mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Sreeraj S Kurup <sreekuttan2156239@gmail.com>
To: o-takashi@sakamocchi.jp
Cc: linux1394-devel@lists.sourceforge.net,
	linux-kernel@vger.kernel.org,
	Sreeraj S Kurup <sreekuttan2156239@gmail.com>
Subject: [PATCH V3 v3 1/2] firewire: core: validate overall descriptor length in fw_core_add_descriptor()
Date: Sat, 25 Jul 2026 15:52:54 +0000	[thread overview]
Message-ID: <20260725155255.3054-2-sreekuttan2156239@gmail.com> (raw)
In-Reply-To: <20260725155255.3054-1-sreekuttan2156239@gmail.com>

In fw_core_add_descriptor(), incoming descriptor structures are processed
without checking whether the descriptor's specified length falls within
valid boundaries. An empty descriptor (length 0) or an oversized descriptor
exceeding the IEEE 1394 Config ROM capacity can lead to invalid processing.

Add bounds checking at the start of fw_core_add_descriptor() using the
in_range() helper macro to reject descriptors with length 0 or length
exceeding 256 quadlets (the standard maximum Configuration ROM size).

Signed-off-by: Sreeraj S Kurup <sreekuttan2156239@gmail.com>
---
 drivers/firewire/core-card.c | 10 +++++-----
 1 file changed, 5 insertions(+), 5 deletions(-)

diff --git a/drivers/firewire/core-card.c b/drivers/firewire/core-card.c
index a754c6366b97..eaec54ea287a 100644
--- a/drivers/firewire/core-card.c
+++ b/drivers/firewire/core-card.c
@@ -16,6 +16,7 @@
 #include <linux/list.h>
 #include <linux/module.h>
 #include <linux/mutex.h>
+#include <linux/minmax.h>
 #include <linux/spinlock.h>
 #include <linux/workqueue.h>
 
@@ -167,11 +168,10 @@ int fw_core_add_descriptor(struct fw_descriptor *desc)
 {
 	size_t i;
 
-	/*
-	 * Check descriptor is valid; the length of all blocks in the
-	 * descriptor has to add up to exactly the length of the
-	 * block.
-	 */
+	/* Reject empty descriptors or those exceeding max Config ROM size (256 quadlets) */
+	if (!in_range(desc->length, 1, 256))
+		return -EINVAL;
+
 	i = 0;
 	while (i < desc->length)
 		i += (desc->data[i] >> 16) + 1;
-- 
2.54.0


  reply	other threads:[~2026-07-25 15:54 UTC|newest]

Thread overview: 4+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-07-25 15:52 [PATCH v3 0/2] firewire: core: validate descriptor and sub-block lengths " Sreeraj S Kurup
2026-07-25 15:52 ` Sreeraj S Kurup [this message]
2026-07-25 15:52 ` [PATCH V3 v3 2/2] firewire: core: validate " Sreeraj S Kurup
2026-07-27  0:47 ` [PATCH v3 0/2] firewire: core: validate descriptor and " Takashi Sakamoto

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260725155255.3054-2-sreekuttan2156239@gmail.com \
    --to=sreekuttan2156239@gmail.com \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux1394-devel@lists.sourceforge.net \
    --cc=o-takashi@sakamocchi.jp \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®