From nobody Sat Jul 25 02:11:16 2026 Received: from mail-pl1-f198.google.com (mail-pl1-f198.google.com [209.85.214.198]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id D527A322DAF for ; Mon, 20 Jul 2026 16:57:33 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.214.198 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784566655; cv=none; b=pRoIZKUR1WZH1ZX1AqUNQ5+Ual2Pi1gvB/9ISwa1nkXvEyjRxu3a22/tJ01z1/6VdZEfqOQ75pJHSISqgKuRfLpCKEqB/6u45T0nnB1wR12mO1cH1n7zjOa3Ft0etL7ufOEdXZU9/LfIl7xcjRd74Cwgvi4GFHMNbYa6gWtRVRQ= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784566655; c=relaxed/simple; bh=txRVoarM9RtPWUWP0CtgOYUtrKwjXI7x8OF9IaeZvqw=; h=Date:Mime-Version:Message-ID:Subject:From:To:Cc:Content-Type; b=FnYwe0YfKSbH7rvg+CtT6CQIabDNEjr3N//bnb3eTCHHa0wj2gTI649hBfnkKHLSIobZZJtsnif+x84+lquxqtPTsQmQtckNrrZcdEpv4Tj22ruQTEyBb7zUu8bNLoCy2jXoYZVej6BKT6fAxfo6KRMFvwKn2a+x17P5qOqinrk= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--sonalipradhan.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=MAcSuKjr; arc=none smtp.client-ip=209.85.214.198 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--sonalipradhan.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="MAcSuKjr" Received: by mail-pl1-f198.google.com with SMTP id d9443c01a7336-2cca5e0a0c9so202773615ad.1 for ; Mon, 20 Jul 2026 09:57:33 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1784566653; x=1785171453; darn=vger.kernel.org; h=content-type:cc:to:from:subject:message-id:mime-version:date:from :to:cc:subject:date:message-id:reply-to:content-type; bh=pp8INu7R2avTucfkh21LhjYSN0E+XTKfW4u2lNTh3fs=; b=MAcSuKjr2851HVM7INV4boXvAXAabgunyupOWNKuijX6NL7kRtf9u4pT5sr/D9LY1E bL8O0i9IBKdGQtYIfmcszrLOcDqUFs0T3M0qTOIafqb5aDGmGlaxTy4xuwXoFAUXcIhu aZTZQRzs5YAHivsVSq2PvUTZmqHapVw13AF8DVvyWOqIkHe4LPVBusa4qdX1aUOqy0RG 4Yf86UAAV0ICiSNxaDPfbZcxYNLuBjHYbmD7gZ/Gm/0DbQQZ00nEy+AVDCNIB/agXijl Fzj2eJA3hcTTDMIs8GSs4k889fqBWZtp3DnhvsBVYxQhF4eeAEtVE884mjoe6gWYU/sG HPOQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784566653; x=1785171453; h=content-type:cc:to:from:subject:message-id:mime-version:date :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=pp8INu7R2avTucfkh21LhjYSN0E+XTKfW4u2lNTh3fs=; b=KX8YGwE8F1zJyWS7cLXUk+OA5XiDUKWctjmYt8HfGX3qs0UaZIgNU+G0sIWw9n/bJ1 t7XZK6KX5cJg7iPneW8ryP+Bg7nl7n+rFTYun+0wUvEkyvxEKTvLw+cfTEaEo6w9x+Bt M9mCLRRazlTXdQDnbh+XGMh5GBl8tSxhjtU2aQLPSJEbHoBLJLxUBY/dLu6aUU3TTUVZ 9bPCu7CZtMO9ZBT2podVAk8GVfz/daWODjgXymLXG7xd/SY9JhJiiuW+zZ0x1uh4BgnE wDDtBsU6Mhls6hWpza0/jbs19nemYiYz3xAB2FaLpkvFTDXps4FvRI1XOHIe03Wze5Va suJA== X-Forwarded-Encrypted: i=1; AHgh+RqZeBtAz0cq8v1h0AOv0mUf3WzwT/V1zawfdQKQ9rgEdEXLTYDtAwJVWGnIBN0g9C0fnTSVhmIeqz1D0Wo=@vger.kernel.org X-Gm-Message-State: AOJu0YxK4pDvkw/1/O0xa9E+Usc0myW4h/e09/MYOpfx8RmQK100Pv0y /ExsRnVCH9fNaP5jwUzJJx/xX5hb0pgc13g/UiWuPxO/ZM4ZsXdnXtZA9UxsQDf39d6snBcjAhJ n5AcL1F3UQvDeOt9+P9n/cO78L1Uaytdaag== X-Received: from plim8.prod.google.com ([2002:a17:903:3b48:b0:2cf:7a5b:f7ad]) (user=sonalipradhan job=prod-delivery.src-stubby-dispatcher) by 2002:a17:903:8c8:b0:2ce:e75f:b713 with SMTP id d9443c01a7336-2cf349640f3mr154178425ad.23.1784566652964; Mon, 20 Jul 2026 09:57:32 -0700 (PDT) Date: Mon, 20 Jul 2026 16:56:54 +0000 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 X-Mailer: git-send-email 2.55.0.229.g6434b31f56-goog Message-ID: <20260720165654.2224591-1-sonalipradhan@google.com> Subject: [PATCH] usb: gadget: f_ncm: Use unsigned int for ndp_index From: Sonali Pradhan To: Greg Kroah-Hartman Cc: Kuen-Han Tsai , Kees Cook , raub camaioni , Jim Baxter , Felipe Balbi , linux-usb@vger.kernel.org, linux-kernel@vger.kernel.org, Sonali Pradhan , stable@vger.kernel.org Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" The variable ndp_index is declared as a signed integer, but it stores the return value of get_ncm(), which is unsigned. A malicious host can supply a large offset that overflows the signed ndp_index, making it negative. Because ndp_index is compared against unsigned bounds, this negative value bypasses sanity checks and leads to an out-of-bounds read when calculating the address of the NDP block (ntb_ptr + ndp_index). Fix this by changing ndp_index to unsigned int to ensure consistent unsigned comparisons throughout the function. Fixes: 370af734dfaf ("usb: gadget: NCM: RX function support multiple NDPs") Cc: stable@vger.kernel.org Signed-off-by: Sonali Pradhan --- drivers/usb/gadget/function/f_ncm.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/drivers/usb/gadget/function/f_ncm.c b/drivers/usb/gadget/funct= ion/f_ncm.c index 64eabda2f546..bf02545b37a2 100644 --- a/drivers/usb/gadget/function/f_ncm.c +++ b/drivers/usb/gadget/function/f_ncm.c @@ -1171,7 +1171,7 @@ static int ncm_unwrap_ntb(struct gether *port, unsigned char *ntb_ptr =3D skb->data; __le16 *tmp; unsigned index, index2; - int ndp_index; + unsigned int ndp_index; unsigned dg_len, dg_len2; unsigned ndp_len; unsigned block_len; --=20 2.55.0.229.g6434b31f56-goog