* [PATCH] drm/rockchip: analogix_dp: bound endpoint name formatting
@ 2026-09-01 19:55 Yudi Yang
2026-09-03 14:12 ` Heiko Stuebner
0 siblings, 1 reply; 2+ messages in thread
From: Yudi Yang @ 2026-09-01 19:55 UTC (permalink / raw)
To: Sandy Huang, Heiko Stübner, Andy Yan
Cc: Maarten Lankhorst, Maxime Ripard, Thomas Zimmermann, David Airlie,
Simona Vetter, Dmitry Baryshkov, Damon Ding, dri-devel,
linux-rockchip, linux-arm-kernel, linux-kernel, Yudi Yang, stable
rockchip_dp_drm_encoder_enable() uses sprintf() to format a device tree
path into a 32-byte stack buffer. Device tree paths are not limited to
this size, so a sufficiently long path can overflow the buffer.
Use snprintf() with the destination size to truncate the generated name
and keep the writes within bounds.
Fixes: 729f8eefdcad ("drm/rockchip: analogix_dp: Add support for RK3588")
Cc: stable@vger.kernel.org
Signed-off-by: Yudi Yang <2000jedi@gmail.com>
---
drivers/gpu/drm/rockchip/analogix_dp-rockchip.c | 7 ++++---
1 file changed, 4 insertions(+), 3 deletions(-)
diff --git a/drivers/gpu/drm/rockchip/analogix_dp-rockchip.c b/drivers/gpu/drm/rockchip/analogix_dp-rockchip.c
index 587e60232ec7..efd5a98e80bd 100644
--- a/drivers/gpu/drm/rockchip/analogix_dp-rockchip.c
+++ b/drivers/gpu/drm/rockchip/analogix_dp-rockchip.c
@@ -241,10 +241,11 @@ static void rockchip_dp_drm_encoder_enable(struct drm_encoder *encoder,
of_graph_get_remote_port(endpoint.local_node);
of_property_read_u32(remote_port, "reg", &port_id);
- sprintf(name, "%s vp%d", remote_port_parent->full_name, port_id);
+ snprintf(name, sizeof(name), "%s vp%d",
+ remote_port_parent->full_name, port_id);
} else {
- sprintf(name, "%s %s",
- remote_port_parent->full_name, endpoint.id ? "vopl" : "vopb");
+ snprintf(name, sizeof(name), "%s %s",
+ remote_port_parent->full_name, endpoint.id ? "vopl" : "vopb");
}
DRM_DEV_DEBUG(dp->dev, "vop %s output to dp\n", (ret) ? "LIT" : "BIG");
--
2.43.0
^ permalink raw reply related [flat|nested] 2+ messages in thread* Re: [PATCH] drm/rockchip: analogix_dp: bound endpoint name formatting
2026-09-01 19:55 [PATCH] drm/rockchip: analogix_dp: bound endpoint name formatting Yudi Yang
@ 2026-09-03 14:12 ` Heiko Stuebner
0 siblings, 0 replies; 2+ messages in thread
From: Heiko Stuebner @ 2026-09-03 14:12 UTC (permalink / raw)
To: Sandy Huang, Andy Yan, Yudi Yang
Cc: Heiko Stuebner, Maarten Lankhorst, Maxime Ripard,
Thomas Zimmermann, David Airlie, Simona Vetter, Dmitry Baryshkov,
Damon Ding, dri-devel, linux-rockchip, linux-arm-kernel,
linux-kernel, stable
On Tue, 01 Sep 2026 14:55:11 -0500, Yudi Yang wrote:
> rockchip_dp_drm_encoder_enable() uses sprintf() to format a device tree
> path into a 32-byte stack buffer. Device tree paths are not limited to
> this size, so a sufficiently long path can overflow the buffer.
>
> Use snprintf() with the destination size to truncate the generated name
> and keep the writes within bounds.
>
> [...]
Applied, thanks!
[1/1] drm/rockchip: analogix_dp: bound endpoint name formatting
commit: bc69439d983cc491cc86e01fafc1deb94e1bb85e
Best regards,
--
Heiko Stuebner <heiko@sntech.de>
^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2026-09-03 14:12 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-01 19:55 [PATCH] drm/rockchip: analogix_dp: bound endpoint name formatting Yudi Yang
2026-09-03 14:12 ` Heiko Stuebner
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox