nfc: nci: assert requested protocol is valid
authorJeremy Cline <jeremy@jcline.org>
Mon, 9 Oct 2023 20:00:54 +0000 (16:00 -0400)
committerPaolo Abeni <pabeni@redhat.com>
Thu, 12 Oct 2023 07:32:10 +0000 (09:32 +0200)
The protocol is used in a bit mask to determine if the protocol is
supported. Assert the provided protocol is less than the maximum
defined so it doesn't potentially perform a shift-out-of-bounds and
provide a clearer error for undefined protocols vs unsupported ones.

Fixes: 6a2968aaf50c ("NFC: basic NCI protocol implementation")
Reported-and-tested-by: syzbot+0839b78e119aae1fec78@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=0839b78e119aae1fec78
Signed-off-by: Jeremy Cline <jeremy@jcline.org>
Reviewed-by: Simon Horman <horms@kernel.org>
Link: https://lore.kernel.org/r/20231009200054.82557-1-jeremy@jcline.org
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
net/nfc/nci/core.c

index fff755d..6c9592d 100644 (file)
@@ -909,6 +909,11 @@ static int nci_activate_target(struct nfc_dev *nfc_dev,
                return -EINVAL;
        }
 
+       if (protocol >= NFC_PROTO_MAX) {
+               pr_err("the requested nfc protocol is invalid\n");
+               return -EINVAL;
+       }
+
        if (!(nci_target->supported_protocols & (1 << protocol))) {
                pr_err("target does not support the requested protocol 0x%x\n",
                       protocol);