From: Sasha Levin <sashal@kernel.org>
To: linux-kernel@vger.kernel.org, stable@vger.kernel.org
Cc: Justin Tee <justin.tee@broadcom.com>,
Himanshu Madhani <himanshu.madhani@oracle.com>,
"Martin K . Petersen" <martin.petersen@oracle.com>,
Sasha Levin <sashal@kernel.org>,
james.smart@broadcom.com, dick.kennedy@broadcom.com,
jejb@linux.ibm.com, linux-scsi@vger.kernel.org
Subject: [PATCH AUTOSEL 5.4 04/31] scsi: lpfc: Fix possible file string name overflow when updating firmware
Date: Tue, 16 Jan 2024 15:02:13 -0500 [thread overview]
Message-ID: <20240116200310.259340-4-sashal@kernel.org> (raw)
In-Reply-To: <20240116200310.259340-1-sashal@kernel.org>
From: Justin Tee <justin.tee@broadcom.com>
[ Upstream commit f5779b529240b715f0e358489ad0ed933bf77c97 ]
Because file_name and phba->ModelName are both declared a size 80 bytes,
the extra ".grp" file extension could cause an overflow into file_name.
Define a ELX_FW_NAME_SIZE macro with value 84. 84 incorporates the 4 extra
characters from ".grp". file_name is changed to be declared as a char and
initialized to zeros i.e. null chars.
Signed-off-by: Justin Tee <justin.tee@broadcom.com>
Link: https://lore.kernel.org/r/20231031191224.150862-3-justintee8345@gmail.com
Reviewed-by: Himanshu Madhani <himanshu.madhani@oracle.com>
Signed-off-by: Martin K. Petersen <martin.petersen@oracle.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/scsi/lpfc/lpfc.h | 1 +
drivers/scsi/lpfc/lpfc_init.c | 4 ++--
2 files changed, 3 insertions(+), 2 deletions(-)
diff --git a/drivers/scsi/lpfc/lpfc.h b/drivers/scsi/lpfc/lpfc.h
index 088b764aefa4..7ce0d94cdc01 100644
--- a/drivers/scsi/lpfc/lpfc.h
+++ b/drivers/scsi/lpfc/lpfc.h
@@ -32,6 +32,7 @@
struct lpfc_sli2_slim;
#define ELX_MODEL_NAME_SIZE 80
+#define ELX_FW_NAME_SIZE 84
#define LPFC_PCI_DEV_LP 0x1
#define LPFC_PCI_DEV_OC 0x2
diff --git a/drivers/scsi/lpfc/lpfc_init.c b/drivers/scsi/lpfc/lpfc_init.c
index af5238ab6309..f5e509381563 100644
--- a/drivers/scsi/lpfc/lpfc_init.c
+++ b/drivers/scsi/lpfc/lpfc_init.c
@@ -12527,7 +12527,7 @@ lpfc_write_firmware(const struct firmware *fw, void *context)
int
lpfc_sli4_request_firmware_update(struct lpfc_hba *phba, uint8_t fw_upgrade)
{
- uint8_t file_name[ELX_MODEL_NAME_SIZE];
+ char file_name[ELX_FW_NAME_SIZE] = {0};
int ret;
const struct firmware *fw;
@@ -12536,7 +12536,7 @@ lpfc_sli4_request_firmware_update(struct lpfc_hba *phba, uint8_t fw_upgrade)
LPFC_SLI_INTF_IF_TYPE_2)
return -EPERM;
- snprintf(file_name, ELX_MODEL_NAME_SIZE, "%s.grp", phba->ModelName);
+ scnprintf(file_name, sizeof(file_name), "%s.grp", phba->ModelName);
if (fw_upgrade == INT_FW_UPGRADE) {
ret = request_firmware_nowait(THIS_MODULE, FW_ACTION_HOTPLUG,
--
2.43.0
next prev parent reply other threads:[~2024-01-16 20:03 UTC|newest]
Thread overview: 32+ messages / expand[flat|nested] mbox.gz Atom feed top
2024-01-16 20:02 [PATCH AUTOSEL 5.4 01/31] wifi: rt2x00: restart beacon queue when hardware reset Sasha Levin
2024-01-16 20:02 ` [PATCH AUTOSEL 5.4 02/31] selftests/bpf: satisfy compiler by having explicit return in btf test Sasha Levin
2024-01-16 20:02 ` [PATCH AUTOSEL 5.4 03/31] selftests/bpf: Fix pyperf180 compilation failure with clang18 Sasha Levin
2024-01-16 20:02 ` Sasha Levin [this message]
2024-01-16 20:02 ` [PATCH AUTOSEL 5.4 05/31] PCI: Add no PM reset quirk for NVIDIA Spectrum devices Sasha Levin
