mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH net] net: usb: sierra_net: reject short firmware attribute reads
@ 2026-10-05 15:59 Xinsheng Zhu
  2026-10-08  2:30 ` patchwork-bot+netdevbpf
  0 siblings, 1 reply; 2+ messages in thread
From: Xinsheng Zhu @ 2026-10-05 15:59 UTC (permalink / raw)
  To: netdev
  Cc: linux-usb, linux-kernel, andrew+netdev, davem, edumazet, kuba,
	pabeni, rfiler, epasheva

sierra_net_get_fw_attr() only checks usbnet_read_cmd() for negative
return values before converting attrdata and storing it in *datap.
A zero-length or one-byte response leaves attrdata wholly or partially
uninitialized.

Although sierra_net_bind() rejects responses of unexpected length, its
dev_dbg() call uses fwattr before that check. When the debug message is
enabled, the incomplete value may therefore be used in the debug output.

Require the return value to equal sizeof(attrdata) before accessing the
buffer. Return -EIO for short reads, retaining the existing handling of
negative errors and leaving the output parameter untouched on failure.

Found by manual code inspection with LLM assistance. The issue has not
been reproduced at runtime.

Fixes: eb4fd8cd355c ("net/usb: add sierra_net.c driver")
Signed-off-by: Xinsheng Zhu <xinsheng.zhu.ny@gmail.com>
---
 drivers/net/usb/sierra_net.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/net/usb/sierra_net.c b/drivers/net/usb/sierra_net.c
index 4d3ed642b3e7..95668a5ccd5f 100644
--- a/drivers/net/usb/sierra_net.c
+++ b/drivers/net/usb/sierra_net.c
@@ -637,7 +637,7 @@ static int sierra_net_get_fw_attr(struct usbnet *dev, u16 *datap)
 				sizeof(attrdata)	/* __u16 size */
 				);
 
-	if (result < 0)
+	if (result != sizeof(attrdata))
 		return -EIO;
 
 	*datap = le16_to_cpu(attrdata);

base-commit: 8b4e7209c842d8cb9516f1f5ef0a88aa2d8831a6
-- 
2.54.0 (Apple Git-157)


^ permalink raw reply	[flat|nested] 2+ messages in thread

* Re: [PATCH net] net: usb: sierra_net: reject short firmware attribute reads
  2026-10-05 15:59 [PATCH net] net: usb: sierra_net: reject short firmware attribute reads Xinsheng Zhu
@ 2026-10-08  2:30 ` patchwork-bot+netdevbpf
  0 siblings, 0 replies; 2+ messages in thread
From: patchwork-bot+netdevbpf @ 2026-10-08  2:30 UTC (permalink / raw)
  To: Xinsheng Zhu
  Cc: netdev, linux-usb, linux-kernel, andrew+netdev, davem, edumazet,
	kuba, pabeni, rfiler, epasheva

Hello:

This patch was applied to netdev/net-next.git (main)
by Jakub Kicinski <kuba@kernel.org>:

On Mon,  5 Oct 2026 11:59:20 -0400 you wrote:
> sierra_net_get_fw_attr() only checks usbnet_read_cmd() for negative
> return values before converting attrdata and storing it in *datap.
> A zero-length or one-byte response leaves attrdata wholly or partially
> uninitialized.
> 
> Although sierra_net_bind() rejects responses of unexpected length, its
> dev_dbg() call uses fwattr before that check. When the debug message is
> enabled, the incomplete value may therefore be used in the debug output.
> 
> [...]

Here is the summary with links:
  - [net] net: usb: sierra_net: reject short firmware attribute reads
    https://git.kernel.org/netdev/net-next/c/8df0638138d3

You are awesome, thank you!
-- 
Deet-doot-dot, I am a bot.
https://korg.docs.kernel.org/patchwork/pwbot.html



^ permalink raw reply	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2026-10-08  2:30 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-10-05 15:59 [PATCH net] net: usb: sierra_net: reject short firmware attribute reads Xinsheng Zhu
2026-10-08  2:30 ` patchwork-bot+netdevbpf

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®