]> git.ipfire.org Git - thirdparty/kernel/stable.git/commitdiff
nfc: nci: Fix handling of zero-length payload packets in nci_rx_work()
authorRyosuke Yasuoka <ryasuoka@redhat.com>
Tue, 21 May 2024 15:34:42 +0000 (00:34 +0900)
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Sun, 16 Jun 2024 11:32:27 +0000 (13:32 +0200)
[ Upstream commit 6671e352497ca4bb07a96c48e03907065ff77d8a ]

When nci_rx_work() receives a zero-length payload packet, it should not
discard the packet and exit the loop. Instead, it should continue
processing subsequent packets.

Fixes: d24b03535e5e ("nfc: nci: Fix uninit-value in nci_dev_up and nci_ntf_packet")
Signed-off-by: Ryosuke Yasuoka <ryasuoka@redhat.com>
Reviewed-by: Simon Horman <horms@kernel.org>
Reviewed-by: Krzysztof Kozlowski <krzysztof.kozlowski@linaro.org>
Link: https://lore.kernel.org/r/20240521153444.535399-1-ryasuoka@redhat.com
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
net/nfc/nci/core.c

index e2d632e0d3eb491122bd547d944156396bc8bb09..3182b4228cfa453f1739ba4efec87e97a2aa5b9e 100644 (file)
@@ -1517,8 +1517,7 @@ static void nci_rx_work(struct work_struct *work)
 
                if (!nci_valid_size(skb)) {
                        kfree_skb(skb);
-                       kcov_remote_stop();
-                       break;
+                       continue;
                }
 
                /* Process frame */