From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-pf1-f171.google.com (mail-pf1-f171.google.com [209.85.210.171]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id B0052377560 for ; Fri, 21 Aug 2026 03:35:41 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.210.171 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787283344; cv=none; b=ripmqI18IhMYyZKmAd8H1xIv8049VmKUrqjewwZPpYNiuiVwWTbuJqovMJuv4+MpLV4mlraXTQj/nTlxTdzLMaZtxDot1xoMVYi37hIpqfCywf3gnGrCnwdYyDQkuueJ0o8osSVzwRWcuUJh+2bXaqxwhVotu5uLETE1qCXxWqw= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787283344; c=relaxed/simple; bh=KWUdr7QjdL/P5FemNe2dO+4gc717FuyqKfmff+EFr0M=; h=From:To:Cc:Subject:Date:Message-Id:In-Reply-To:References: MIME-Version; b=UHG5Ttx57nBpBEK3i/yEkWSoEXM0jDC8Q1Ny02Y5DddInvMjJGhFFQdsf3yWr1VeRqywcDKBzXS1xSXSWH2OuvRWCfMLrAoEsIwqwZWtXzpgMBWY+HoCGrAN+oR7r+piTQjK88iHURH7jeLlUbB4TKILw1gi8lzWh6uMiZJQ3wY= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=qyURAstI; arc=none smtp.client-ip=209.85.210.171 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="qyURAstI" Received: by mail-pf1-f171.google.com with SMTP id d2e1a72fcca58-8518d5ddaabso392380b3a.2 for ; Thu, 20 Aug 2026 20:35:41 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1787283340; x=1787888140; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=UJkZ6RvxbNcjAoli9z1uAOHLN7PuUwcVnyV1b+h3Wd0=; b=qyURAstIjHh28uICehrxEJ/JZopCKDxkuH0DfLHIJLLNOCCL///F/OXsqRnabOa0iM 9ipBp4lz7SGkyBgmK9BPVzmScI51IobtW3/UiUi/sRLWvC/tGBbmy7vGp8SWsnMxGUWU /yoRAcw74FAq0e+MjmdxgA68xT/27TlDio8/Tc4z520kZftnqs0NNcXqmLD9wCOXvMBk oblMi4Q3p3r7JFPMy87exUfNOxZqRxWLTAYqByCzmYFNmsNMIQbsqf/riKpchfPAb4aG QbGGenISVLB5DF6v75AjO00PoCePPmwjHJb22hIwQgLXc9hk11/Ztb/O1rGYEJnmILuA kVLw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787283340; x=1787888140; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=UJkZ6RvxbNcjAoli9z1uAOHLN7PuUwcVnyV1b+h3Wd0=; b=Zxgv7P4TwQCmFea5kbc2ORjphL+L3A6E+0MAjuuKNfYqyjJg2JqT68hrTDhK4h2AN/ dJ8dns3bwbariDFVt/u9cEouwyU/SVNqWfbnF52uezjmf103Kzdc59iGW3PKCp15P5kx dPloWhy5uPSIPnBpKBdWoSlSCzAPDOZ60sP15QpzNYVt7cuzYjC4KyW0q2GZGvSEOTPB Pj3xgWkMy6J4Ao+dZEWqCJ6JBqMJAWQWUyCxG/Aw3nmxRSniHUGOpzs93Of4pxNXg3yB ID5wORsdKaN1yn/Mh2Eoz8aQG580nJ9J932f9cxT1GCE7PcMS9V31mRYsSsyB1G7HHPa n7Hg== X-Gm-Message-State: AOJu0Yz7C9x9dh1XUtviMOkEarbOuVier/RwFL7TTg+4wdB/l9nJEcQE SdZL3RjOSbIO7IDYDJOqKYliZVqs2iXO2Rt2dbz1fMVimJ9zTHS+Cqan X-Gm-Gg: AR+sD12DP5M1J62nw/wYepIm+MCsl1KtxUYsAgUzlwWY95s7FUGubA8QqEUwN9A+U5T 5qF41LEULMxw3lh1b/mwUW3bWqIjcbyPrfoKTetUzWSP8tzg9e8J7qloxciqL09AQ0LRvZZE9X2 /lVA138EU790bcuHV+nfClTyKoOoyHAokrLNKlQjUIEz8VNF24ZkxckOxNsyqGkMYf42agMeUsh ImT8Wymlaxe0cmEulVj1Py7utf/xlfdhwMxn5QW6k+Lqpm4YR/fmnaZ5XaLZQZohwDILMog4zB8 fYZyjGMg5vy3mMcs9QWsnV7hTSFerzHv6RGqrPSrpWW3SYvt1WwKvA0czv5pqMsKF1t0duGWq4b