Re: [PATCH] net: wwan: mhi_wwan_mbim: validate datagram bounds before copy
flat view
From: Loic Poulain <loic.poulain@oss.qualcomm.com>
Date: 2026-09-07 07:57:23
Also in:
stable
Hi Aamir, Please review AI-generated fixes carefully before submitting them, it will save reviewers time... You've submitted a lot of patches in the last two days. I'd suggest starting with just a few, if not one, to first validate that your process is solid and that your AI-assisted fixes are reliable and double checked, before moving to a bulk submission. On Mon, Sep 7, 2026 at 3:49 AM Aamir Ahmed [off-list ref] wrote:
mhi_mbim_rx() copies datagrams from the NTB using skb_copy_bits() but
never validates that the datagram offset and length from the NDP entry
actually lie within the source skb. If a malicious or buggy modem sends
an NDP entry with dgram_offset + dgram_len > skb->len, skb_copy_bits()
returns -EFAULT and the destination skb is delivered with partially
uninitialized data.
Add a bounds check matching the one in cdc_mbim.c to skip datagrams
that would read past the end of the transfer block.
Fixes: aab8d56c11be ("net: Add Qualcomm MHI MBIM network driver")That hash doesn't exist.
quoted hunk ↗ jump to hunk
Cc: stable@vger.kernel.org Signed-off-by: Aamir Ahmed <redacted> --- drivers/net/wwan/mhi_wwan_mbim.c | 3 +++ 1 file changed, 3 insertions(+)diff --git a/drivers/net/wwan/mhi_wwan_mbim.c b/drivers/net/wwan/mhi_wwan_mbim.c index a94998712597..acdcaceebc48 100644 --- a/drivers/net/wwan/mhi_wwan_mbim.c +++ b/drivers/net/wwan/mhi_wwan_mbim.c@@ -315,6 +315,9 @@ static void mhi_mbim_rx(struct mhi_mbim_context *mbim, struct sk_buff *skb) if (!dgram_offset || !dgram_len) break; /* null terminator */ + if (dgram_offset + dgram_len > skb->len) + continue;
This seems redundant with the existing check in skb_copy_bits(). What would make more sense, however, is to check the return value of skb_copy_bits(). Regards, Loic
+
skbn = netdev_alloc_skb(link->ndev, dgram_len);
if (!skbn)
continue;
--
2.43.0