summaryrefslogtreecommitdiffstats
path: root/scripts/elf-parse.c
diff options
context:
space:
mode:
authorDaehyeon Ko <4ncienth@gmail.com>2026-09-09 10:07:37 +0900
committerMika Westerberg <mika.westerberg@linux.intel.com>2026-09-14 10:48:17 +0200
commit80756e263846ab694984e749e8c626897331438f (patch)
tree8a22f645d593e8a0dc674171ac7a17c03e6fefd7 /scripts/elf-parse.c
parente6df180e976fd08673214bc1305a46a8536aea9a (diff)
downloadlinux-stable-80756e263846ab694984e749e8c626897331438f.tar.gz
linux-stable-80756e263846ab694984e749e8c626897331438f.zip
thunderbolt: Reject oversized XDomain properties responses
tb_xdp_properties_request() allocates room for 45 data dwords in its 252-byte response buffer. The XDomain length field is six bits wide, however, and a malicious peer can set it to 63. After the fixed response fields are subtracted, the driver treats this as 48 data dwords. Commit 322e93448d90 ("thunderbolt: Clamp XDomain response data copy to allocation size") only bounds the copy against data_len. If data_len is at least 48, memcpy() reads 192 bytes from the 180-byte res->data array, causing a 12-byte heap out-of-bounds read. Commit 4db2bd2ed478 ("thunderbolt: Limit XDomain response copy to actual frame size") limits the earlier copy but does not constrain this header-derived length. Reject response data lengths that exceed the allocated source buffer before copying them into the assembled property block. Fixes: d1ff70241a27 ("thunderbolt: Add support for XDomain discovery protocol") Cc: stable@vger.kernel.org Assisted-by: LLM Signed-off-by: Daehyeon Ko <4ncienth@gmail.com> Signed-off-by: Mika Westerberg <mika.westerberg@linux.intel.com>
Diffstat (limited to 'scripts/elf-parse.c')
0 files changed, 0 insertions, 0 deletions