All of lore.kernel.org
 help / color / mirror / Atom feed
From: Simon Horman <horms@kernel.org>
To: Doruk Tan Ozturk <doruk@0sec.ai>
Cc: jk@codeconstruct.com.au, matt@codeconstruct.com.au,
	andrew+netdev@lunn.ch, davem@davemloft.net, edumazet@google.com,
	kuba@kernel.org, pabeni@redhat.com, netdev@vger.kernel.org,
	linux-kernel@vger.kernel.org, stable@vger.kernel.org
Subject: Re: [PATCH net v2] mctp: serial: handle zero-length frames to prevent rx buffer overflow
Date: Wed, 22 Jul 2026 16:13:02 +0100	[thread overview]
Message-ID: <20260722151302.GE418547@horms.kernel.org> (raw)
In-Reply-To: <20260715082021.46315-1-doruk@0sec.ai>

On Wed, Jul 15, 2026 at 10:20:21AM +0200, Doruk Tan Ozturk wrote:
> The MCTP serial receive state machine reads a frame length byte in
> mctp_serial_push_header() case 2 and validates it upper-bound-only:
> 
> 	if (c > MCTP_SERIAL_FRAME_MTU) {
> 		dev->rxstate = STATE_ERR;
> 	} else {
> 		dev->rxlen = c;
> 		dev->rxpos = 0;
> 		dev->rxstate = STATE_DATA;
> 		...
> 	}
> 
> A length of zero passes this check, so rxlen is set to 0 and the state
> machine advances to STATE_DATA. In mctp_serial_push() STATE_DATA, the
> incoming byte is stored and rxpos incremented before the terminator is
> tested:
> 
> 	dev->rxbuf[dev->rxpos] = c;
> 	dev->rxpos++;
> 	dev->rxstate = STATE_DATA;
> 	if (dev->rxpos == dev->rxlen) {
> 		dev->rxpos = 0;
> 		dev->rxstate = STATE_TRAILER;
> 	}
> 
> With rxlen == 0 the "rxpos == rxlen" terminator can never fire (rxpos is
> already 1 on the first data byte), so subsequent bytes are written past
> the end of the fixed 74-byte rxbuf, which is the last member of the
> netdev private area. Every following data byte is an attacker-controlled
> 1-byte out-of-bounds heap write, and the overflow continues until a
> frame (0x7e) or escape byte resets the parser -- effectively unbounded.
> 
> Reaching this requires CAP_NET_ADMIN to attach the N_MCTP line
> discipline and bring the resulting mctpserialN netdev up, after which
> the bytes arrive via the tty receive path.
> 
> Route a zero-length frame straight to STATE_TRAILER instead of
> STATE_DATA. The trailer/framing bytes are still consumed, and the frame
> resolves to a zero-length skb that the MCTP core rejects; the parser
> never enters STATE_DATA with rxlen == 0, so the out-of-bounds write can
> no longer occur.
> 
> KASAN, on a frame of 0x7e 0x01 0x00 followed by data bytes (before this
> change):
> 
>   UBSAN: array-index-out-of-bounds in drivers/net/mctp/mctp-serial.c:370
>   index 74 is out of range for type 'u8 [74]'
>   BUG: KASAN: slab-out-of-bounds in mctp_serial_tty_receive_buf
>   Write of size 1 at addr ... by task kworker/u16:0
>    mctp_serial_tty_receive_buf
>    tty_ldisc_receive_buf
>    flush_to_ldisc
>   Allocated by task 152:
>    alloc_netdev_mqs
>    mctp_serial_open
> 
> v2: route zero-length frames to STATE_TRAILER instead of STATE_ERR so
>     the trailer/framing bytes are still consumed (Jeremy Kerr).
> 
> Found by 0sec automated security-research tooling (https://0sec.ai).
> Fixes: a0c2ccd9b5ad ("mctp: Add MCTP-over-serial transport binding")
> Cc: stable@vger.kernel.org
> Suggested-by: Jeremy Kerr <jk@codeconstruct.com.au>
> Assisted-by: 0sec:multi-model
> Signed-off-by: Doruk Tan Ozturk <doruk@0sec.ai>

Reviewed-by: Simon Horman <horms@kernel.org>


      reply	other threads:[~2026-07-22 15:13 UTC|newest]

Thread overview: 2+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-07-15  8:20 [PATCH net v2] mctp: serial: handle zero-length frames to prevent rx buffer overflow Doruk Tan Ozturk
2026-07-22 15:13 ` Simon Horman [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260722151302.GE418547@horms.kernel.org \
    --to=horms@kernel.org \
    --cc=andrew+netdev@lunn.ch \
    --cc=davem@davemloft.net \
    --cc=doruk@0sec.ai \
    --cc=edumazet@google.com \
    --cc=jk@codeconstruct.com.au \
    --cc=kuba@kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=matt@codeconstruct.com.au \
    --cc=netdev@vger.kernel.org \
    --cc=pabeni@redhat.com \
    --cc=stable@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.