+2
−0
Loading
mainline inclusion from mainline-v6.14-rc1 commit 110b43ef05342d5a11284cc8b21582b698b4ef1c category: bugfix bugzilla: https://gitee.com/src-openeuler/kernel/issues/IBPC8J CVE: CVE-2025-21735 Reference: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=110b43ef05342d5a11284cc8b21582b698b4ef1c -------------------------------- The "pipe" variable is a u8 which comes from the network. If it's more than 127, then it results in memory corruption in the caller, nci_hci_connect_gate(). Cc: stable@vger.kernel.org Fixes: a1b0b941 ("NFC: nci: Create pipe on specific gate in nci_hci_connect_gate") Signed-off-by:Dan Carpenter <dan.carpenter@linaro.org> Reviewed-by:
Simon Horman <horms@kernel.org> Reviewed-by:
Krzysztof Kozlowski <krzysztof.kozlowski@linaro.org> Link: https://patch.msgid.link/bcf5453b-7204-4297-9c20-4d8c7dacf586@stanley.mountain Signed-off-by:
Jakub Kicinski <kuba@kernel.org> Signed-off-by:
Yang Yingliang <yangyingliang@huawei.com>