Re: [PATCH net] nfc: nci: fix out-of-bounds read in activation parameter parsing

From: David Heidelberg

Date: Sun Jul 19 2026 - 09:54:59 EST


On 28/06/2026 23:00, Muhammad Bilal wrote:
nci_extract_activation_params_iso_dep() and
nci_extract_activation_params_nfc_dep() receive a pointer into the
RF_INTF_ACTIVATED_NTF notification but are not told how many bytes
remain. Each reads a one-byte length field (rats_res_len,
attrib_res_len, atr_res_len or atr_req_len) and then memcpy()s that many
bytes from the packet. The length is clamped to the destination size,
but it is never checked against the remaining activation-parameter data,
so a notification whose length field is larger than the data present
reads past the end of the buffer.

The sibling nci_extract_rf_params_*() helpers were recently given a
data_len argument and matching remaining-length checks, but the
activation-parameter helpers were not updated.

Pass the remaining length down and validate each field against it before
copying, as the rf_params helpers do.

Fixes: ac2068384034 ("NFC: Parse NCI NFC-DEP activation params")
Cc: stable@xxxxxxxxxxxxxxx
Signed-off-by: Muhammad Bilal <meatuni001@xxxxxxxxx>
---
net/nfc/nci/ntf.c | 36 ++++++++++++++++++++++++++++++------
1 file changed, 30 insertions(+), 6 deletions(-)

Hello Muhammad.

This issue got (partially?) addressed by

https://lore.kernel.org/all/20260612-b4-disp-6d52d8b0-v3-1-e26221f8826d@xxxxxxxxx/

If you feel there is still something to improve, feel free to send patch against the for-linus branch where it's already applied.

Thank you
David