]> git.ipfire.org Git - thirdparty/kernel/linux.git/commitdiff
usb: gadget: f_ncm: validate datagram bounds in ncm_unwrap_ntb()
authorSonali Pradhan <sonalipradhan@google.com>
Fri, 3 Jul 2026 08:37:24 +0000 (08:37 +0000)
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Mon, 13 Jul 2026 05:10:11 +0000 (07:10 +0200)
When unpacking host-supplied NTBs, ncm_unwrap_ntb() checks datagram length
against frame_max but does not verify that the datagram fits within the
declared block length. Additionally, when decoding multiple NTBs from a
single socket buffer, subsequent block lengths are not checked against the
actual remaining buffer data.

With these checks missing, a malicious USB host can specify datagram
offsets and lengths that point beyond the block, or supply secondary NTB
headers declaring lengths larger than the buffer. skb_put_data() then
copies adjacent kernel memory from skb_shared_info into the network skb.

Fix this by verifying that sufficient buffer space remains for the NTB
header before parsing, handling zero-length block declarations, ensuring
that block lengths never exceed the remaining buffer space, and verifying
that each datagram payload stays strictly within the block boundary.

Fixes: 427694cfaafa ("usb: gadget: ncm: Handle decoding of multiple NTB's in unwrap call")
Fixes: 2b74b0a04d3e ("USB: gadget: f_ncm: add bounds checks to ncm_unwrap_ntb()")
Cc: stable <stable@kernel.org>
Assisted-by: Jetski:Gemini-2.5-Pro
Signed-off-by: Sonali Pradhan <sonalipradhan@google.com>
Link: https://patch.msgid.link/20260703083725.1903850-1-sonalipradhan@google.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
drivers/usb/gadget/function/f_ncm.c

index c5bf8a448d64192a1e4f9c94fc6309155ec33e5f..64eabda2f54696248785189182ea61aefcca28c1 100644 (file)
@@ -1189,6 +1189,10 @@ static int ncm_unwrap_ntb(struct gether *port,
        frame_max = ncm_opts->max_segment_size;
 
 parse_ntb:
+       if (to_process < (int)opts->nth_size) {
+               INFO(port->func.config->cdev, "Packet too small for headers\n");
+               goto err;
+       }
        tmp = (__le16 *)ntb_ptr;
 
        /* dwSignature */
@@ -1209,8 +1213,12 @@ parse_ntb:
        tmp++; /* skip wSequence */
 
        block_len = get_ncm(&tmp, opts->block_length);
+       if (block_len == 0)
+               block_len = to_process;
+
        /* (d)wBlockLength */
-       if ((block_len < opts->nth_size + opts->ndp_size) || (block_len > ntb_max)) {
+       if ((block_len < opts->nth_size + opts->ndp_size) || (block_len > ntb_max) ||
+                       (block_len > to_process)) {
                INFO(port->func.config->cdev, "Bad block length: %#X\n", block_len);
                goto err;
        }
@@ -1273,7 +1281,7 @@ parse_ntb:
                        index = index2;
                        /* wDatagramIndex[0] */
                        if ((index < opts->nth_size) ||
-                                       (index > block_len - opts->dpe_size)) {
+                                       (index > block_len)) {
                                INFO(port->func.config->cdev,
                                     "Bad index: %#X\n", index);
                                goto err;
@@ -1285,7 +1293,8 @@ parse_ntb:
                         * ethernet hdr + crc or larger than max frame size
                         */
                        if ((dg_len < 14 + crc_len) ||
-                                       (dg_len > frame_max)) {
+                                       (dg_len > frame_max) ||
+                                       (dg_len > block_len - index)) {
                                INFO(port->func.config->cdev,
                                     "Bad dgram length: %#X\n", dg_len);
                                goto err;
@@ -1310,7 +1319,7 @@ parse_ntb:
                        dg_len2 = get_ncm(&tmp, opts->dgram_item_len);
 
                        /* wDatagramIndex[1] */
-                       if (index2 > block_len - opts->dpe_size) {
+                       if (index2 > block_len) {
                                INFO(port->func.config->cdev,
                                     "Bad index: %#X\n", index2);
                                goto err;