From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-qv1-f48.google.com (mail-qv1-f48.google.com [209.85.219.48]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id BD4C527FD75 for ; Tue, 19 May 2026 14:30:27 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.219.48 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1779201029; cv=none; b=sxRDmPCtbrXgXfJKwadXbvr/xoehtdPXpJ14UFQ0WsSuyA7K3ODhurtM/kNetejqOOoj86cvsTWtQRfvX2/NQ8oWFnf9eU7W2fjhFWT9yoR8Um3gWoidDeVzSAz3SatPgHoOTh+Pq4PdeRCpm6BlOlqB84sb3Dz4Brqm6rEepms= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1779201029; c=relaxed/simple; bh=xVlYxYIeHhvu7QE0wN2skagDW3LUz6aqOlnUqRxJNac=; h=Date:From:To:Cc:Subject:Message-ID:References:MIME-Version: Content-Type:Content-Disposition:In-Reply-To; b=RYZL59ChExr1TUqRrq7EXV71qy/UHXZMKBhCrhl9853BjB1l3GektauTczdXj8hJFsobmm4uZY58Z5EGD6JajdxePNaXfacJ+8dJUKfXiMj3Xkv7WfC3AY9UbvdGAwcr9nV/d4cPPb9Sjn4AbZPzikMjxkSZ5WH6NrDJEY7KoTM= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=ziepe.ca; spf=pass smtp.mailfrom=ziepe.ca; dkim=pass (2048-bit key) header.d=ziepe.ca header.i=@ziepe.ca header.b=iIAJb4aL; arc=none smtp.client-ip=209.85.219.48 Authentication-Results: smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=ziepe.ca Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=ziepe.ca Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=ziepe.ca header.i=@ziepe.ca header.b="iIAJb4aL" Received: by mail-qv1-f48.google.com with SMTP id 6a1803df08f44-8b4eb1fd5d0so48131796d6.0 for ; Tue, 19 May 2026 07:30:27 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ziepe.ca; s=google; t=1779201027; x=1779805827; darn=vger.kernel.org; h=in-reply-to:content-disposition:mime-version:references:message-id :subject:cc:to:from:date:from:to:cc:subject:date:message-id:reply-to; bh=kaAsMUfND4CCo/Yp/chnDoXFX+KRgMMX2KDfI9OYfN4=; b=iIAJb4aLT5ZKY1jGe1Vf6EZpPanjedpi+yi73vDR2yTRkM/MG2S0WOo4FTbevkvG6D kYGV4e9H7Wo93jnTj5C8I2mY4d35jLRisujo/nn2DGnF/FdxgRE/smwC6F0eYpO9vOwt CH11U2FHxa5rTEsXEdkKlbThln3/ApnMd+OGZcEu1jVwhOuxITVZoVbdrbwdQWa3Q+8/ OYbJov7oDc2GeUtcosGG8Zy/T+Bpum2sRjD5aZUnA+Sndr0qO1Ekrrz3xcXKOA4N1jqO MYznOjjILm2J1tfFSRVP9dUej5eWj+4i4akF3o+hljs4tRttZPPXTKXULwMiuSA/6jng tyxQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1779201027; x=1779805827; h=in-reply-to:content-disposition:mime-version:references:message-id :subject:cc:to:from:date:x-gm-gg:x-gm-message-state:from:to:cc :subject:date:message-id:reply-to; bh=kaAsMUfND4CCo/Yp/chnDoXFX+KRgMMX2KDfI9OYfN4=; b=PjO3PS9jfsOL+zUg4kvUIqoIbnfiPsd7rak9YZP94R110TtenEh3LI7cOIx/BhK0GP bWYKCvqOXsy8NZKyUpcDAXsoG+avnmnCZ19UNh8k65oped09csPlHlI0DppfOOpCuYB1 /iAvTc3vhx9xQUL4q6eH8q/vjS5iJ3d0Czg4LnedEwahv5TO5VM9Y9sFsuvUmHWylnId zlpK3KhoIUWSb2c6lVPTiPpNZg5sZx9KnzVoT7j8y7zjTeZ+YnEYzAWi/o3bPsEYtTTT