Re: [PATCH net v2] nfc: llcp: reject PDUs shorter than the LLCP header

David Laight <[email protected]> Mon, 13 Jul 2026 22:15:56 +0100
Newsgroups dev.linux.lists.oe-linux-nfc,org.kernel.vger.linux-kernel,org.kernel.vger.netdev,org.kernel.vger.stable
Message-ID <20260713221556.13a830b8@pumpkin>
On Mon, 13 Jul 2026 17:58:48 +0200
Doruk Tan Ozturk <[email protected]> wrote:

> Every LLCP PDU begins with a two-byte header (DSAP/SSAP + PTYPE), but the
> receive path never checked that a frame is at least LLCP_HEADER_SIZE bytes
> before parsing it.

Is there a similar problem with non-linear skb?
Maybe they can't get into this code, but who knows what can happen
with unusual configs.

	David


> A peer LLCP PDU travels: NFC-DEP frame -> nfc_tm_data_received() (target /
> NCI path) or nfc_llcp_recv() (initiator data-exchange callback) ->
> __nfc_llcp_recv() -> rx_work -> nfc_llcp_rx_skb() ->
> nfc_llcp_recv_connect(). For a CONNECT (or CC) PDU nfc_llcp_recv_connect()
> computes
> 
> 	tlv_array_len = skb->len - LLCP_HEADER_SIZE;
> 
> as a size_t and hands it to the TLV walk. When skb->len is 0 or 1 the
> subtraction wraps to a huge value and the walk runs far past the skb,
> causing an out-of-bounds read; nfc_llcp_ptype()/nfc_llcp_ssap() likewise
> read pdu->data[1] for such a short frame.
> 
> A nearby NFC device can reach this without authentication; LLCP link
> activation happens automatically after NFC-DEP.
> 
> Reject PDUs shorter than the LLCP header in __nfc_llcp_recv(), the common
> choke point shared by both the target (nfc_llcp_data_received()) and
> initiator (nfc_llcp_recv()) receive paths, so a short skb is freed before
> the rx_work worker is scheduled.
> 
> Reproduced with a KFENCE out-of-bounds read via /dev/virtual_nci on
> linux-next.
> 
> Found by 0sec (https://0sec.ai) using automated source analysis.
> 
> Fixes: d646960f7986 ("NFC: Initial LLCP support")
> Cc: [email protected]
> Assisted-by: 0sec:claude-opus-4-8
> Signed-off-by: Doruk Tan Ozturk <[email protected]>
> ---
> v2: move the check into __nfc_llcp_recv() so a short skb is dropped
>     before the rx_work worker is scheduled (Vadim Fedorenko), which also
>     covers the initiator nfc_llcp_recv() path. Reword the commit message
>     (drop the "same guard as AGF" wording) and add a KFENCE reproduction
>     note.
> 
>  net/nfc/llcp_core.c | 5 +++++
>  1 file changed, 5 insertions(+)
> 
> diff --git a/net/nfc/llcp_core.c b/net/nfc/llcp_core.c
> index aed5fe1afef0..72b6e707ad0c 100644
> --- a/net/nfc/llcp_core.c
> +++ b/net/nfc/llcp_core.c
> @@ -1565,6 +1565,11 @@ static void nfc_llcp_rx_work(struct work_struct *work)
>  
>  static void __nfc_llcp_recv(struct nfc_llcp_local *local, struct sk_buff *skb)
>  {
> +	if (skb->len < LLCP_HEADER_SIZE) {
> +		kfree_skb(skb);
> +		return;
> +	}
> +
>  	local->rx_pending = skb;
>  	timer_delete(&local->link_timer);
>  	schedule_work(&local->rx_work);