Re: [PATCH] mfd: iqs62x: reject zero-length firmware records

Lee Jones <[email protected]>
Newsgroups dev.linux.lists.mfd,org.kernel.vger.linux-kernel
Message-ID <[email protected]>
On Mon, 06 Jul 2026, Pengpeng Hou wrote:

> From: Pengpeng <[email protected]>
> 
> The IQS62x firmware parser treats the first data byte as part of
> struct iqs62x_fw_rec and advances by len - 1 after the fixed record
> header. A zero length record would underflow that arithmetic and leave
> later type-specific reads without a valid current record payload.
> 
> Reject zero-length records and compare the declared tail length against
> the remaining firmware bytes without open-coded subtraction on the
> cursor.
> 
> Signed-off-by: Pengpeng <[email protected]>

Nit: Your Author and Signed-off-by tags should use your full name.

> ---
>  drivers/mfd/iqs62x.c | 2 +-
>  1 file changed, 1 insertion(+), 1 deletion(-)
> 
> diff --git a/drivers/mfd/iqs62x.c b/drivers/mfd/iqs62x.c
> index ee017617d1d1..412ae7777f72 100644
> --- a/drivers/mfd/iqs62x.c
> +++ b/drivers/mfd/iqs62x.c
> @@ -237,7 +237,7 @@ static int iqs62x_firmware_parse(struct iqs62x_core *iqs62x,
>  		fw_rec = (struct iqs62x_fw_rec *)(fw->data + pos);
>  		pos += sizeof(*fw_rec);
>  
> -		if (pos + fw_rec->len - 1 > fw->size) {
> +		if (!fw_rec->len || fw_rec->len - 1 > fw->size - pos) {
>  			ret = -EINVAL;
>  			break;
>  		}
> -- 
> 2.43.0
> 

-- 
Lee Jones
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.