From: Mika Westerberg <mika.westerberg@linux.intel.com>
To: Pengpeng Hou <pengpeng@iscas.ac.cn>
Cc: Andreas Noever <andreas.noever@gmail.com>,
Mika Westerberg <westeri@kernel.org>,
Yehezkel Bernat <YehezkelShB@gmail.com>,
linux-usb@vger.kernel.org, linux-kernel@vger.kernel.org
Subject: Re: [PATCH v2] thunderbolt: validate DROM entry lengths
Date: Sun, 2 Aug 2026 10:41:49 +0200 [thread overview]
Message-ID: <20260802084149.GM20844@black.igk.intel.com> (raw)
In-Reply-To: <20260731141700.3-thunderbolt-v2-pengpeng@iscas.ac.cn>
Hi,
On Fri, Jul 31, 2026 at 10:20:54PM +0800, Pengpeng Hou wrote:
> tb_drom_parse_entries() checks that a DROM entry does not run past the
> end of the DROM, but it does not require the declared entry length to
> cover the entry header itself. A one-byte generic string entry therefore
> makes the payload length calculation underflow.
>
> Require each entry to contain its two-byte header before dispatching to
> the type-specific DROM entry parsers. Also require a USB4 product
> descriptor entry to contain the vendor and product fields read by its
> parser.
>
> Signed-off-by: Pengpeng Hou <pengpeng@iscas.ac.cn>
> ---
> Changes since v1: https://lore.kernel.org/all/20260706091532.77293-1-pengpeng@iscas.ac.cn/
> - use the full author name in From and Signed-off-by as requested by
> Mika Westerberg
> - validate the fields read from USB4 product descriptor entries
> - rebase onto the current tree
>
> drivers/thunderbolt/eeprom.c | 19 ++++++++++++++++---
> 1 file changed, 16 insertions(+), 3 deletions(-)
>
> diff --git a/drivers/thunderbolt/eeprom.c b/drivers/thunderbolt/eeprom.c
> index 5681c17f82ec..87ae1b8d7c82 100644
> --- a/drivers/thunderbolt/eeprom.c
> +++ b/drivers/thunderbolt/eeprom.c
> @@ -348,6 +348,12 @@ static int tb_drom_parse_entry_generic(struct tb_switch *sw,
> const struct tb_drom_entry_desc *desc =
> (const struct tb_drom_entry_desc *)entry;
>
> + /* Header, USB spec, vendor ID, and product ID. */
Can't you just compare to the desc here since that's the structure we find
there in that entry?
> + if (header->len < sizeof(*header) + 3 * sizeof(u16)) {
> + tb_sw_warn(sw, "USB4 product descriptor entry is too short\n");
> + return -EIO;
> + }
> +
> if (!sw->vendor && !sw->device) {
> sw->vendor = desc->idVendor;
> sw->device = desc->idProduct;
> @@ -414,9 +420,16 @@ static int tb_drom_parse_entries(struct tb_switch *sw, size_t header_size)
> int res;
>
> while (pos < drom_size) {
> - struct tb_drom_entry_header *entry = (void *) (sw->drom + pos);
> - if (pos + 1 == drom_size || pos + entry->len > drom_size
> - || !entry->len) {
> + struct tb_drom_entry_header *entry;
> +
> + if (drom_size - pos < sizeof(*entry)) {
> + tb_sw_warn(sw, "DROM buffer overrun\n");
> + return -EIO;
> + }
> +
> + entry = (void *)(sw->drom + pos);
> + if (entry->len < sizeof(*entry) ||
> + entry->len > drom_size - pos) {
> tb_sw_warn(sw, "DROM buffer overrun\n");
> return -EIO;
> }
> --
> 2.50.1
prev parent reply other threads:[~2026-08-02 8:41 UTC|newest]
Thread overview: 2+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-07-31 14:20 [PATCH v2] thunderbolt: validate DROM entry lengths Pengpeng Hou
2026-08-02 8:41 ` Mika Westerberg [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260802084149.GM20844@black.igk.intel.com \
--to=mika.westerberg@linux.intel.com \
--cc=YehezkelShB@gmail.com \
--cc=andreas.noever@gmail.com \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-usb@vger.kernel.org \
--cc=pengpeng@iscas.ac.cn \
--cc=westeri@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.