From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-pf1-f171.google.com (mail-pf1-f171.google.com [209.85.210.171]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 52F9938737A for ; Sat, 25 Jul 2026 15:54:38 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.210.171 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784994883; cv=none; b=h2NjDPsvlGotUY+lGvd+etO0nZUh1htzlUJuHDVe9LLB1z6poMZsWbZpVCh1sZnUDiMoC/law/iTE6HPLYCHEptdfS64eQsC32++hTgRrbjbONh4T3YZVQ+FE4vnhFBPcPrAtuMyygRpG9qx7iQGy9OHDNY/syf5/zSc/Kh/fp0= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784994883; c=relaxed/simple; bh=+Dl2Fw3dYrXgqut748OOBNd969DO/1NVbI/srwxRy7o=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=daN7XVoYOPp4F8I9poGiMGiKlCOHAjsP125oO+/e0AWb4hZ6ofJ3FqllYgeApH/cCGGDJPtrNooV6LYPeNMa0CbFN7+MPN3t4jIECDWGM924Oa997mt468NMpyGcBAGSQTx1OejD6lUeB7G7ur8AzW0auCbikzmbUj/4hZAxNKg= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=h6NowhY/; arc=none smtp.client-ip=209.85.210.171 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="h6NowhY/" Received: by mail-pf1-f171.google.com with SMTP id d2e1a72fcca58-848479c9bd5so1018558b3a.3 for ; Sat, 25 Jul 2026 08:54:36 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1784994874; x=1785599674; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=A3Sw79SCITjfwhxPgpHfkwizRSWcwfTYmPLW8/OAOMU=; b=h6NowhY/ntt+oMl6KSelp7eS1hTI68mXPWxbvY3y0xcO+0/abSqFRFUA37wTIGWcEF KyxvFgWyfGq8thFpl/ahm4fOxceDRruVl3MCxZWTjIPsWDGnp8ENQgLe+mzmdb8tvIde L2O5k8+1wx5ZZ5lioFAskKoNJwRr889xuPlofUUWQop1r1gZhhY+NfzHcUNA9a9yNTTl ENdFfD6bGqkXsgwpcBcB+lipme2IuTng961lOrijYPoo69L3Fzso6q1V6qpwoGu8I9k6 38UB+V9VZpTZGwIqwHQOU8GBCf6OvmGaxbWzHEaRiDCZgbNBHI3io9HieMzOyEbRC6hK v3kQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784994874; x=1785599674; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=A3Sw79SCITjfwhxPgpHfkwizRSWcwfTYmPLW8/OAOMU=; b=Eo21sTITP2VKpUdqthoFq8nNsyerCrp3VtQ9xVqLfMN0LS1N8cfposgcJ7iT+E2/KR wRtX4lfgrxW4WbkXHwelS6agK2tSfZ/usRGzraOh0xpjzxH+iDOpj1Tj8l24+f7YLiMg gHZg8DM2T6ZNucyIWcxryEexEaezwFG43ZTmRUOJrkgUiz7RPlM9bVnOf1SaRKV+cyDa 9pUguMoetyHSw9id6zcLszsKlt+/QzK7NyuQhTKeOPye4A5P5p/8++PWtMQE4yHEslVP /9vFA4ZOPhYTonnSMZ9YZMe8PEEPoQfoUdOvA5PIh0DH9j528/VxQKXi+yphaz5SnPJU r79w== X-Forwarded-Encrypted: i=1; AHgh+RpIrQkykjb26+YL7WY64ja0QUMdUd0mdRdTEdGheUdhZu5BY09iT6FoGzLpLVmI6AmDfZD2Io+Jf8zNCoM=@vger.kernel.org X-Gm-Message-State: AOJu0YyOqzqS4dpChzSzVvy5t4hu+ph8rm8voA8qP8JQ+djy9CpdXoWi Amajv8MR4T/KXRDiWUZ5esc38SGjofPPV+KBhr1NXGD0UslXwuJvzogSLEzRV5UNfNw= X-Gm-Gg: AR+sD113wN7/rqJdezr7LD6OzsxWzwYzzuuY7P7gN8rLOhC1L++1BcQQSn6Rc1QPmmm 1A1A+bIXJNEZB1EWhdHqQ2F615tbY6kg2f/uxhPe1Zhc85qKXTKqVqJQi0QJQKcuS+qeu47JUul zGAEe9ypiSXeCY9WIpHdR3T6Q3wOpVIBrISqARra4nwsKxf4nybKys/9AjCz1edtKJCDGobe53a /kzp6w0YWD6Axniu5sp7j2fjJtmD+FgzTgEOAD8ao2ZPIJUf/A9xYL+RInMvV6/DHSw40aSmmHu j1Sfw0qe+lUNjDBWSXseFKChx7H7329g+YZ8foa/X6Iv/MVyA++M3Anpo2j2pnLmexg260DzDIt mNmaqVELM+j4k7qQ5x76/RQHudlN72vtTE0QhYs5pUyI7EeZZm5Zwny3akqWNXQNHm+r/7MYSfM Ia5Cc+VLGTJwuuUtufPUvtBUu+u3oPUxSK2WTg X-Received: by 2002:a05:6a21:4c03:b0:3c0:b55a:80ff with SMTP id adf61e73a8af0-3c67da78f78mr2764152637.24.1784994873766; Sat, 25 Jul 2026 08:54:33 -0700 (PDT) Received: from localhost.localdomain ([103.149.158.159]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-314bc549b11sm12630500eec.18.2026.07.25.08.54.31 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sat, 25 Jul 2026 08:54:33 -0700 (PDT) From: Sreeraj S Kurup To: o-takashi@sakamocchi.jp Cc: linux1394-devel@lists.sourceforge.net, linux-kernel@vger.kernel.org, Sreeraj S Kurup Subject: [PATCH V3 v3 1/2] firewire: core: validate overall descriptor length in fw_core_add_descriptor() Date: Sat, 25 Jul 2026 15:52:54 +0000 Message-ID: <20260725155255.3054-2-sreekuttan2156239@gmail.com> X-Mailer: git-send-email 2.54.0 In-Reply-To: <20260725155255.3054-1-sreekuttan2156239@gmail.com> References: <20260725155255.3054-1-sreekuttan2156239@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit In fw_core_add_descriptor(), incoming descriptor structures are processed without checking whether the descriptor's specified length falls within valid boundaries. An empty descriptor (length 0) or an oversized descriptor exceeding the IEEE 1394 Config ROM capacity can lead to invalid processing. Add bounds checking at the start of fw_core_add_descriptor() using the in_range() helper macro to reject descriptors with length 0 or length exceeding 256 quadlets (the standard maximum Configuration ROM size). Signed-off-by: Sreeraj S Kurup --- drivers/firewire/core-card.c | 10 +++++----- 1 file changed, 5 insertions(+), 5 deletions(-) diff --git a/drivers/firewire/core-card.c b/drivers/firewire/core-card.c index a754c6366b97..eaec54ea287a 100644 --- a/drivers/firewire/core-card.c +++ b/drivers/firewire/core-card.c @@ -16,6 +16,7 @@ #include #include #include +#include #include #include @@ -167,11 +168,10 @@ int fw_core_add_descriptor(struct fw_descriptor *desc) { size_t i; - /* - * Check descriptor is valid; the length of all blocks in the - * descriptor has to add up to exactly the length of the - * block. - */ + /* Reject empty descriptors or those exceeding max Config ROM size (256 quadlets) */ + if (!in_range(desc->length, 1, 256)) + return -EINVAL; + i = 0; while (i < desc->length) i += (desc->data[i] >> 16) + 1; -- 2.54.0