From: "Lekë Hapçiu" <snowwlake@icloud.com>
To: David Heidelberg <david+nfc@ixit.cz>
Cc: davem@davemloft.net, edumazet@google.com, kuba@kernel.org,
pabeni@redhat.com, krzk@kernel.org, horms@kernel.org,
linux-kernel@vger.kernel.org, netdev@vger.kernel.org,
oe-linux-nfc@lists.linux.dev,
"Lekë Hapçiu" <snowwlake@icloud.com>
Subject: [PATCH net v5 0/3] nfc: fix remaining OOB bugs in NCI/LLCP parsing
Date: Thu, 16 Jul 2026 22:35:04 +0200 [thread overview]
Message-ID: <20260716203507.7328-1-snowwlake@icloud.com> (raw)
Rebased against David's linux-nfc for-linus tree [1], as requested.
This was originally a 5-patch series. Two of the five (the
parse_gb_tlv()/parse_connection_tlv() offset-wrap fix and the
nfc_llcp_recv_snl() TLV bounds fix) have since been fixed independently
by other contributors already merged into for-linus:
d8bd2dedbde5 ("nfc: llcp: fix OOB read and u8 offset wrap in TLV parsers")
27256cdb290e ("nfc: llcp: bound SNL TLV parsing to the skb and add length checks")
Those two are dropped from this series to avoid duplicating work. The
remaining three patches are unchanged in substance from v4, just
rebased and renumbered:
1/3 (was 1/5) - nci_store_general_bytes_nfc_dep() u8 underflow
2/3 (was 4/5) - nfc_llcp_recv_dm() OOB read of the reason byte
3/3 (was 5/5) - nfc_llcp_connect_sn() TLV parsing OOB
All three still reproduce against current for-linus (verified against
1671b8fb7300 before rebase). checkpatch --strict is clean on all three.
[1] https://codeberg.org/linux-nfc/linux.git for-linus
Lekë Hapçiu (3):
nfc: nci: fix u8 underflow in nci_store_general_bytes_nfc_dep
nfc: llcp: fix OOB read of DM reason byte in nfc_llcp_recv_dm
nfc: llcp: fix TLV parsing OOB in nfc_llcp_connect_sn
net/nfc/llcp_core.c | 19 +++++++++++++++++--
net/nfc/nci/ntf.c | 6 ++++++
2 files changed, 23 insertions(+), 2 deletions(-)
--
2.51.0
next reply other threads:[~2026-07-16 20:38 UTC|newest]
Thread overview: 5+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-07-16 20:35 Lekë Hapçiu [this message]
2026-07-16 20:35 ` [PATCH net v5 1/3] nfc: nci: fix u8 underflow in nci_store_general_bytes_nfc_dep Lekë Hapçiu
2026-07-16 20:35 ` [PATCH net v5 2/3] nfc: llcp: fix OOB read of DM reason byte in nfc_llcp_recv_dm Lekë Hapçiu
2026-07-16 20:35 ` [PATCH net v5 3/3] nfc: llcp: fix TLV parsing OOB in nfc_llcp_connect_sn Lekë Hapçiu
2026-07-19 15:04 ` [PATCH net v5 0/3] nfc: fix remaining OOB bugs in NCI/LLCP parsing David Heidelberg
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260716203507.7328-1-snowwlake@icloud.com \
--to=snowwlake@icloud.com \
--cc=davem@davemloft.net \
--cc=david+nfc@ixit.cz \
--cc=edumazet@google.com \
--cc=horms@kernel.org \
--cc=krzk@kernel.org \
--cc=kuba@kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=netdev@vger.kernel.org \
--cc=oe-linux-nfc@lists.linux.dev \
--cc=pabeni@redhat.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox