From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from vger.kernel.org (vger.kernel.org [23.128.96.18]) by smtp.lore.kernel.org (Postfix) with ESMTP id 3B977EB64DD for ; Wed, 12 Jul 2023 13:01:27 +0000 (UTC) Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S232985AbjGLNBY (ORCPT ); Wed, 12 Jul 2023 09:01:24 -0400 Received: from lindbergh.monkeyblade.net ([23.128.96.19]:37652 "EHLO lindbergh.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S232140AbjGLNBW (ORCPT ); Wed, 12 Jul 2023 09:01:22 -0400 Received: from sipsolutions.net (s3.sipsolutions.net [IPv6:2a01:4f8:191:4433::2]) by lindbergh.monkeyblade.net (Postfix) with ESMTPS id A32E11736; Wed, 12 Jul 2023 06:01:21 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sipsolutions.net; s=mail; h=MIME-Version:Content-Transfer-Encoding: Content-Type:References:In-Reply-To:Date:Cc:To:From:Subject:Message-ID:Sender :Reply-To:Content-ID:Content-Description:Resent-Date:Resent-From:Resent-To: Resent-Cc:Resent-Message-ID; bh=7Mwy7Es+QCyPK8S0J7Ou3RSKVlLA8cMmzE6C5fqkOHA=; t=1689166881; x=1690376481; b=lTJQKVJQ0RPkEhlLeGsUvjhJ8cZTUvPvlbyrvRA0ca2shVP 4qzyOZsbdOT9RQqGOduZI6pNscXb4ICTxR3URWwCGE3B0oKUDI//r1Zx4jgw2rsQley5ejlfZ6ZDH Dm6kQEuXVK4xv3px1jMCbPi14z5EmyCyHHQguVbRj9kFh4FTns7MON+UZeG2VK8/ATQyS7RAYlWp3 0jthUan8usKKksdYCPnJjjSmmzMgmbxvo1NmjFGmIl9wPl9fZ9nJour2V6Lf/4Jypzx4Qu+7WPdT1 qafw8pHYLW1dWz5l+hDGgijp2miEyceMK6mogTvKFGak0joMLqZ62vX/QvVnfIWA==; Received: by sipsolutions.net with esmtpsa (TLS1.3:ECDHE_X25519__RSA_PSS_RSAE_SHA256__AES_256_GCM:256) (Exim 4.96) (envelope-from ) id 1qJZSk-00GfuA-1M; Wed, 12 Jul 2023 15:00:58 +0200 Message-ID: <6a4a8980912380085ea628049b5e19e38bcd8e1d.camel@sipsolutions.net> Subject: Re: [PATCH] USB: disable all RNDIS protocol drivers From: Johannes Berg To: Oliver Neukum , Greg Kroah-Hartman , Enrico Mioso Cc: Jan Engelhardt , linux-kernel@vger.kernel.org, "David S. Miller" , Eric Dumazet , Jakub Kicinski , Paolo Abeni , Kalle Valo , Oleksij Rempel , Maciej =?UTF-8?Q?=C5=BBenczykowski?= , Neil Armstrong , Mauro Carvalho Chehab , Andrzej Pietrasiewicz , Jacopo Mondi , =?UTF-8?Q?=C5=81ukasz?= Stelmach , Laurent Pinchart , linux-usb@vger.kernel.org, netdev@vger.kernel.org, linux-wireless@vger.kernel.org, Ilja Van Sprundel , Joseph Tartaro Date: Wed, 12 Jul 2023 15:00:55 +0200 In-Reply-To: References: <20221123124620.1387499-1-gregkh@linuxfoundation.org> <2023070430-fragment-remember-2fdd@gregkh> Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable User-Agent: Evolution 3.48.4 (3.48.4-1.fc38) MIME-Version: 1.0 X-malware-bazaar: not-scanned Precedence: bulk List-ID: X-Mailing-List: linux-usb@vger.kernel.org On Wed, 2023-07-12 at 11:22 +0200, Oliver Neukum wrote: >=20 > On 04.07.23 08:47, Greg Kroah-Hartman wrote: > > On Mon, Jul 03, 2023 at 11:11:57PM +0200, Enrico Mioso wrote: > > > Hi all!! > > >=20 > > > I think the rndis_host USB driver might emit a warning in the dmesg, = but disabling the driver wouldn't be a good idea. > > > The TP-Link MR6400 V1 LTE modem and also some ZTE modems integrated i= n routers do use this protocol. > > >=20 > > > We may also distinguish between these cases and devices you might plu= g in - as they pose different risk levels. > >=20 > > Again, you have to fully trust the other side of an RNDIS connection, > > any hints on how to have the kernel determine that? > it is a network protocol. So this statement is kind of odd. > Are you saying that there are RNDIS messages that cannot be verified > for some reason, that still cannot be disclosed? Agree, it's also just a USB device, so no special trickery with DMA, shared buffers, etc. I mean, yeah, the RNDIS code is really old and almost certainly has a severe lack of input validation, but that still doesn't mean it's fundamentally impossible. johannes