Commit ca4d4c34 authored by Dan Carpenter's avatar Dan Carpenter Committed by David S. Miller
Browse files

nfc: pn533: prevent potential memory corruption



If the "type_a->nfcid_len" is too large then it would lead to memory
corruption in pn533_target_found_type_a() when we do:

	memcpy(nfc_tgt->nfcid1, tgt_type_a->nfcid_data, nfc_tgt->nfcid1_len);

Fixes: c3b1e1e8 ("NFC: Export NFCID1 from pn533")
Signed-off-by: default avatarDan Carpenter <dan.carpenter@oracle.com>
Signed-off-by: default avatarDavid S. Miller <davem@davemloft.net>
parent 8577dd8a
Loading
Loading
Loading
Loading
+3 −0
Original line number Diff line number Diff line
@@ -706,6 +706,9 @@ static bool pn533_target_type_a_is_valid(struct pn533_target_type_a *type_a,
	if (PN533_TYPE_A_SEL_CASCADE(type_a->sel_res) != 0)
		return false;

	if (type_a->nfcid_len > NFC_NFCID1_MAXSIZE)
		return false;

	return true;
}