From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 921E14DB540; Wed, 30 Sep 2026 16:33:53 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790786034; cv=none; b=OwEfyMs4zK7gR9NpgElyRbilmAgvzMqXPno3j/us0oQVdqdZqOPlaCteqdIwZDayj8nUPk3rqdhd+ygi1Z6exoZqxoN4v13rJWv4c2oRdICTTY+Fw76x+WGLiHXTusL0wKwdNG+RbHQkc2KAc5Sfnctnuue+g51H9JBEQy0UQyE= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790786034; c=relaxed/simple; bh=oWI4/LRHY7ua1FYz0o0W2VYHuCKd8QJsMtA8EhQNGD0=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=LUdBrBL6qTEF6lCyUtNMn+FhbKHKexx6xqfhKnPMtffJQPRbPDKZ7pxMXXlsjbkW6Aoiculrf1ygwiakM2NMaAWoCUMEuQ69NVODKiIjmr4DCZ6B8hb/y9bOupQ5GxX8dxuPzDbpNrywpDATMjun9cGaq7afn7wUZQTL6tksuXk= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=cdR3DO+M; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="cdR3DO+M" Received: by smtp.kernel.org (Postfix) with ESMTPSA id ED6121F000FF; Wed, 30 Sep 2026 16:33:52 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1790786033; bh=OeQeJSacePpw+cKPx5OpDrJX9hHkmPeEWuRKDK/Oa8o=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=cdR3DO+MBpJHxCDM4wwFjZNpmoCdOI5Y8mZ4mJXxDifa2AWXB0KOyUYoYjFZrRlHF IZ5e4ntTnwqM+2HUVXWeyOnEUd1xzfQ/mUMtxR7P9nE0GQx0FQZTVrwbx5hiK/dDW3 JHySwCh2GhYd7KmjYBAnvJY0ITcKPRvM++gdXL4k= From: Greg Kroah-Hartman To: stable@vger.kernel.org Cc: Greg Kroah-Hartman , patches@lists.linux.dev, Loic Poulain , Guanglei Zhu , Jakub Kicinski Subject: [PATCH 6.1 718/982] net: wwan: mhi_wwan_mbim: guard against a cyclic NDP chain Date: Wed, 30 Sep 2026 17:24:14 +0200 Message-ID: <20260930152432.176230450@linuxfoundation.org> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260930152416.775402466@linuxfoundation.org> References: <20260930152416.775402466@linuxfoundation.org> User-Agent: quilt/0.69 X-stable: review X-Patchwork-Hint: ignore Precedence: bulk X-Mailing-List: patches@lists.linux.dev List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit 6.1-stable review patch. If anyone has any objections, please let me know. ------------------ From: Guanglei Zhu commit 5d063822ac5184939c1ed377a339a01d8ae814e8 upstream. The NDP traversal in mhi_mbim_rx() only stops when wNextNdpIndex is zero. Nothing requires the offsets to advance, so a modem that points an NDP at itself, or at an earlier NDP, keeps the loop spinning forever on one CPU. Break out when the next NDP offset is not larger than the current one. Fixes: aa730a9905b7 ("net: wwan: Add MHI MBIM network driver") Cc: stable@vger.kernel.org Suggested-by: Loic Poulain Signed-off-by: Guanglei Zhu Signed-off-by: Greg Kroah-Hartman Verified in a QEMU guest with a fault injector feeding the driver's receive callback an NTB whose single NDP points at itself: the unpatched driver spins in mhi_mbim_rx() with one CPU pinned at 100% and the thread never returns. With this check the loop terminates within one iteration. Changes in v2: move the non-increasing check to the wNextNdpIndex retrieval site, as suggested by Loic Poulain, instead of tracking the previous offset in a separate variable. Link: https://patch.msgid.link/20260911021734.1396599-1-zhugl3@xiaopeng.com Signed-off-by: Jakub Kicinski --- drivers/net/wwan/mhi_wwan_mbim.c | 10 +++++++--- 1 file changed, 7 insertions(+), 3 deletions(-) --- a/drivers/net/wwan/mhi_wwan_mbim.c +++ b/drivers/net/wwan/mhi_wwan_mbim.c @@ -338,9 +338,13 @@ static void mhi_mbim_rx(struct mhi_mbim_ unlock: rcu_read_unlock(); next_ndp: - /* Other NDP to process? */ - ndpoffset = (int)le16_to_cpu(ndp16.wNextNdpIndex); - if (!ndpoffset) + /* Other NDP to process? The offsets must advance, or a + * self-referencing NDP keeps the loop spinning forever. + */ + n = (int)le16_to_cpu(ndp16.wNextNdpIndex); + if (n > ndpoffset) + ndpoffset = n; + else break; }