[PATCH v3 0/2] thunderbolt: validate DROM entry extents

Pengpeng Hou <[email protected]>
Newsgroups org.kernel.vger.linux-usb,org.kernel.vger.linux-kernel
Message-ID <[email protected]>
The generic DROM walker can read a two-byte entry header from a one-byte
tail and accepts an entry whose declared length is shorter than that
header.  Separately, the USB4 product descriptor parser reads a complete
struct tb_drom_entry_desc without requiring that structure to be present.

Split those contracts into two patches.  The descriptor check now uses
sizeof(*desc), as requested by Mika Westerberg, instead of spelling out
the fields manually.

Changes since v2:
https://lore.kernel.org/all/[email protected]/
- split the generic entry and USB4 descriptor checks
- validate the USB4 entry with sizeof(*desc)
- rebase and re-review against the current tree

The series was reviewed statically. I did not test it with malformed
device DROM data.

Pengpeng Hou (2):
  thunderbolt: require complete DROM entry headers
  thunderbolt: validate USB4 product descriptor entry size

 drivers/thunderbolt/eeprom.c | 18 +++++++++++++++---
 1 file changed, 15 insertions(+), 3 deletions(-)

base-commit: f5bbbfec59b4e2fb7520a91de3df8a6174325d6a

-- 
2.50.1 (Apple Git-155)
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.