digital_tg_recv_sens_req() reads resp->data[0] into sens_req before
checking !resp->len, so a zero-length response causes a out-of-bounds
read before the guard that was meant to prevent it.
Fix by checking resp->len first and returning -EINVAL early, then
reading resp->data[0] only when the buffer is known non-empty.
Fixes: bf30a67c947e ("NFC: digital: Add tg_listen_md and tg_get_rf_tech driver hooks")
Signed-off-by: Ömer Mete Kaya <redacted>
---
net/nfc/digital_technology.c | 9 +++++++--
1 file changed, 7 insertions(+), 2 deletions(-)
diff --git a/net/nfc/digital_technology.c b/net/nfc/digital_technology.c
index ae6487c10..b27d45e05 100644
--- a/net/nfc/digital_technology.c
+++ b/net/nfc/digital_technology.c
@@ -1097,10 +1097,15 @@ void digital_tg_recv_sens_req(struct nfc_digital_dev *ddev, void *arg,
goto exit;
}
+ if (!resp->len) {
+ rc = -EINVAL;
+ goto exit;
+ }
+
sens_req = resp->data[0];
- if (!resp->len || (sens_req != DIGITAL_CMD_SENS_REQ &&
- sens_req != DIGITAL_CMD_ALL_REQ)) {
+ if (sens_req != DIGITAL_CMD_SENS_REQ &&
+ sens_req != DIGITAL_CMD_ALL_REQ) {
rc = -EINVAL;
goto exit;
}
--2.55.0