From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 9F91C51AEEE; Wed, 30 Sep 2026 17:27:35 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790789256; cv=none; b=NLOanlC3qZKmYjJeAlkVgArGDokLt202b4g403pWG8S9KVoNip/Zg1aO7x6osdxBbw/YpI7k2ENvgz2criSbZcls5r4LFiNBiBmZts/5oqIW06RK+0qoG3GFgCzkjqHrqai2LLfrFhzdS6g4FV43cvJ70AJXeLlVnEUfEjTT068= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790789256; c=relaxed/simple; bh=1UNg7Xa6GoFsc2FfYDoPZ5IWQcPASxWLC15NMi7O4xk=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=ZzxY3L4zR9ElH8vQa97ZODoGoJBqI3jXUmw995KOyotVgoobkfCsrWHIIGo8dBEuQMkD/LPF2F6w0Xxo/l1zQTPvlKw8Pd/FIm/s0VJR7ke8+PAL37vbdXRFF9Ghqh3ORPpxSvG55dH/1ZQdkX8+REAWTI8oC7PkWzIU/8N0+D8= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=cQT1mi1R; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="cQT1mi1R" Received: by smtp.kernel.org (Postfix) with ESMTPSA id EA9691F00898; Wed, 30 Sep 2026 17:27:34 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1790789255; bh=wyF4+HW0zc2S9fwJtYb3RzFyu+OzbXOkXLF+JH9A2gM=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=cQT1mi1Rl5BRQspk8sMtMekIml1vhoXJI1ZWupQBpSVqMnzH+LIxp57SgbM7jjZDF iaux1mtJS5xsjPYnD+Iip2XLp5NIZSXBCa9nHfH/Q3KPRA8ploXLoAVlvN6nf+aNsC swxgZTOjWCa31+rkgmAJMbmiPGf+loAOSxTFFPSo= From: Greg Kroah-Hartman To: stable@vger.kernel.org Cc: Greg Kroah-Hartman , patches@lists.linux.dev, syzbot+1853daab1a47603d4678@syzkaller.appspotmail.com, Deepanshu Kartikey , David Heidelberg , Sasha Levin Subject: [PATCH 6.12 414/877] nfc: pn533: fix OOB read in pn533_acr122_is_rx_frame_valid() Date: Wed, 30 Sep 2026 17:22:05 +0200 Message-ID: <20260930152423.627186636@linuxfoundation.org> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260930152414.738996857@linuxfoundation.org> References: <20260930152414.738996857@linuxfoundation.org> User-Agent: quilt/0.69 X-stable: review X-Patchwork-Hint: ignore Precedence: bulk X-Mailing-List: patches@lists.linux.dev List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit 6.12-stable review patch. If anyone has any objections, please let me know. ------------------ From: Deepanshu Kartikey [ Upstream commit b61732f47316d45f27706db7812950145d3327b5 ] frame->ccid.datalen is read directly from the USB response frame and used, unchecked, as an index into frame->data[]. A malicious or malfunctioning device can set this field to an arbitrary value, causing the driver to read far outside the received buffer. Bound ccid.datalen against the maximum possible ACR122 frame size before using it. This replaces the existing datalen == 0 check, since datalen < 2 already covers that case and additionally rejects datalen == 1, which would still underflow the "datalen - 2" offset used below. Fixes: 9815c7cf22da ("NFC: pn533: Separate physical layer from the core implementation") Reported-by: syzbot+1853daab1a47603d4678@syzkaller.appspotmail.com Closes: https://syzkaller.appspot.com/bug?extid=1853daab1a47603d4678 Tested-by: syzbot+1853daab1a47603d4678@syzkaller.appspotmail.com Assisted-by: LLM Signed-off-by: Deepanshu Kartikey Link: https://patch.msgid.link/20260923035627.6210-1-kartikey406@gmail.com Signed-off-by: David Heidelberg Signed-off-by: Sasha Levin --- drivers/nfc/pn533/usb.c | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/drivers/nfc/pn533/usb.c b/drivers/nfc/pn533/usb.c index 0f12f86ebb023..35f3350cad324 100644 --- a/drivers/nfc/pn533/usb.c +++ b/drivers/nfc/pn533/usb.c @@ -319,7 +319,9 @@ static bool pn533_acr122_is_rx_frame_valid(void *_frame, struct pn533 *dev) if (frame->ccid.type != 0x83) return false; - if (!frame->ccid.datalen) + if (frame->ccid.datalen < 2 || + frame->ccid.datalen > PN533_ACR122_FRAME_MAX_PAYLOAD_LEN + + PN533_ACR122_RX_FRAME_TAIL_LEN) return false; if (frame->data[frame->ccid.datalen - 2] == 0x63) -- 2.53.0