From fd734e841c567d7b0dccdc3bf8c46f11d39d0f49 Mon Sep 17 00:00:00 2001 From: Dan Carpenter Date: Mon, 10 Mar 2025 11:50:48 +0800 Subject: [PATCH] NFC: nci: Add bounds checking in nci_hci_create_pipe() mainline inclusion from mainline-v6.14-rc1 commit 110b43ef05342d5a11284cc8b21582b698b4ef1c category: bugfix bugzilla: https://gitee.com/src-openeuler/kernel/issues/IBPC8J CVE: CVE-2025-21735 Reference: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=110b43ef05342d5a11284cc8b21582b698b4ef1c -------------------------------- The "pipe" variable is a u8 which comes from the network. If it's more than 127, then it results in memory corruption in the caller, nci_hci_connect_gate(). Cc: stable@vger.kernel.org Fixes: a1b0b9415817 ("NFC: nci: Create pipe on specific gate in nci_hci_connect_gate") Signed-off-by: Dan Carpenter Reviewed-by: Simon Horman Reviewed-by: Krzysztof Kozlowski Link: https://patch.msgid.link/bcf5453b-7204-4297-9c20-4d8c7dacf586@stanley.mountain Signed-off-by: Jakub Kicinski Signed-off-by: Yang Yingliang --- net/nfc/nci/hci.c | 2 ++ 1 file changed, 2 insertions(+) diff --git a/net/nfc/nci/hci.c b/net/nfc/nci/hci.c index 4fe336ff2bfa..f8140488b08a 100644 --- a/net/nfc/nci/hci.c +++ b/net/nfc/nci/hci.c @@ -548,6 +548,8 @@ static u8 nci_hci_create_pipe(struct nci_dev *ndev, u8 dest_host, pr_debug("pipe created=%d\n", pipe); + if (pipe >= NCI_HCI_MAX_PIPES) + pipe = NCI_HCI_INVALID_PIPE; return pipe; } -- Gitee