From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-oo1-f49.google.com (mail-oo1-f49.google.com [209.85.161.49]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 1243D32B130 for ; Sat, 8 Aug 2026 22:39:09 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.161.49 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786228751; cv=none; b=GnJv33l51K6ZGtTFdivBLj21m/VjRrXxsE9tOVUh47ZNYYFefHZutA738WMuZJY85d08MZa5SWvT/ABzG20tvt7qLqyCXCnL1NTuDrcU9AVZPIlcidgCRnJufKGsNmgQtmJ4yUwrsBmhkXqVYS5YzdiyLrMHIXk5ZlQPccfa6L0= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786228751; c=relaxed/simple; bh=niXm/N5BBBtoVsM6jszdquk/kqKSZ0XTjTTqc2jw024=; h=Message-ID:Date:MIME-Version:Subject:To:Cc:References:From: In-Reply-To:Content-Type; b=KE8yOWL2Ii8kFdRCYypkYIh6X4eODUxa98I7YLBsU74XhXdYUytZHWLB2nU6Vi5+8/hegfp9SOAD2LBBH5yRzI7s6/EMZPZ8r8571aoOh0cvTZvf4prGu0EAf4VW/gKEacxckZF9DBbTJwwxSMRQ+JvDk+EUDg45Lj9FmdvCEco= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=baylibre.com; spf=pass smtp.mailfrom=baylibre.com; dkim=pass (2048-bit key) header.d=baylibre.com header.i=@baylibre.com header.b=Oh/Tgfna; arc=none smtp.client-ip=209.85.161.49 Authentication-Results: smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=baylibre.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=baylibre.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=baylibre.com header.i=@baylibre.com header.b="Oh/Tgfna" Received: by mail-oo1-f49.google.com with SMTP id 006d021491bc7-6b03e59a9b4so209775eaf.3 for ; Sat, 08 Aug 2026 15:39:09 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=baylibre.com; s=google; t=1786228749; x=1786833549; darn=vger.kernel.org; h=content-transfer-encoding:content-type:in-reply-to:from :content-language:references:cc:to:subject:user-agent:mime-version :date:message-id:from:to:cc:subject:date:message-id:reply-to :content-type; bh=JI1+G+6qkA/DFYJt6nTy2HlA5K1RIKwf70bN14N3C2Y=; b=Oh/TgfnagF/GCeKHVj3gjdlNvejOI/5ukn23yMPxGVyPI/08a4La9EJ3mjnv7inS0x WYUpm/xr7rLYV7WfPCFLkrFC1wNaIIkcPP3TiZbflbBrRV9YfQQWg1ltcVZEh7ISCbyI 2TnIy/PX0Jcz91+I+61KmE58ELkqC0FwOAlrcZo+Px8YDJyUUDSGV/P8vWy7k0G2B0q8 FqLsKfQFgEXvJ0OrpyMTS+OqmJOrCz1AWDT1Y+jE+U9IjElCCPrqF28l04sVWqxR+vTy +ApmCrcMqrZ5LC4BVTyTX4Ixbqwqaz0jYWHE5javPvHYwTxZ3cbJbJnAZdPzv7XWjJiH FUtA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786228749; x=1786833549; h=content-transfer-encoding:content-type:in-reply-to:from :content-language:references:cc:to:subject:user-agent:mime-version :date:message-id:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=JI1+G+6qkA/DFYJt6nTy2HlA5K1RIKwf70bN14N3C2Y=; b=ClMrx7M7xksB7C9lkCNEeVmZKtiBP+Fy6saRdNN44O3qItPUZr/zOoC9+GVz1jKYfN pKZScGXuAvnHpTkGXlLwpzE/eGIMypfJSpBzVplkPfMRvSp6c44h5KucJPwtHJeuP3XZ dbx9OPe1oIDn+xQKNo27eVLR3cnpsuiHbC9tt5Mzp7lEEEZo1QX8Re5JdVt3JW+Wo/qY HE7SNEfxuD8DowLRN++q2egpLe65lXQMHNTmKw5ZzPsoJ4H+9mi+TOaCWlTleIy6yUya kM1TFtFp6cJZ8uFnRe4MmSD6+9+DIG0qfYLTmaICIeyTMnlbd4O1PDhEFUUutYS1efsC Hb2w== X-Forwarded-Encrypted: i=1; AHgh+RqjiRsoBNfzf2eejVN7pzGJHus91q5VYN9TzwZR+u/gkCaKeDSAXz8zEKUakQwG0v+Lld1SeR5bQTDrGKI=@vger.kernel.org X-Gm-Message-State: AOJu0YxqH861xlxjfm3w0LetWWOA4QSQBpEXit1GdMVFjeKzZd9AgN2j CpOwjJ6pbdR4mZmbGP9S0xvO6CCYTXXptu25Yco1/ngCZhKYjtUTo4HfHQRXibx4wpU= X-Gm-Gg: AR+sD13RRTatgs5MWPJxoeVNke3Yf7xn3k6C2ETJz7nT5Vl9tnZGRg7COAL/J4P4G94 xe9qDcSzq/43IAgPhdLotT3UvHYQFljq3z9U/EmCwmz7m8TT38b2VhFvjMKPLIQrkU4O5B/LWgq E4lzc8IoOeaEUa0pQ81MskdShu1q3QGoV8yr8edSEktU0qwqlFfnJVkR9QkxbmdxL5wfgBSMJnu A4YpSueEZw7EoLi/rojl7OfrO4XYw91Wf6Zx1QX2fdw/QXUgWcvUErk2jr2h1zQYKpJGeLmQKi7 DXjL7reOTKBuCoGJ4Q5bWQnOfVeXWwcgF8m+HfwCiARh8yhMqd1gNjUHRke8ZWPrDb2RNAHclL/ E7lQCXnan0K++58Ful9H/V4vajqMBjkX191LqcojZNHjDsnaoWAyqQXkOfoN2p8x+N1IhMCRD8E sI0lnxTtA/hwE6iRtgXBFOfpLiWPeCMMOmVKEzspQa2m5s6cOifUbswQZhN3LktGh49CK1Rx2WU uXL8doWa0rzImM2ZX5+aP3kfbxXQKuvfZ6QLbVf X-Received: by 2002:a05:6820:992:b0:6ae:9815:7c8e with SMTP id 006d021491bc7-6b04213b973mr5509347eaf.21.1786228748829; Sat, 08 Aug 2026 15:39:08 -0700 (PDT) Received: from ?IPV6:2600:8803:e7e4:500:99c2:f16e:201c:3bb5? ([2600:8803:e7e4:500:99c2:f16e:201c:3bb5]) by smtp.gmail.com with ESMTPSA id 586e51a60fabf-459f1a0224bsm4901696fac.3.2026.08.08.15.39.06 (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Sat, 08 Aug 2026 15:39:07 -0700 (PDT) Message-ID: Date: Sat, 8 Aug 2026 17:39:05 -0500 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 User-Agent: Mozilla Thunderbird Subject: Re: [PATCH RESEND v2] iio: accel: fxls8962af: clamp FIFO sample count To: Shengzhuo Wei , Jonathan Cameron , =?UTF-8?Q?Nuno_S=C3=A1?= , Andy Shevchenko , Sean Nyekjaer Cc: linux-iio@vger.kernel.org, linux-kernel@vger.kernel.org, stable@vger.kernel.org, Joshua Crofts References: <20260809-fxls8962af-fifo-v2-1-80ff1be1f1f2@cherr.cc> Content-Language: en-US From: David Lechner In-Reply-To: <20260809-fxls8962af-fifo-v2-1-80ff1be1f1f2@cherr.cc> Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit On 8/8/26 4:04 PM, Shengzhuo Wei wrote: > fxls8962af_fifo_flush() copies the number of samples the device reports > in its FIFO status register into an on-stack buffer > > u16 buffer[FXLS8962AF_FIFO_LENGTH * 3]; > > which is sized for at most FXLS8962AF_FIFO_LENGTH (32) samples. The > sample count is read from the BUF_STATUS register and only masked to its > 6 valid bits (0..63), with no clamp to the buffer size. The watermark > path caps the count on the write side (fxls8962af_set_watermark) but > the read path does not, so a malfunctioning or malicious device > reporting BUF_CNT > 32 overflows the buffer. > > Clamp count to FXLS8962AF_FIFO_LENGTH, mirroring the watermark clamp. > > Fixes: 79e3a5bdd9ef ("iio: accel: fxls8962af: add hw buffered sampling") > Cc: stable@vger.kernel.org > Assisted-by: GLM:5.2 > Reviewed-by: Joshua Crofts > Signed-off-by: Shengzhuo Wei > --- > The transfer reads count * 6 bytes through regmap, so a device reporting > up to 63 samples writes up to 378 bytes into the 192-byte buffer, > clobbering the stack canary, saved registers and the return address. > This mirrors the bmc150 fix (ce0e1cae2609). A well-formed flush reports > at most FXLS8962AF_FIFO_LENGTH samples, so legitimate devices are > unaffected. > --- When you do a RESEND, please say here why, otherwise we don't know. Did something change? > Changes in v2: > - Use min() instead of min_t() as suggested by Andy Shevchenko. > - Link to v1: https://lore.kernel.org/r/20260806-fxls8962af-fifo-v1-1-bd9d27047fee@cherr.cc > --- > drivers/iio/accel/fxls8962af-core.c | 2 ++ > 1 file changed, 2 insertions(+) > > diff --git a/drivers/iio/accel/fxls8962af-core.c b/drivers/iio/accel/fxls8962af-core.c > index d0c2a8daef0db964134ad10b25782b9f5752613d..18d7b09bddd2b4f506c3348bf4e8cf94ce1c554a 100644 > --- a/drivers/iio/accel/fxls8962af-core.c > +++ b/drivers/iio/accel/fxls8962af-core.c > @@ -969,6 +969,8 @@ static int fxls8962af_fifo_flush(struct iio_dev *indio_dev) > if (!count) > return 0; > > + count = min(count, FXLS8962AF_FIFO_LENGTH); > + > data->old_timestamp = data->timestamp; > data->timestamp = iio_get_time_ns(indio_dev); > > > --- > base-commit: 848acc8ffe1b7cd5f1bf427b93069becfebc2c9d > change-id: 20260806-fxls8962af-fifo-c3812fd02eeb > > Best regards,