ODwUfn5KE5TDW6Belf4blUx+Evct/0sCJCMotbhoJ2ogVzo9aw9SS3bO5V5lJDgslCM/U2AZR5T AHJT8GNrV7VgkoluC5TpaTjLWjXqcqRno80Qj1tA1MzjEgpnWWtdFdt85DD6CU3LKIC3sSOFT03 jACwnyDnNYaOCzgV2sFNmm+zfZOkDU= X-Received: by 2002:a05:6a20:b7aa:b0:3cb:c1f8:5722 with SMTP id adf61e73a8af0-3cd3007cfb5mr5560517637.10.1787283340537; Thu, 20 Aug 2026 20:35:40 -0700 (PDT) Received: from hcdev-d520mt2.. (60-250-196-139.hinet-ip.hinet.net. [60.250.196.139]) by smtp.gmail.com with ESMTPSA id 41be03b00d2f7-cc15891a04csm2204271a12.15.2026.08.20.20.35.39 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 20 Aug 2026 20:35:40 -0700 (PDT) From: a0282524688@gmail.com To: lee@kernel.org, Ming Yu Cc: linux-kernel@vger.kernel.org, Ming Yu , mfd@lists.linux.dev Subject: [PATCH v7 07/10] mfd: nct6694: Validate the interrupt IN endpoint Date: Fri, 21 Aug 2026 11:35:02 +0800 Message-Id: <20260821033505.4017901-8-a0282524688@gmail.com> X-Mailer: git-send-email 2.34.1 In-Reply-To: <20260821033505.4017901-1-a0282524688@gmail.com> References: <20260821033505.4017901-1-a0282524688@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit From: Ming Yu The probe reads endpoint[0] of the current altsetting without checking that the interface actually describes any endpoint. A device reporting zero endpoints makes the driver read past the endpoint array. Locate the interrupt IN endpoint with usb_find_int_in_endpoint(), which validates the descriptor before it is used. Fixes: 51dad33ede63 ("mfd: Add core driver for Nuvoton NCT6694") Signed-off-by: Ming Yu --- Changes in v7: - New patch. Fixes the out-of-bounds endpoint access reported on v6 patch 6/7. drivers/mfd/nct6694-usb.c | 9 ++------- 1 file changed, 2 insertions(+), 7 deletions(-) diff --git a/drivers/mfd/nct6694-usb.c b/drivers/mfd/nct6694-usb.c index 793ce54c02aa..c8667984df5e 100644 --- a/drivers/mfd/nct6694-usb.c +++ b/drivers/mfd/nct6694-usb.c @@ -266,7 +266,6 @@ static int nct6694_usb_probe(struct usb_interface *iface, { struct usb_device *udev = interface_to_usbdev(iface); struct usb_endpoint_descriptor *int_endpoint; - struct usb_host_interface *interface; struct device *dev = &iface->dev; struct nct6694_usb_data *udata; struct nct6694 *nct6694; @@ -305,13 +304,9 @@ static int nct6694_usb_probe(struct usb_interface *iface, if (ret) goto err_urb; - interface = iface->cur_altsetting; - - int_endpoint = &interface->endpoint[0].desc; - if (!usb_endpoint_is_int_in(int_endpoint)) { - ret = -ENODEV; + ret = usb_find_int_in_endpoint(iface->cur_altsetting, &int_endpoint); + if (ret) goto err_urb; - } usb_fill_int_urb(udata->int_in_urb, udev, usb_rcvintpipe(udev, NCT6694_INT_IN_EP), udata->int_buffer, sizeof(*udata->int_buffer), nct6694_usb_int_callback, -- 2.34.1