All of lore.kernel.org
 help / color / mirror / Atom feed
From: Bart Van Assche <bvanassche@acm.org>
To: Li Qiang <liqiang01@kylinos.cn>, linux-scsi@vger.kernel.org
Cc: linux-kernel@vger.kernel.org, alim.akhtar@samsung.com,
	avri.altman@wdc.com, James.Bottomley@HansenPartnership.com,
	martin.petersen@oracle.com, peter.wang@mediatek.com,
	beanhuo@micron.com, can.guo@oss.qualcomm.com,
	adrian.hunter@intel.com, tomas.winkler@intel.com
Subject: Re: [PATCH v2 6/6] scsi: ufs: debugfs: Reserve space for a string terminator
Date: Wed, 22 Jul 2026 11:08:29 -0700	[thread overview]
Message-ID: <ce9beb4b-a65e-4547-a809-1dd30621966f@acm.org> (raw)
In-Reply-To: <20260717153914.26321-7-liqiang01@kylinos.cn>

On 7/17/26 8:39 AM, Li Qiang wrote:
> ufs_saved_err_write() copies user input into a zero-initialized stack
> buffer and passes it to kstrtoint(). A write that fills the entire
> buffer overwrites its only terminator.
> 
> Reject an input whose length leaves no room for the trailing NUL.
> 
> Fixes: 7340faae9474 ("scsi: ufs: core: Add debugfs attributes for triggering the UFS EH")
> Signed-off-by: Li Qiang <liqiang01@kylinos.cn>
> ---
>   drivers/ufs/core/ufs-debugfs.c | 2 +-
>   1 file changed, 1 insertion(+), 1 deletion(-)
> 
> diff --git a/drivers/ufs/core/ufs-debugfs.c b/drivers/ufs/core/ufs-debugfs.c
> index e3dd81d6fe82..be527209540d 100644
> --- a/drivers/ufs/core/ufs-debugfs.c
> +++ b/drivers/ufs/core/ufs-debugfs.c
> @@ -165,7 +165,7 @@ static ssize_t ufs_saved_err_write(struct file *file, const char __user *buf,
>   	char val_str[16] = { };
>   	int val, ret;
>   
> -	if (count > sizeof(val_str))
> +	if (count >= sizeof(val_str))
>   		return -EINVAL;
>   	if (copy_from_user(val_str, buf, count))
>   		return -EFAULT;

Reviewed-by: Bart Van Assche <bvanassche@acm.org>

      parent reply	other threads:[~2026-07-22 18:08 UTC|newest]

Thread overview: 37+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-07-16  6:19 [PATCH 0/5] scsi: ufs: Fix descriptor parsing and invalid input handling liqiang
2026-07-16  6:19 ` [PATCH 1/5] scsi: ufs: core: Validate string descriptors liqiang
2026-07-16 17:47   ` Bart Van Assche
2026-07-17 15:35     ` Li Qiang
2026-07-16  6:19 ` [PATCH 2/5] scsi: ufs: Fix NULL dereferences after tag lookup liqiang
2026-07-16  6:43   ` sashiko-bot
2026-07-16 17:52   ` Bart Van Assche
2026-07-16  6:19 ` [PATCH 3/5] scsi: ufs: core: Validate connected lane counts liqiang
2026-07-16  6:19 ` [PATCH 4/5] scsi: ufs: rpmb: Validate frame before parsing liqiang
2026-07-16  6:28   ` sashiko-bot
2026-07-16 17:58   ` Bart Van Assche
2026-07-16  6:19 ` [PATCH 5/5] scsi: ufs: debugfs: Reserve space for a string terminator liqiang
2026-07-16 17:56   ` Bart Van Assche
2026-07-16 17:42 ` [PATCH 0/5] scsi: ufs: Fix descriptor parsing and invalid input handling Bart Van Assche
2026-07-17 15:16   ` Li Qiang
2026-07-17 15:39 ` [PATCH v2 0/6] " Li Qiang
2026-07-17 15:39   ` [PATCH v2 1/6] scsi: ufs: core: Validate string descriptors Li Qiang
2026-07-20  9:13     ` Peter Wang (王信友)
2026-07-22 18:06     ` Bart Van Assche
2026-07-17 15:39   ` [PATCH v2 2/6] scsi: ufs: Avoid NULL CQE dereference when reporting invalid tags Li Qiang
2026-07-20  9:14     ` Peter Wang (王信友)
2026-07-22 18:07     ` Bart Van Assche
2026-07-17 15:39   ` [PATCH v2 3/6] scsi: ufs: core: Validate connected lane counts Li Qiang
2026-07-17 16:21     ` sashiko-bot
2026-07-17 15:39   ` [PATCH v2 4/6] scsi: ufs: rpmb: Validate request frame length before parsing Li Qiang
2026-07-17 16:32     ` sashiko-bot
2026-07-20  9:15     ` Peter Wang (王信友)
2026-07-22 12:04     ` Bean Huo
2026-07-17 15:39   ` [PATCH v2 5/6] scsi: ufs: rpmb: Use unaligned accessors for RPMB frames Li Qiang
2026-07-17 16:54     ` sashiko-bot
2026-07-20  9:15     ` Peter Wang (王信友)
2026-07-22 12:33     ` Bean Huo
2026-07-22 13:54       ` Bart Van Assche
2026-07-23  8:12         ` David Laight
2026-07-17 15:39   ` [PATCH v2 6/6] scsi: ufs: debugfs: Reserve space for a string terminator Li Qiang
2026-07-20  9:16     ` Peter Wang (王信友)
2026-07-22 18:08     ` Bart Van Assche [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=ce9beb4b-a65e-4547-a809-1dd30621966f@acm.org \
    --to=bvanassche@acm.org \
    --cc=James.Bottomley@HansenPartnership.com \
    --cc=adrian.hunter@intel.com \
    --cc=alim.akhtar@samsung.com \
    --cc=avri.altman@wdc.com \
    --cc=beanhuo@micron.com \
    --cc=can.guo@oss.qualcomm.com \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-scsi@vger.kernel.org \
    --cc=liqiang01@kylinos.cn \
    --cc=martin.petersen@oracle.com \
    --cc=peter.wang@mediatek.com \
    --cc=tomas.winkler@intel.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.