bG7B2XRFVw9/0NjZTSZYbC5Wc18o037peIjgdCitqWWQDhGWOvmP86pnv3coKTjEshVp rdUQ== X-Forwarded-Encrypted: i=1; AFNElJ9nr+eJOraok0JPF5F146TNP0rK/PBSwIqunI+XH55p0nObkNKwpax+2zhm2ZXjO/u3ciDDToq8wIiJEjY=@vger.kernel.org X-Gm-Message-State: AOJu0YwCkIeLqW0C6LJeupzg12+OtrPLi9267dM3jPYrLyo0cTCDUTVb 5Q9QuziljKM4qKu5836eBBnCjWW3MpHM69UkVbo2Bwj6LK9Yl1ZTihqcBa5eVQlWEuY= X-Gm-Gg: Acq92OHM1DvYRwH/RyMzokpngbx6sNDYKH8RHa6MV+gbKpkoFX+1U3Nm1zmbNEOojNZ IC19Csx2dH9mGu/kM21kYxiicyuWv8UkN8UBaozz9uaOUUx4KsUxMy8BFqEGH9EWmVtLraVemSA S6vpFyocG5lfl/qolgQ0ELja41X8Y2QX/syUI3b88W3j+RhP2RpWSwAktY4iA+4jW2TbN5EaUph Em+JNcEYNug+tE5ygLX0jONsxddvGfDJ2gpSd5PfddFyAkEOiwzF77jWnSgqBbV974pOjPnYbrC pwKJMYSXe2hy6GQazatv7g8AN0o2JAVom1FoiVAXTkKdlZlT3Ed/7TEElyf+ZUwfVPX2qUcLkNG PKucFHxTyW8JETHlZNFd9BjZxLzPPK7SKb0oEJiEMMReieCKbtlWVAK8GGYZ+TjZiOK9ozkw9NZ gvWmIuwPYblmI6PcHK/tjSq8NHQJIziNmueLUB0XB2XH7t3txPt66A51TKrcbTDRaM9QxB3UdFj +bdiWChyVI988Z7 X-Received: by 2002:a05:6214:46a0:b0:8a5:104b:e361 with SMTP id 6a1803df08f44-8ca0f6f3944mr322587386d6.50.1779201026652; Tue, 19 May 2026 07:30:26 -0700 (PDT) Received: from ziepe.ca (crbknf0213w-47-54-130-67.pppoe-dynamic.high-speed.nl.bellaliant.net. [47.54.130.67]) by smtp.gmail.com with ESMTPSA id 6a1803df08f44-8ca3608c1desm91696546d6.2.2026.05.19.07.30.26 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 19 May 2026 07:30:26 -0700 (PDT) Received: from jgg by wakko with local (Exim 4.97) (envelope-from ) id 1wPLSj-0000000F7UP-2wvG; Tue, 19 May 2026 11:30:25 -0300 Date: Tue, 19 May 2026 11:30:25 -0300 From: Jason Gunthorpe To: Heechan Kang Cc: Brett Creeley , Dave Jiang , Saeed Mahameed , Jonathan Cameron , Greg Kroah-Hartman , linux-kernel@vger.kernel.org, stable@vger.kernel.org Subject: Re: [PATCH] fwctl: pds: Validate RPC input size before parsing Message-ID: <20260519143025.GC7702@ziepe.ca> References: <20260517062232.1858747-1-gganji11@naver.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <20260517062232.1858747-1-gganji11@naver.com> On Sun, May 17, 2026 at 03:22:32PM +0900, Heechan Kang wrote: > The fwctl core allocates the device-specific RPC input buffer with > fwctl_rpc.in_len and passes that buffer to the driver callback. > > pdsfc_fw_rpc() casts the buffer to struct fwctl_rpc_pds and then calls > pdsfc_validate_rpc(), which reads fields from that structure before > checking that the input buffer is large enough to contain it. A short > in_len can make pds_fwctl read beyond the allocation. > > Reject pds RPC buffers that are smaller than struct fwctl_rpc_pds before > parsing any pds-specific fields. > > Fixes: 92c66ee829b9 ("pds_fwctl: add rpc and query support") > Cc: stable@vger.kernel.org # v6.15+ > Signed-off-by: Heechan Kang > --- > drivers/fwctl/pds/main.c | 3 +++ > 1 file changed, 3 insertions(+) Applied to for-rc, thanks Jason