]> git.ipfire.org Git - thirdparty/kernel/linux.git/commitdiff
USB: serial: io_ti: reject oversized boot-mode firmware
authorPengpeng Hou <pengpeng@iscas.ac.cn>
Mon, 20 Jul 2026 11:48:17 +0000 (19:48 +0800)
committerJohan Hovold <johan@kernel.org>
Mon, 20 Jul 2026 14:35:40 +0000 (16:35 +0200)
do_boot_mode() copies the firmware payload, excluding its four-byte prefix,
into a fixed 15.5 KiB staging buffer. check_fw_sanity() already proves that
the image contains its seven-byte header and validates the declared image
length and checksum, but it does not impose this boot-mode destination
limit.

Reject images whose payload does not fit before allocating and filling the
staging buffer.

Fixes: d12b219a228e ("edgeport-ti: use request_firmware()")
Signed-off-by: Pengpeng Hou <pengpeng@iscas.ac.cn>
Signed-off-by: Johan Hovold <johan@kernel.org>
drivers/usb/serial/io_ti.c

index 07c0eff3bef4056fdcaaa9cb30d5b743d974091c..cc28f5869a3e8a8222e619e14db5fade40c0f763 100644 (file)
@@ -1464,6 +1464,12 @@ static int do_boot_mode(struct edgeport_serial *serial,
                /* Allocate a 15.5k buffer + 3 byte header */
                buffer_size = (((1024 * 16) - 512) +
                                        sizeof(struct ti_i2c_image_header));
+               if (fw->size - 4 > buffer_size) {
+                       dev_err(dev, "%s - firmware image is too large\n",
+                               __func__);
+                       return -EINVAL;
+               }
+
                buffer = kmalloc(buffer_size, GFP_KERNEL);
                if (!buffer)
                        return -ENOMEM;