mirror of
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git
synced 2026-09-11 06:52:31 -04:00
iio: accel: fxls8962af: clamp the device-reported FIFO sample count
fxls8962af_fifo_flush() transfers the sample count the device reports in BUF_STATUS into an on-stack buffer sized for FXLS8962AF_FIFO_LENGTH (32) samples, but the count is a 6-bit field (0..63) that is only checked for zero. A device, or an attacker on the I2C/SPI bus, reporting 33..63 overflows the buffer by up to 186 bytes: a stack out-of-bounds write. Clamp the count to FXLS8962AF_FIFO_LENGTH before the transfer, mirroring the clamp already applied in fxls8962af_set_watermark(). Conforming hardware reports at most that many samples and is unaffected. Signed-off-by: Bryam Vargas <hexlabsecurity@proton.me> Reviewed-by: Andy Shevchenko <andriy.shevchenko@intel.com> Signed-off-by: Jonathan Cameron <jic23@kernel.org>
This commit is contained in:
committed by
Jonathan Cameron
parent
d2a4411137
commit
2f8225b91e
@@ -970,6 +970,8 @@ static int fxls8962af_fifo_flush(struct iio_dev *indio_dev)
|
||||
if (!count)
|
||||
return 0;
|
||||
|
||||
count = min(count, FXLS8962AF_FIFO_LENGTH);
|
||||
|
||||
data->old_timestamp = data->timestamp;
|
||||
data->timestamp = iio_get_time_ns(indio_dev);
|
||||
|
||||
|
||||
Reference in New Issue
Block a user