]> git.ipfire.org Git - thirdparty/kernel/linux.git/commitdiff
ptp: ocp: Fix board ID over-read
authorAhmad Byagowi <ahmadexp@gmail.com>
Tue, 4 Aug 2026 21:07:51 +0000 (14:07 -0700)
committerJakub Kicinski <kuba@kernel.org>
Thu, 6 Aug 2026 16:15:40 +0000 (09:15 -0700)
The EEPROM board ID is a fixed 13-byte field and is not guaranteed to
contain a NUL terminator. Passing it directly to
devlink_info_version_fixed_put() treats it as a C string and may read
beyond the field.

Format at most OCP_BOARD_ID_LEN bytes into the existing local buffer
before reporting the ID. Use a precision limit because the snprintf()
output size alone does not bound the source string scan.

Fixes: 0cfcdd1ebcfe ("ptp: ocp: add nvmem interface for accessing eeprom")
Cc: stable@vger.kernel.org
Signed-off-by: Ahmad Byagowi <ahmadexp@gmail.com>
Reviewed-by: Vadim Fedorenko <vadim.fedorenko@linux.dev>
Link: https://patch.msgid.link/20260804210751.48248-1-ahmadexp@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
drivers/ptp/ptp_ocp.c

index 35e911f1ad78c0fc4f8e85e0308f808b46754fb4..3d26ec1f7b9ec2c510c0050c011e40d1a7727006 100644 (file)
@@ -2177,9 +2177,11 @@ ptp_ocp_devlink_info_get(struct devlink *devlink, struct devlink_info_req *req,
        if (err)
                return err;
 
+       snprintf(buf, sizeof(buf), "%.*s", OCP_BOARD_ID_LEN,
+                (const char *)bp->board_id);
        err = devlink_info_version_fixed_put(req,
                        DEVLINK_INFO_VERSION_GENERIC_BOARD_ID,
-                       bp->board_id);
+                       buf);
        if (err)
                return err;