Thread (4 messages) 4 messages, 2 authors, 23d ago

[PATCH] net: wwan: mhi_wwan_mbim: validate datagram bounds before copy

COLD23d

From: Aamir Ahmed <hidden>
Date: 2026-09-07 01:49:57
Also in: stable
Subsystem: networking drivers, the rest, wwan drivers · Maintainers: Andrew Lunn, "David S. Miller", Eric Dumazet, Jakub Kicinski, Paolo Abeni, Linus Torvalds, Loic Poulain, Sergey Ryazanov

mhi_mbim_rx() copies datagrams from the NTB using skb_copy_bits() but
never validates that the datagram offset and length from the NDP entry
actually lie within the source skb. If a malicious or buggy modem sends
an NDP entry with dgram_offset + dgram_len > skb->len, skb_copy_bits()
returns -EFAULT and the destination skb is delivered with partially
uninitialized data.

Add a bounds check matching the one in cdc_mbim.c to skip datagrams
that would read past the end of the transfer block.

Fixes: aab8d56c11be ("net: Add Qualcomm MHI MBIM network driver")
Cc: stable@vger.kernel.org
Signed-off-by: Aamir Ahmed <redacted>
---
 drivers/net/wwan/mhi_wwan_mbim.c | 3 +++
 1 file changed, 3 insertions(+)
diff --git a/drivers/net/wwan/mhi_wwan_mbim.c b/drivers/net/wwan/mhi_wwan_mbim.c
index a94998712597..acdcaceebc48 100644
--- a/drivers/net/wwan/mhi_wwan_mbim.c
+++ b/drivers/net/wwan/mhi_wwan_mbim.c
@@ -315,6 +315,9 @@ static void mhi_mbim_rx(struct mhi_mbim_context *mbim, struct sk_buff *skb)
 			if (!dgram_offset || !dgram_len)
 				break; /* null terminator */
 
+			if (dgram_offset + dgram_len > skb->len)
+				continue;
+
 			skbn = netdev_alloc_skb(link->ndev, dgram_len);
 			if (!skbn)
 				continue;
-- 
2.43.0
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help