Thread (4 messages) 4 messages, 2 authors, 29d ago

Re: [PATCH] net: wwan: mhi_wwan_mbim: validate datagram bounds before copy

flat view

From: Loic Poulain <loic.poulain@oss.qualcomm.com>
Date: 2026-09-07 07:57:23
Also in: stable

Hi Aamir,

Please review AI-generated fixes carefully before submitting them, it
will save reviewers time...

You've submitted a lot of patches in the last two days. I'd suggest
starting with just a few, if not one, to first validate that your
process is solid and that your AI-assisted fixes are reliable and
double checked, before moving to a bulk submission.

On Mon, Sep 7, 2026 at 3:49 AM Aamir Ahmed [off-list ref] wrote:
mhi_mbim_rx() copies datagrams from the NTB using skb_copy_bits() but
never validates that the datagram offset and length from the NDP entry
actually lie within the source skb. If a malicious or buggy modem sends
an NDP entry with dgram_offset + dgram_len > skb->len, skb_copy_bits()
returns -EFAULT and the destination skb is delivered with partially
uninitialized data.

Add a bounds check matching the one in cdc_mbim.c to skip datagrams
that would read past the end of the transfer block.

Fixes: aab8d56c11be ("net: Add Qualcomm MHI MBIM network driver")
That hash doesn't exist.
quoted hunk ↗ jump to hunk
Cc: stable@vger.kernel.org
Signed-off-by: Aamir Ahmed <redacted>
---
 drivers/net/wwan/mhi_wwan_mbim.c | 3 +++
 1 file changed, 3 insertions(+)
diff --git a/drivers/net/wwan/mhi_wwan_mbim.c b/drivers/net/wwan/mhi_wwan_mbim.c
index a94998712597..acdcaceebc48 100644
--- a/drivers/net/wwan/mhi_wwan_mbim.c
+++ b/drivers/net/wwan/mhi_wwan_mbim.c
@@ -315,6 +315,9 @@ static void mhi_mbim_rx(struct mhi_mbim_context *mbim, struct sk_buff *skb)
                        if (!dgram_offset || !dgram_len)
                                break; /* null terminator */

+                       if (dgram_offset + dgram_len > skb->len)
+                               continue;
This seems redundant with the existing check in skb_copy_bits().
What would make more sense, however, is to check the return value of
skb_copy_bits().

Regards,
Loic

+
                        skbn = netdev_alloc_skb(link->ndev, dgram_len);
                        if (!skbn)
                                continue;
--
2.43.0
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help