Netdev List
 help / color / mirror / Atom feed
From: "Lekë Hapçiu" <snowwlake@icloud.com>
To: David Heidelberg <david+nfc@ixit.cz>
Cc: davem@davemloft.net, edumazet@google.com, kuba@kernel.org,
	pabeni@redhat.com, krzk@kernel.org, horms@kernel.org,
	linux-kernel@vger.kernel.org, netdev@vger.kernel.org,
	oe-linux-nfc@lists.linux.dev,
	"Lekë Hapçiu" <snowwlake@icloud.com>
Subject: [PATCH net v5 0/3] nfc: fix remaining OOB bugs in NCI/LLCP parsing
Date: Thu, 16 Jul 2026 22:35:04 +0200	[thread overview]
Message-ID: <20260716203507.7328-1-snowwlake@icloud.com> (raw)

Rebased against David's linux-nfc for-linus tree [1], as requested.

This was originally a 5-patch series. Two of the five (the
parse_gb_tlv()/parse_connection_tlv() offset-wrap fix and the
nfc_llcp_recv_snl() TLV bounds fix) have since been fixed independently
by other contributors already merged into for-linus:

  d8bd2dedbde5 ("nfc: llcp: fix OOB read and u8 offset wrap in TLV parsers")
  27256cdb290e ("nfc: llcp: bound SNL TLV parsing to the skb and add length checks")

Those two are dropped from this series to avoid duplicating work. The
remaining three patches are unchanged in substance from v4, just
rebased and renumbered:

  1/3 (was 1/5) - nci_store_general_bytes_nfc_dep() u8 underflow
  2/3 (was 4/5) - nfc_llcp_recv_dm() OOB read of the reason byte
  3/3 (was 5/5) - nfc_llcp_connect_sn() TLV parsing OOB

All three still reproduce against current for-linus (verified against
1671b8fb7300 before rebase). checkpatch --strict is clean on all three.

[1] https://codeberg.org/linux-nfc/linux.git for-linus

Lekë Hapçiu (3):
  nfc: nci: fix u8 underflow in nci_store_general_bytes_nfc_dep
  nfc: llcp: fix OOB read of DM reason byte in nfc_llcp_recv_dm
  nfc: llcp: fix TLV parsing OOB in nfc_llcp_connect_sn

 net/nfc/llcp_core.c | 19 +++++++++++++++++--
 net/nfc/nci/ntf.c   |  6 ++++++
 2 files changed, 23 insertions(+), 2 deletions(-)

-- 
2.51.0


             reply	other threads:[~2026-07-16 20:38 UTC|newest]

Thread overview: 5+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-07-16 20:35 Lekë Hapçiu [this message]
2026-07-16 20:35 ` [PATCH net v5 1/3] nfc: nci: fix u8 underflow in nci_store_general_bytes_nfc_dep Lekë Hapçiu
2026-07-16 20:35 ` [PATCH net v5 2/3] nfc: llcp: fix OOB read of DM reason byte in nfc_llcp_recv_dm Lekë Hapçiu
2026-07-16 20:35 ` [PATCH net v5 3/3] nfc: llcp: fix TLV parsing OOB in nfc_llcp_connect_sn Lekë Hapçiu
2026-07-19 15:04 ` [PATCH net v5 0/3] nfc: fix remaining OOB bugs in NCI/LLCP parsing David Heidelberg

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260716203507.7328-1-snowwlake@icloud.com \
    --to=snowwlake@icloud.com \
    --cc=davem@davemloft.net \
    --cc=david+nfc@ixit.cz \
    --cc=edumazet@google.com \
    --cc=horms@kernel.org \
    --cc=krzk@kernel.org \
    --cc=kuba@kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=netdev@vger.kernel.org \
    --cc=oe-linux-nfc@lists.linux.dev \
    --cc=pabeni@redhat.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox