From: "Krzysztof Wilczyński" <kwilczynski@kernel.org>
To: sashiko-reviews@lists.linux.dev
Cc: linux-pci@vger.kernel.org
Subject: Re: [PATCH 3/4] PCI/sysfs: Handle a malformed _DSM result in acpi_attr_is_visible()
Date: Fri, 14 Aug 2026 18:35:24 +0900 [thread overview]
Message-ID: <20260814093405.GA3463973@rocinante> (raw)
In-Reply-To: <20260814071951.085BD1F00A3A@smtp.kernel.org>
Hello,
> [Severity: High]
> This isn't a bug introduced by this patch, but while reviewing how the _DSM
> buffer is handled in this file, I noticed a pre-existing issue in
> dsm_label_utf16s_to_utf8s():
>
> drivers/pci/pci-label.c:dsm_label_utf16s_to_utf8s() {
> int len;
>
> len = utf16s_to_utf8s((const wchar_t *)obj->buffer.pointer,
> obj->buffer.length,
> UTF16_LITTLE_ENDIAN,
> buf, PAGE_SIZE - 1);
> buf[len++] = '\n';
>
> return len;
> }
>
> Does this code pass a byte length instead of a character count?
>
> Because utf16s_to_utf8s() expects the inlen parameter to represent the number
> of 16-bit characters, passing obj->buffer.length (which is the size in bytes)
> might instruct the function to process up to twice as many characters as are
> actually allocated for the buffer.
>
> Could this result in an out-of-bounds heap memory read when an unprivileged
> user reads the world-readable /sys/bus/pci/devices/.../label sysfs file?
The last patch of this series aims to address this issue.
Thank you!
Krzysztof
next prev parent reply other threads:[~2026-08-14 9:35 UTC|newest]
Thread overview: 13+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-14 7:05 [PATCH 0/4] PCI/sysfs: Fix the ACPI device name attributes Krzysztof Wilczyński
2026-08-14 7:05 ` [PATCH 1/4] PCI/sysfs: Stop reporting _DSM failures as -EPERM Krzysztof Wilczyński
2026-08-14 7:19 ` sashiko-bot
2026-08-14 9:36 ` Krzysztof Wilczyński
2026-08-14 7:05 ` [PATCH 2/4] PCI/sysfs: Decouple acpi_index from the optional device name element Krzysztof Wilczyński
2026-08-14 7:11 ` sashiko-bot
2026-08-14 7:05 ` [PATCH 3/4] PCI/sysfs: Handle a malformed _DSM result in acpi_attr_is_visible() Krzysztof Wilczyński
2026-08-14 7:19 ` sashiko-bot
2026-08-14 9:35 ` Krzysztof Wilczyński [this message]
2026-08-14 7:05 ` [PATCH 4/4] PCI/sysfs: Pass the device name length in UTF-16 code units Krzysztof Wilczyński
2026-08-14 7:14 ` sashiko-bot
2026-08-14 10:22 ` Krzysztof Wilczyński
2026-08-14 9:45 ` [PATCH 0/4] PCI/sysfs: Fix the ACPI device name attributes Krzysztof Wilczyński
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260814093405.GA3463973@rocinante \
--to=kwilczynski@kernel.org \
--cc=linux-pci@vger.kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.