2024-01-16 20:02 ` [PATCH AUTOSEL 5.4 06/31] bonding: return -ENOMEM instead of BUG in alb_upper_dev_walk Sasha Levin
2024-01-16 20:02 ` [PATCH AUTOSEL 5.4 07/31] ARM: dts: imx7d: Fix coresight funnel ports Sasha Levin
2024-01-16 20:02 ` [PATCH AUTOSEL 5.4 08/31] ARM: dts: imx7s: Fix lcdif compatible Sasha Levin
2024-01-16 20:02 ` [PATCH AUTOSEL 5.4 09/31] ARM: dts: imx7s: Fix nand-controller #size-cells Sasha Levin
2024-01-16 20:02 ` [PATCH AUTOSEL 5.4 10/31] wifi: ath9k: Fix potential array-index-out-of-bounds read in ath9k_htc_txstatus() Sasha Levin
2024-01-16 20:02 ` [PATCH AUTOSEL 5.4 11/31] bpf: Add map and need_defer parameters to .map_fd_put_ptr() Sasha Levin
2024-01-17 4:16 ` Hou Tao
2024-01-16 20:02 ` [PATCH AUTOSEL 5.4 12/31] scsi: libfc: Don't schedule abort twice Sasha Levin
2024-01-16 20:02 ` [PATCH AUTOSEL 5.4 13/31] scsi: libfc: Fix up timeout error in fc_fcp_rec_error() Sasha Levin
2024-01-16 20:02 ` [PATCH AUTOSEL 5.4 14/31] ARM: dts: rockchip: fix rk3036 hdmi ports node Sasha Levin
2024-01-16 20:02 ` [PATCH AUTOSEL 5.4 15/31] ARM: dts: imx25/27-eukrea: Fix RTC node name Sasha Levin
2024-01-16 20:02 ` [PATCH AUTOSEL 5.4 16/31] ARM: dts: imx: Use flash@0,0 pattern Sasha Levin
2024-01-16 20:02 ` [PATCH AUTOSEL 5.4 17/31] ARM: dts: imx27: Fix sram node Sasha Levin
2024-01-16 20:02 ` [PATCH AUTOSEL 5.4 18/31] ARM: dts: imx1: " Sasha Levin
2024-01-16 20:02 ` [PATCH AUTOSEL 5.4 19/31] ARM: dts: imx25/27: Pass timing0 Sasha Levin
2024-01-16 20:02 ` [PATCH AUTOSEL 5.4 20/31] ARM: dts: imx27-apf27dev: Fix LED name Sasha Levin
2024-01-16 20:02 ` [PATCH AUTOSEL 5.4 21/31] ARM: dts: imx23-sansa: Use preferred i2c-gpios properties Sasha Levin
2024-01-16 20:02 ` [PATCH AUTOSEL 5.4 22/31] ARM: dts: imx23/28: Fix the DMA controller node name Sasha Levin
2024-01-16 20:02 ` [PATCH AUTOSEL 5.4 23/31] block: prevent an integer overflow in bvec_try_merge_hw_page Sasha Levin
2024-01-16 20:02 ` [PATCH AUTOSEL 5.4 24/31] md: Whenassemble the array, consult the superblock of the freshest device Sasha Levin
2024-01-16 20:02 ` [PATCH AUTOSEL 5.4 25/31] arm64: dts: qcom: msm8996: Fix 'in-ports' is a required property Sasha Levin
2024-01-16 20:02 ` [PATCH AUTOSEL 5.4 26/31] arm64: dts: qcom: msm8998: Fix 'out-ports' " Sasha Levin
2024-01-16 20:02 ` [PATCH AUTOSEL 5.4 27/31] wifi: rtl8xxxu: Add additional USB IDs for RTL8192EU devices Sasha Levin
2024-01-16 20:02 ` [PATCH AUTOSEL 5.4 28/31] libbpf: Fix NULL pointer dereference in bpf_object__collect_prog_relos Sasha Levin
2024-01-16 20:02 ` [PATCH AUTOSEL 5.4 29/31] wifi: rtlwifi: add calculate_bit_shift() Sasha Levin
2024-01-16 20:02 ` [PATCH AUTOSEL 5.4 30/31] wifi: rtlwifi: rtl8723{be,ae}: using calculate_bit_shift() Sasha Levin
2024-01-16 20:02 ` [PATCH AUTOSEL 5.4 31/31] wifi: cfg80211: free beacon_ies when overridden from hidden BSS Sasha Levin
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20240116200310.259340-4-sashal@kernel.org \
--to=sashal@kernel.org \
--cc=dick.kennedy@broadcom.com \
--cc=himanshu.madhani@oracle.com \
--cc=james.smart@broadcom.com \
--cc=jejb@linux.ibm.com \
--cc=justin.tee@broadcom.com \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-scsi@vger.kernel.org \
--cc=martin.petersen@oracle.com \
--cc=stable@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®