[lvc-project] [PATCH 5.10/6.1] usb: typec: tcpm: bound altmode_desc[] per iteration in svdm_consume_modes()
Denis Arefev
arefev at swemel.ru
Fri Sep 11 16:35:44 MSK 2026
From: Greg Kroah-Hartman <gregkh at linuxfoundation.org>
commit 3389c149c68c3fea61910ad5d34f7bf3bff44e32 upstream.
svdm_consume_modes() checks pmdata->altmodes against the array size once
before the loop over the count, but forgot to check the bound at every
point in the loop.
In the well-behaved SVDM discovery flow this is harmless because each of
at most SVID_DISCOVERY_MAX SVIDs contributes at most MODE_DISCOVERY_MAX
modes, exactly filling altmode_desc[ALTMODE_DISCOVERY_MAX]. But the
CMDT_RSP_ACK handler in tcpm_pd_svdm() does not correlate an incoming
ACK with any request the port actually sent. Once port->partner is set,
an unsolicited Discover Modes ACK is consumed unconditionally. A broken
or malicious port partner can therefore drive altmodes to
ALTMODE_DISCOVERY_MAX - 1 via the normal flow, and then send one extra
Discover Modes ACK with seven VDOs. Because the pre-loop check passes,
the loop could then writes up to five entries past altmode_desc[]. For
mode_data_prime the next field in struct tcpm_port is the
partner_altmode[] pointer array, which then receives partner-chosen
SVID/VDO bytes.
Move the bound check inside the loop so the array can never be indexed
past ALTMODE_DISCOVERY_MAX regardless of how many VDOs the partner
supplies or how the function was reached.
Assisted-by: gkh_clanker_t1000
Cc: Badhri Jagan Sridharan <badhri at google.com>
Cc: Heikki Krogerus <heikki.krogerus at linux.intel.com>
Cc: stable <stable at kernel.org>
Link: https://patch.msgid.link/2026051351-reshuffle-skillful-90af@gregkh
Signed-off-by: Greg Kroah-Hartman <gregkh at linuxfoundation.org>
[Denis Arefev: adapted for 5.10/6.1: tcpm has no SOP' support here,
svdm_consume_modes() takes no rx_sop_type argument and has a single
pre-loop bound check instead of the two in the SOP/SOP' switch;
drop that one check and add the per-iteration bound check]
Signed-off-by: Denis Arefev <arefev at swemel.ru>
---
Backport fix for CVE-2026-63962
Link: https://nvd.nist.gov/vuln/detail/CVE-2026-63962
---
drivers/usb/typec/tcpm/tcpm.c | 9 ++++-----
1 file changed, 4 insertions(+), 5 deletions(-)
diff --git a/drivers/usb/typec/tcpm/tcpm.c b/drivers/usb/typec/tcpm/tcpm.c
index 6969db16f07c..c3fac41eb387 100644
--- a/drivers/usb/typec/tcpm/tcpm.c
+++ b/drivers/usb/typec/tcpm/tcpm.c
@@ -1541,17 +1541,16 @@ static void svdm_consume_modes(struct tcpm_port *port, const u32 *p, int cnt)
struct typec_altmode_desc *paltmode;
int i;
- if (pmdata->altmodes >= ARRAY_SIZE(port->partner_altmode)) {
- /* Already logged in svdm_consume_svids() */
- return;
- }
-
if (pmdata->svid_index < 0 || pmdata->svid_index >= pmdata->nsvids) {
tcpm_log(port, "Invalid SVID index %d", pmdata->svid_index);
return;
}
for (i = 1; i < cnt; i++) {
+ if (pmdata->altmodes >= ALTMODE_DISCOVERY_MAX) {
+ /* Already logged in svdm_consume_svids() */
+ return;
+ }
paltmode = &pmdata->altmode_desc[pmdata->altmodes];
memset(paltmode, 0, sizeof(*paltmode));
--
2.43.0
More information about the lvc-project
mailing list