Thread (2 messages) flat view 2 messages, 2 authors, 21d ago
COLD21d

[PATCH net-next v2] net: usb: cx82310_eth: bound partial-frame remainder by current skb length

From: Jason Winter <hidden>
Date: 2026-08-17 19:47:56
Also in: linux-usb
Subsystem: networking drivers, the rest, usb networking drivers · Maintainers: Andrew Lunn, "David S. Miller", Eric Dumazet, Jakub Kicinski, Paolo Abeni, Linus Torvalds

When a frame straddles two bulk URBs, cx82310_rx_fixup() stores the
number of bytes still expected in dev->partial_rem and on the next call
memcpy()s that many bytes from the new skb without checking that the new
URB actually delivered that much data. A malicious device can declare a
large frame in one URB and follow it with a short URB, causing the
memcpy to read past the valid skb data into uncleared bytes in the
receive buffer and forward the result up the network stack.

Drop the partial frame and reset the carry-over state if the current skb
is shorter than the recorded remainder.

Assisted-by: gkh_clanker_t1000
Signed-off-by: Jason Winter <redacted>
---
Changes in v2:
- Target net-next and drop the Fixes tag.
- No code changes.

 drivers/net/usb/cx82310_eth.c | 7 +++++++
 1 file changed, 7 insertions(+)
diff --git a/drivers/net/usb/cx82310_eth.c b/drivers/net/usb/cx82310_eth.c
index 068acb052adb..8ca6b75fdd20 100644
--- a/drivers/net/usb/cx82310_eth.c
+++ b/drivers/net/usb/cx82310_eth.c
@@ -251,6 +251,13 @@ static int cx82310_rx_fixup(struct usbnet *dev, struct sk_buff *skb)
 	 * end of that packet at the beginning.
 	 */
 	if (dev->partial_rem) {
+		if (dev->partial_rem > skb->len) {
+			netdev_err(dev->net,
+				   "RX partial frame: need %lu, got %u\n",
+				   dev->partial_rem, skb->len);
+			dev->partial_rem = 0;
+			return 0;
+		}
 		len = dev->partial_len + dev->partial_rem;
 		skb2 = alloc_skb(len, GFP_ATOMIC);
 		if (!skb2)
-- 
2.55.0
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help