| From 759209074f8aefd79d7a835c410d558ee33a23f1 Mon Sep 17 00:00:00 2001 |
| From: Sasha Levin <sashal@kernel.org> |
| Date: Mon, 1 Nov 2021 10:12:12 +0300 |
| Subject: Bluetooth: stop proccessing malicious adv data |
| |
| From: Pavel Skripkin <paskripkin@gmail.com> |
| |
| [ Upstream commit 3a56ef719f0b9682afb8a86d64b2399e36faa4e6 ] |
| |
| Syzbot reported slab-out-of-bounds read in hci_le_adv_report_evt(). The |
| problem was in missing validaion check. |
| |
| We should check if data is not malicious and we can read next data block. |
| If we won't check ptr validness, code can read a way beyond skb->end and |
| it can cause problems, of course. |
| |
| Fixes: e95beb414168 ("Bluetooth: hci_le_adv_report_evt code refactoring") |
| Reported-and-tested-by: syzbot+e3fcb9c4f3c2a931dc40@syzkaller.appspotmail.com |
| Signed-off-by: Pavel Skripkin <paskripkin@gmail.com> |
| Signed-off-by: Marcel Holtmann <marcel@holtmann.org> |
| Signed-off-by: Sasha Levin <sashal@kernel.org> |
| --- |
| net/bluetooth/hci_event.c | 8 +++++++- |
| 1 file changed, 7 insertions(+), 1 deletion(-) |
| |
| diff --git a/net/bluetooth/hci_event.c b/net/bluetooth/hci_event.c |
| index 9f52145bb7b76..7ffcca9ae82a1 100644 |
| --- a/net/bluetooth/hci_event.c |
| +++ b/net/bluetooth/hci_event.c |
| @@ -5661,7 +5661,8 @@ static void hci_le_adv_report_evt(struct hci_dev *hdev, struct sk_buff *skb) |
| struct hci_ev_le_advertising_info *ev = ptr; |
| s8 rssi; |
| |
| - if (ev->length <= HCI_MAX_AD_LENGTH) { |
| + if (ev->length <= HCI_MAX_AD_LENGTH && |
| + ev->data + ev->length <= skb_tail_pointer(skb)) { |
| rssi = ev->data[ev->length]; |
| process_adv_report(hdev, ev->evt_type, &ev->bdaddr, |
| ev->bdaddr_type, NULL, 0, rssi, |
| @@ -5671,6 +5672,11 @@ static void hci_le_adv_report_evt(struct hci_dev *hdev, struct sk_buff *skb) |
| } |
| |
| ptr += sizeof(*ev) + ev->length + 1; |
| + |
| + if (ptr > (void *) skb_tail_pointer(skb) - sizeof(*ev)) { |
| + bt_dev_err(hdev, "Malicious advertising data. Stopping processing"); |
| + break; |
| + } |
| } |
| |
| hci_dev_unlock(hdev); |
| -- |
| 2.34.1 |
| |