From: sashiko-bot@kernel.org
To: "Pengpeng Hou" <pengpeng@iscas.ac.cn>
Cc: dri-devel@lists.freedesktop.org
Subject: Re: [PATCH] fbdev: udlfb: validate vendor descriptor items
Date: Mon, 06 Jul 2026 09:44:36 +0000 [thread overview]
Message-ID: <20260706094437.1774E1F00A3D@smtp.kernel.org> (raw)
In-Reply-To: <20260706093038.80131-1-pengpeng@iscas.ac.cn>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
Pre-existing issues:
- [High] Out-of-bounds read in `dev_info` using `%11ph` format specifier, potentially causing a kernel panic.
--
commit 8284c1b4f9c66a4ef2393d5e8aa1741e7ef14d8a
Author: Pengpeng Hou <pengpeng@iscas.ac.cn>
fbdev: udlfb: validate vendor descriptor items
This commit validates key-length-value items inside the DisplayLink vendor
descriptor in dlfb_parse_vendor_descriptor(). It ensures each item contains
its key, length, and declared value bytes before reading item-specific fields.
> diff --git a/drivers/video/fbdev/udlfb.c b/drivers/video/fbdev/udlfb.c
> index fdbb8671a810c..e78d6f95c9c5c 100644
> --- a/drivers/video/fbdev/udlfb.c
> +++ b/drivers/video/fbdev/udlfb.c
> @@ -1586,19 +1586,29 @@ static int dlfb_parse_vendor_descriptor(struct dlfb_data *dlfb,
[Severity: High]
This isn't a bug introduced by this patch, but earlier in
dlfb_parse_vendor_descriptor(), there is a potential out-of-bounds read:
if (total_len > 5) {
dev_info(&intf->dev,
"vendor descriptor length: %d data: %11ph\n",
total_len, desc);
Can this unconditionally read 11 bytes even if total_len is as small as 6?
If a malicious USB device stalls the initial control request for the vendor
descriptor, and instead provides it as a 6-byte extra descriptor within the
configuration descriptor blob, desc will point directly into the USB core's
rawdescriptors allocation, and total_len will be 6.
Because the %11ph format specifier unconditionally reads exactly 11 bytes,
would this read 5 bytes out of bounds, potentially causing a kernel panic if
the buffer ends at a page boundary?
> desc += 5; /* the fixed header we've already parsed */
>
> while (desc < desc_end) {
[ ... ]
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260706093038.80131-1-pengpeng@iscas.ac.cn?part=1
next prev parent reply other threads:[~2026-07-06 9:44 UTC|newest]
Thread overview: 4+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-07-06 9:30 [PATCH] fbdev: udlfb: validate vendor descriptor items Pengpeng Hou
2026-07-06 9:44 ` sashiko-bot [this message]
2026-07-18 18:26 ` Helge Deller
2026-07-18 18:59 ` Helge Deller
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260706094437.1774E1F00A3D@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=dri-devel@lists.freedesktop.org \
--cc=pengpeng@iscas.ac.cn \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox