Skip to content

Commit 012406f

Browse files
Badhri Jagan Sridharangregkh
authored andcommitted
usb: typec: tcpm: Validate SVID index in svdm_consume_modes()
commit 7b681dd upstream. In svdm_consume_modes(), the SVID value is read from pmdata->svids using pmdata->svid_index as an array index without bounds validation: paltmode->svid = pmdata->svids[pmdata->svid_index]; If pmdata->svid_index is driven beyond SVID_DISCOVERY_MAX (16), it results in an out-of-bounds read of the pmdata->svids array. Because pd_mode_data is embedded inside struct tcpm_port, indexing past svids reads into adjacent fields. In particular: - At index 16, it reads the altmodes count. - At index 18 and beyond, it reads into altmode_desc[], which contains partner-supplied SVDM Discovery Modes VDOs. By injecting a chosen SVID into altmode_desc[0].vdo and driving svid_index to 20, the partner can force paltmode->svid to be loaded with an arbitrary, partner- chosen SVID, which is then registered via typec_partner_register_altmode(). Fix this by validating that pmdata->svid_index is non-negative and strictly less than pmdata->nsvids before accessing the pmdata->svids array inside svdm_consume_modes(). Assisted-by: Antigravity:gemini-3.5-flash Fixes: 4ab8c18 ("usb: typec: Register a device for every mode") Cc: stable <stable@kernel.org> Signed-off-by: Badhri Jagan Sridharan <badhri@google.com> Reviewed-by: RD Babiera <rdbabiera@google.com> Acked-by: Heikki Krogerus <heikki.krogerus@linux.intel.com> Link: https://patch.msgid.link/20260622220803.305750-1-badhri@google.com Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
1 parent a82450b commit 012406f

1 file changed

Lines changed: 5 additions & 0 deletions

File tree

drivers/usb/typec/tcpm/tcpm.c

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1555,6 +1555,11 @@ static void svdm_consume_modes(struct tcpm_port *port, const u32 *p, int cnt)
15551555
return;
15561556
}
15571557

1558+
if (pmdata->svid_index < 0 || pmdata->svid_index >= pmdata->nsvids) {
1559+
tcpm_log(port, "Invalid SVID index %d", pmdata->svid_index);
1560+
return;
1561+
}
1562+
15581563
for (i = 1; i < cnt; i++) {
15591564
paltmode = &pmdata->altmode_desc[pmdata->altmodes];
15601565
memset(paltmode, 0, sizeof(*paltmode));

0 commit comments

Comments
 (0)