Re: OOB accesses in ax88179_rx_fixup() (in USB network card driver) - variants

Marcin Kozlowski <[email protected]>
Newsgroups com.openwall.lists.kernel-hardening
Message-ID <CAP6wrbUVPSEUTm7JkL=zv6nzxRbAr=jNPo9ZPBA-_AXz7yCeKQ@mail.gmail.com>
gl620a.c is some usb to usb computer cable, and lg-vl600.c a usb 4g dongle.
Both drivers seem NOT to use skb metadata (they take packet len and count
from skb->data directly).

Why would ASIX driver use metadata and others (those 2) don't?

Could not find any info on skb Metadata.

Thanks,

Marcin

On Mon, 21 Mar 2022, 10:39 Marcin Kozlowski <[email protected]> wrote:

> Hi List,
>
> Don't have much experience and knowledge in that area.
>
> Found this:
>
>
> https://git.kernel.org/pub/scm/linux/kernel/git/gregkh/usb.git/commit/?h=usb-linus&id=57bc3d3ae8c14df3ceb4e17d26ddf9eeab304581
>
> Checked out a few drivers code and wondered if anybody did a variant
> analysis of this (possibly yes?) However, it seems like Kernel drivers code
> for gl620a.c and lg-vl600.c (quick search) don't "Make sure that the bounds
> of the metadata array are inside the SKB (and in front of the counter at
> the end)."
>
> Example from gl620a.c
>
> https://github.com/torvalds/linux/blob/master/drivers/net/usb/gl620a.c
>
> I think, there is no check for:
>
> /* Make sure that the bounds of the metadata array are inside the SKB
> * (and in front of the counter at the end).
> */
> if (pkt_cnt * 2 + hdr_off > skb->len)
> return 0;
>
> Most likely false positive. Would be great to verify this and learn about
> it.
>
> Thanks,
> Marcin
>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.