[PATCH] rose: fix OOB read on short CLEAR REQUEST frames.
Ashutosh Desai <[email protected]> Thu, 9 Apr 2026 01:32:46 +0000
| Newsgroups | org.kernel.vger.linux-hams,org.kernel.vger.linux-kernel,org.kernel.vger.netdev |
|---|---|
| Message-ID | <[email protected]> |
rose_process_rx_frame() dispatches to state machines after calling rose_decode(), but does not verify the frame is long enough before doing so. All five state machine handlers read skb->data[3] and skb->data[4] (cause and diagnostic bytes) when handling a ROSE_CLEAR_REQUEST frame, yet the only upstream length check is ROSE_MIN_LEN (3 bytes) in rose_route_frame(). A crafted 3-byte ROSE CLEAR REQUEST frame (bytes: GFI/LCI-high, LCI-low, 0x13) passes the minimum length gate and reaches the state machines, where skb->data[3] and skb->data[4] are read one and two bytes past the valid buffer respectively. Add a check in rose_process_rx_frame() that drops any CLEAR REQUEST frame shorter than 5 bytes (3-byte header + cause + diagnostic), covering all five state machines with a single guard. Signed-off-by: Ashutosh Desai <[email protected]> --- net/rose/rose_in.c | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/net/rose/rose_in.c b/net/rose/rose_in.c index 0276b393f..1ac9a6aee 100644 --- a/net/rose/rose_in.c +++ b/net/rose/rose_in.c @@ -271,6 +271,11 @@ int rose_process_rx_frame(struct sock *sk, struct sk_buff *skb) frametype = rose_decode(skb, &ns, &nr, &q, &d, &m); + if (frametype == ROSE_CLEAR_REQUEST && skb->len < 5) { + kfree_skb(skb); + return 0; + } + switch (rose->state) { case ROSE_STATE_1: queued = rose_state1_machine(sk, skb, frametype); -- 2.34.1