[PATCH v3 0/2] firewire: core: validate descriptor and sub-block lengths in fw_core_add_descriptor()
Sreeraj S Kurup <[email protected]> Sat, 25 Jul 2026 15:52:53 +0000
| Newsgroups | gmane.linux.kernel,gmane.linux.kernel.firewire.devel |
|---|---|
| Message-ID | <[email protected]> |
This two-patch series addresses potential out-of-bounds memory
accesses when parsing Config ROM descriptors in
fw_core_add_descriptor().
Patch 1 adds overall length validation using the in_range() macro
to ensure descriptors fit within standard IEEE 1394 Config ROM
limits (256 quadlets).
Patch 2 validates individual sub-block header lengths during
iteration to prevent reading past allocated buffer boundaries on
malformed inputs.
v2 -> v3:
- Split original single patch into two distinct commits for cleaner
review as requested by Takashi Sakamoto.
- Simplified overall length check using the in_range() macro.
Sreeraj S Kurup (2):
firewire: core: validate overall descriptor length in
fw_core_add_descriptor()
firewire: core: validate sub-block lengths in fw_core_add_descriptor()
drivers/firewire/core-card.c | 28 ++++++++++++++++++++++------
1 file changed, 22 insertions(+), 6 deletions(-)
--
2.54.0