[PATCH v3 0/2] firewire: core: validate descriptor and sub-block lengths in fw_core_add_descriptor()

Sreeraj S Kurup <[email protected]> Sat, 25 Jul 2026 15:52:53 +0000
Newsgroups gmane.linux.kernel,gmane.linux.kernel.firewire.devel
Message-ID <[email protected]>
This two-patch series addresses potential out-of-bounds memory
accesses when parsing Config ROM descriptors in
fw_core_add_descriptor().

Patch 1 adds overall length validation using the in_range() macro
to ensure descriptors fit within standard IEEE 1394 Config ROM
limits (256 quadlets).

Patch 2 validates individual sub-block header lengths during
iteration to prevent reading past allocated buffer boundaries on
malformed inputs.

v2 -> v3:
 - Split original single patch into two distinct commits for cleaner
   review as requested by Takashi Sakamoto.
 - Simplified overall length check using the in_range() macro.

Sreeraj S Kurup (2):
  firewire: core: validate overall descriptor length in
    fw_core_add_descriptor()
  firewire: core: validate sub-block lengths in fw_core_add_descriptor()

 drivers/firewire/core-card.c | 28 ++++++++++++++++++++++------
 1 file changed, 22 insertions(+), 6 deletions(-)

-- 
2.54.0