Re: [PATCH net v3 3/3] ieee802154: ca8210: validate data_ind length upfront in ca8210_skb_rx()
From: Miquel Raynal
Date: Sun Oct 04 2026 - 17:00:27 EST
Hi Hui Peng,
>
> msdulen = data_ind[22]; /* msdu_length */
> if (msdulen > IEEE802154_MTU) {
> @@ -1778,9 +1774,25 @@ static int ca8210_skb_rx(
> &priv->spi->dev,
> "received erroneously large msdu length!\n"
> );
> - kfree_skb(skb);
> return -EMSGSIZE;
> }
> +
> + if (len < 30 + msdulen ||
> + (!priv->promiscuous && data_ind[29 + msdulen] > 0 &&
> + len < 29 + msdulen + sizeof(struct secspec))) {
> + dev_err(&priv->spi->dev,
> + "received truncated data indication!\n");
> + return -EMSGSIZE;
> + }
I'm sorry, but this is pure AI illusion of security. I'm pretty sure
this check is tailored to match your very specific need but has no
meaning except just covering the very specific case initially
discovered. I don't know what to propose, but I can't send a Reviewed-by
for that.
Miquèl