDpFnj9M13sqZ/+8n5TIHxEtxXotnaTsntiYkrFq1964VVoYKjHKzug Ptwg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1783773413; x=1784378213; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=TKxklP1jarkRVxjcZK6OwpDBv6NsE5WBXhYoYNX2yBM=; b=qjrFXIMhoDU1bqXR4D7yiFi3GFbr4mbOrSPD+OZXVyo+bI89IdzfWQ/idII+w5uFq3 P3jocBk3Nqe6AhU57pfOMQkyVFkEH5lPz75w+s+EHYh3Ee6EuH0ADtXQIVavy61COWBn H+9ebHq6caMXks0dbtue555chhX/ISo/awI41MXbmvv9T4E3TNs6o/LDKsj3zBjj2LmR Pf2yBkWGt1D6cFip5BlD9gQt46LjB7blbrIHqArzhz480+uMhaalIPWCjSD2oxNs0Z5u LoN7LtSUjM0jlrWpV8/M+8V5/MoRQ/DKAfZLqaCcaHw2jnDfs2MHv6aolfi5yLOgckwr PNYg== X-Forwarded-Encrypted: i=1; AHgh+RpaUNE/FPLCgatCUwpiWObT6lMtEXXyvS5XGikVUuo6FYGyw5RaxQ6QqWRGtBLrLGISWN2LzWUuv9zbOz4=@vger.kernel.org X-Gm-Message-State: AOJu0Yyw0Qs4cKeuZBo77NB0wp33StZWRRHvpPHU4PSggk1g3Iq8725K 19CSFGMZGgqN5ilVpA0P2ShunazysItNO7oN+tf6daj7/2gKMJixb3ileksWyiohAWt1 X-Gm-Gg: AfdE7clBOHtST/eb0Saj8lmV/oJawV/if3/sFnRR8wjhKDzHqP9ctcpmefQ3SAX+o/1 lh6AHow2qBuKl+ifJTy4k2cbYqHCCYYGYspg4fhwmcTbl1ErTjkWa+Yh3QeKi3WKQtsKbdacS9v ZnUgVFUvjS2rJocBgj5TxaqV4ujxrcwT1yKAwNcoRbOAD7c0w1twR37E2xsfxIPZT2cqXLbn4/F zvF+JDmruaTN39bplI9MUuI5Jqtz6X2DTb9xuzqN+qFMQzKiDaERS1/iWYnSW3dtepK3zxXgGDB e9/Htm2V8w9B+v5H03wFwjpqkAw8LYy0KOefRh4SKfX1+u+PeHuBCDG70FZO0s2U55i3yXWI8tR YoujnMlYguVxySXMoaPATaNDAmaLB+IrquYndWiRIE8SIhnOrHKqTRyI7jn2jYDnLPl2R/2pHGW TcAMlrbXPiLZkCcMAqftZSWjgJG219zjTIzsZJ125XwbIqgTIB16hEo/q+7FSUo91/ngGKOqTDY JEEVxNdtGJusd4SkuNTpI9JD0xN1Vwtzik= X-Received: by 2002:a05:6000:2387:b0:476:7036:f854 with SMTP id ffacd0b85a97d-47f2dce9662mr2553907f8f.21.1783773413232; Sat, 11 Jul 2026 05:36:53 -0700 (PDT) Received: from PeakBook-Mini.tail8e484.ts.net ([178.197.218.188]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-47a9e4d83bdsm67690276f8f.13.2026.07.11.05.36.52 (version=TLS1_3 cipher=TLS_CHACHA20_POLY1305_SHA256 bits=256/256); Sat, 11 Jul 2026 05:36:52 -0700 (PDT) From: Doruk Tan Ozturk To: david@ixit.cz Cc: oe-linux-nfc@lists.linux.dev, netdev@vger.kernel.org, linux-kernel@vger.kernel.org, stable@vger.kernel.org Subject: [PATCH net] nfc: port100: reject frames whose declared length exceeds the received data Date: Sat, 11 Jul 2026 14:36:51 +0200 Message-ID: <20260711123651.32595-1-doruk@0sec.ai> X-Mailer: git-send-email 2.53.0 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" port100_recv_response() passes the URB transfer buffer to port100_rx_frame_is_valid(), which checksums le16_to_cpu(frame->datalen) bytes of frame->data. datalen is a 16-bit field supplied by the device and is never checked against the number of bytes actually received (urb->actual_length), so a device reporting a datalen larger than the received frame makes port100_data_checksum() read out of bounds past the transfer buffer. Reject a response whose declared frame size does not fit the received length before validating it. Found by 0sec (https://0sec.ai) using automated source analysis; the missing bound is evident from source. Compile-tested. Fixes: 562d4d59b8a1 ("NFC: Sony Port-100 Series driver") Cc: stable@vger.kernel.org Assisted-by: 0sec:claude-opus-4-8 Signed-off-by: Doruk Tan Ozturk Reviewed-by: Simon Horman --- drivers/nfc/port100.c | 7 +++++++ 1 file changed, 7 insertions(+) diff --git a/drivers/nfc/port100.c b/drivers/nfc/port100.c index 5ae61d7ebcfe..30a4e09875d3 100644 --- a/drivers/nfc/port100.c +++ b/drivers/nfc/port100.c @@ -636,6 +636,13 @@ static void port100_recv_response(struct urb *urb) =20 in_frame =3D dev->in_urb->transfer_buffer; =20 + if (urb->actual_length < PORT100_FRAME_HEADER_LEN || + urb->actual_length < port100_rx_frame_size(in_frame)) { + nfc_err(&dev->interface->dev, "Received a truncated frame\n"); + cmd->status =3D -EIO; + goto sched_wq; + } + if (!port100_rx_frame_is_valid(in_frame)) { nfc_err(&dev->interface->dev, "Received an invalid frame\n"); cmd->status =3D -EIO; --=20 2.43.0