]> git.ipfire.org Git - thirdparty/kernel/linux.git/commitdiff
usb: typec: altmodes/displayport: validate count before reading Status Update VDO
authorGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Wed, 13 May 2026 15:52:49 +0000 (17:52 +0200)
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Tue, 19 May 2026 10:25:35 +0000 (12:25 +0200)
A broken/malicious device can send the incorrect count for a status
update VDO, which will cause the kernel to read uninitialized stack data
and send it off elsewhere.

Fix this up by correctly verifying the count for the update object.

Assisted-by: gkh_clanker_t1000
Cc: stable <stable@kernel.org>
Reviewed-by: Heikki Krogerus <heikki.krogerus@linux.intel.com>
Link: https://patch.msgid.link/2026051350-reacquire-sculpture-4244@gregkh
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
drivers/usb/typec/altmodes/displayport.c

index 35d9c3086990036d1f43eae71bfd6e618e964b94..263a89c5f32433d64c32405f2787d89b1dd5a02a 100644 (file)
@@ -405,6 +405,8 @@ static int dp_altmode_vdm(struct typec_altmode *alt,
                                dp->state = DP_STATE_EXIT_PRIME;
                        break;
                case DP_CMD_STATUS_UPDATE:
+                       if (count < 2)
+                               break;
                        dp->data.status = *vdo;
                        ret = dp_altmode_status_update(dp);
                        break;