Received: by 2002:a05:6358:3188:b0:123:57c1:9b43 with SMTP id q8csp38303999rwd; Wed, 12 Jul 2023 06:04:57 -0700 (PDT) X-Google-Smtp-Source: APBJJlF4duVY+Wze7o0GWGnYYw3PqBJslK0yYzdEf5ZNA7z/fyOyiTkjoZxrNWs0UD1Tbwg3FuWu X-Received: by 2002:ac2:4438:0:b0:4f8:7568:e94b with SMTP id w24-20020ac24438000000b004f87568e94bmr12637222lfl.56.1689167097554; Wed, 12 Jul 2023 06:04:57 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1689167097; cv=none; d=google.com; s=arc-20160816; b=EsVTxNlbiKfO3mK/GUK2evzn94xi5J2iLu3Zlb2HwdPijsQo6z5inhGnwDpyyLkKyq K0LMkIgJbB+LC4ehHGYQdqCvm7HfHdu07l7+bYdODYieP/GYtyw2Gm4l32tbD+RR/VPd pNiEQtY2HsJLLtsP3ehXrsWvdLL4GOwZqQ7yoUytQy/bM97jpCMUVdoaocUWjC8ELVAn gotVyzwC/OZzVtHAYFHyE/+vjO2OPBz+z7/lfNZvfggw8+jd3K4ue0g0JLPGIFFe8CoU RHLC6mCgANqGtt19INnZJ1O59fJzSJ0xRpfojwkHpHFz3B4gn4A2bTY6lOOczL5mPEn7 whAw== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:mime-version:user-agent :content-transfer-encoding:references:in-reply-to:date:cc:to:from :subject:message-id:dkim-signature; bh=7Mwy7Es+QCyPK8S0J7Ou3RSKVlLA8cMmzE6C5fqkOHA=; fh=fz6xnxjj3dx6Qe4l7K4UceZWikfGqTJ2tsaP7e+L+Lo=; b=TOtFPPF+97U35M+gLPZDYiDDKLhmczowQ4rWRBM6cCAvugTMvT6L7THevngoNE0+nm YsqY6tbyepR+1BGn5tb83rsB1Usg+tJKvRv7XijqF8nRAa2LJ7NvJG9DUxgQm7Yqzndz aaiNMJ2Ro5PWiTzKVnZJe+2UX9ufRSqG+cBiVHK7eVdxzVKjszqoTnqTWOPk0zcZzGU2 JG0U5nV/f/g7EUPUoOCGhK3aLoEdTBgk79ijs9XMWqAucQoYCFm6j3G/A/SfuGWyncst TbwVKIx86O6M2Vj8kxNc+Ycnz/SqyXwpelfPv/RJ9+2mnbPMVmd9waq+iXP0Y2JFoHWS 41aw== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@sipsolutions.net header.s=mail header.b=lTJQKVJQ; spf=pass (google.com: domain of linux-wireless-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) smtp.mailfrom=linux-wireless-owner@vger.kernel.org; dmarc=pass (p=NONE sp=REJECT dis=NONE) header.from=sipsolutions.net Return-Path: Received: from out1.vger.email (out1.vger.email. [2620:137:e000::1:20]) by mx.google.com with ESMTP id bf11-20020a0564021a4b00b0051decf83dbesi3963550edb.205.2023.07.12.06.04.42; Wed, 12 Jul 2023 06:04:57 -0700 (PDT) Received-SPF: pass (google.com: domain of linux-wireless-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) client-ip=2620:137:e000::1:20; Authentication-Results: mx.google.com; dkim=pass header.i=@sipsolutions.net header.s=mail header.b=lTJQKVJQ; spf=pass (google.com: domain of linux-wireless-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) smtp.mailfrom=linux-wireless-owner@vger.kernel.org; dmarc=pass (p=NONE sp=REJECT dis=NONE) header.from=sipsolutions.net Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S232984AbjGLNBY (ORCPT + 61 others); Wed, 12 Jul 2023 09:01:24 -0400 Received: from lindbergh.monkeyblade.net ([23.128.96.19]:37652 "EHLO lindbergh.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S232140AbjGLNBW (ORCPT ); Wed, 12 Jul 2023 09:01:22 -0400 Received: from sipsolutions.net (s3.sipsolutions.net [IPv6:2a01:4f8:191:4433::2]) by lindbergh.monkeyblade.net (Postfix) with ESMTPS id A32E11736; Wed, 12 Jul 2023 06:01:21 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sipsolutions.net; s=mail; h=MIME-Version:Content-Transfer-Encoding: Content-Type:References:In-Reply-To:Date:Cc:To:From:Subject:Message-ID:Sender :Reply-To:Content-ID:Content-Description:Resent-Date:Resent-From:Resent-To: Resent-Cc:Resent-Message-ID; bh=7Mwy7Es+QCyPK8S0J7Ou3RSKVlLA8cMmzE6C5fqkOHA=; t=1689166881; x=1690376481; b=lTJQKVJQ0RPkEhlLeGsUvjhJ8cZTUvPvlbyrvRA0ca2shVP 4qzyOZsbdOT9RQqGOduZI6pNscXb4ICTxR3URWwCGE3B0oKUDI//r1Zx4jgw2rsQley5ejlfZ6ZDH Dm6kQEuXVK4xv3px1jMCbPi14z5EmyCyHHQguVbRj9kFh4FTns7MON+UZeG2VK8/ATQyS7RAYlWp3 0jthUan8usKKksdYCPnJjjSmmzMgmbxvo1NmjFGmIl9wPl9fZ9nJour2V6Lf/4Jypzx4Qu+7WPdT1 qafw8pHYLW1dWz5l+hDGgijp2miEyceMK6mogTvKFGak0joMLqZ62vX/QvVnfIWA==; Received: by sipsolutions.net with esmtpsa (TLS1.3:ECDHE_X25519__RSA_PSS_RSAE_SHA256__AES_256_GCM:256) (Exim 4.96) (envelope-from ) id 1qJZSk-00GfuA-1M; Wed, 12 Jul 2023 15:00:58 +0200 Message-ID: <6a4a8980912380085ea628049b5e19e38bcd8e1d.camel@sipsolutions.net> Subject: Re: [PATCH] USB: disable all RNDIS protocol drivers From: Johannes Berg To: Oliver Neukum , Greg Kroah-Hartman , Enrico Mioso Cc: Jan Engelhardt , linux-kernel@vger.kernel.org, "David S. Miller" , Eric Dumazet , Jakub Kicinski , Paolo Abeni , Kalle Valo , Oleksij Rempel , Maciej =?UTF-8?Q?=C5=BBenczykowski?= , Neil Armstrong , Mauro Carvalho Chehab , Andrzej Pietrasiewicz , Jacopo Mondi , =?UTF-8?Q?=C5=81ukasz?= Stelmach , Laurent Pinchart , linux-usb@vger.kernel.org, netdev@vger.kernel.org, linux-wireless@vger.kernel.org, Ilja Van Sprundel , Joseph Tartaro Date: Wed, 12 Jul 2023 15:00:55 +0200 In-Reply-To: References: <20221123124620.1387499-1-gregkh@linuxfoundation.org> <2023070430-fragment-remember-2fdd@gregkh> Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable User-Agent: Evolution 3.48.4 (3.48.4-1.fc38) MIME-Version: 1.0 X-malware-bazaar: not-scanned X-Spam-Status: No, score=-2.1 required=5.0 tests=BAYES_00,DKIM_SIGNED, DKIM_VALID,DKIM_VALID_AU,DKIM_VALID_EF,RCVD_IN_DNSWL_BLOCKED, SPF_HELO_PASS,SPF_PASS,T_SCC_BODY_TEXT_LINE,URIBL_BLOCKED autolearn=ham autolearn_force=no version=3.4.6 X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on lindbergh.monkeyblade.net Precedence: bulk List-ID: X-Mailing-List: linux-wireless@vger.kernel.org On Wed, 2023-07-12 at 11:22 +0200, Oliver Neukum wrote: >=20 > On 04.07.23 08:47, Greg Kroah-Hartman wrote: > > On Mon, Jul 03, 2023 at 11:11:57PM +0200, Enrico Mioso wrote: > > > Hi all!! > > >=20 > > > I think the rndis_host USB driver might emit a warning in the dmesg, = but disabling the driver wouldn't be a good idea. > > > The TP-Link MR6400 V1 LTE modem and also some ZTE modems integrated i= n routers do use this protocol. > > >=20 > > > We may also distinguish between these cases and devices you might plu= g in - as they pose different risk levels. > >=20 > > Again, you have to fully trust the other side of an RNDIS connection, > > any hints on how to have the kernel determine that? > it is a network protocol. So this statement is kind of odd. > Are you saying that there are RNDIS messages that cannot be verified > for some reason, that still cannot be disclosed? Agree, it's also just a USB device, so no special trickery with DMA, shared buffers, etc. I mean, yeah, the RNDIS code is really old and almost certainly has a severe lack of input validation, but that still doesn't mean it's fundamentally impossible. johannes