From: Baochen Qiang <baochen.qiang@oss.qualcomm.com>
To: Jiale Yao <yaojiale02@163.com>,
Jeff Johnson <jjohnson@kernel.org>,
Vasanthakumar Thiagarajan
<vasanthakumar.thiagarajan@oss.qualcomm.com>,
Dan Carpenter <error27@gmail.com>,
linux-wireless@vger.kernel.org, ath12k@lists.infradead.org,
linux-kernel@vger.kernel.org
Subject: Re: [PATCH 2/3] wifi: ath12k: Reserve space for a string terminator
Date: Tue, 29 Sep 2026 10:35:59 +0800 [thread overview]
Message-ID: <0f66a04f-18e0-488e-b6d5-aedead2f82eb@oss.qualcomm.com> (raw)
In-Reply-To: <20260926121250.3258285-3-yaojiale02@163.com>
On 9/26/2026 8:12 PM, Jiale Yao wrote:
> ath12k_write_htt_stats_type() accepts count == size, which fills the
> zero-initialized buffer without a terminating NUL. sscanf() then reads
> beyond the buffer.
>
> Reject input that leaves no room for the trailing NUL.
>
> Fixes: 8c7a5031a6b0 ("wifi: ath12k: Fix buffer overflow in debugfs")
> Signed-off-by: Jiale Yao <yaojiale02@163.com>
> ---
> drivers/net/wireless/ath/ath12k/debugfs_htt_stats.c | 2 +-
> 1 file changed, 1 insertion(+), 1 deletion(-)
>
> diff --git a/drivers/net/wireless/ath/ath12k/debugfs_htt_stats.c b/drivers/net/wireless/ath/ath12k/debugfs_htt_stats.c
> index b772181a496e..f84f1828275a 100644
> --- a/drivers/net/wireless/ath/ath12k/debugfs_htt_stats.c
> +++ b/drivers/net/wireless/ath/ath12k/debugfs_htt_stats.c
> @@ -6190,7 +6190,7 @@ static ssize_t ath12k_write_htt_stats_type(struct file *file,
> const int size = 32;
> int num_args;
>
> - if (count > size)
> + if (count >= size)
> return -EINVAL;
>
> char *buf __free(kfree) = kzalloc(size, GFP_KERNEL);
Reviewed-by: Baochen Qiang <baochen.qiang@oss.qualcomm.com>
next prev parent reply other threads:[~2026-09-29 2:36 UTC|newest]
Thread overview: 14+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-26 12:12 [PATCH 0/3] debugfs: Reserve space for string terminators Jiale Yao
2026-09-26 12:12 ` [PATCH 1/3] platform/olpc: Reserve space for a string terminator Jiale Yao
2026-09-26 12:12 ` [PATCH 2/3] wifi: ath12k: " Jiale Yao
2026-09-26 12:33 ` Dan Carpenter
2026-09-28 17:36 ` Rameshkumar Sundaram
2026-09-29 2:35 ` Baochen Qiang [this message]
2026-10-03 23:07 ` Jeff Johnson
2026-09-26 12:12 ` [PATCH 3/3] dmaengine: xilinx: dpdma: " Jiale Yao
2026-09-26 14:34 ` Laurent Pinchart
2026-10-01 20:50 ` Frank Li
2026-10-01 21:00 ` Laurent Pinchart
2026-10-03 10:09 ` jiale yao
2026-10-04 1:01 ` Frank Li
2026-10-08 17:38 ` [PATCH 0/3] debugfs: Reserve space for string terminators Ilpo Järvinen
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=0f66a04f-18e0-488e-b6d5-aedead2f82eb@oss.qualcomm.com \
--to=baochen.qiang@oss.qualcomm.com \
--cc=ath12k@lists.infradead.org \
--cc=error27@gmail.com \
--cc=jjohnson@kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-wireless@vger.kernel.org \
--cc=vasanthakumar.thiagarajan@oss.qualcomm.com \
--cc=yaojiale02@163.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.