From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from bombadil.infradead.org (bombadil.infradead.org [198.137.202.133]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.lore.kernel.org (Postfix) with ESMTPS id 04A8AC98325 for ; Fri, 25 Sep 2026 15:06:40 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=lists.infradead.org; s=bombadil.20210309; h=Sender:List-Subscribe:List-Help :List-Post:List-Archive:List-Unsubscribe:List-Id:Content-Transfer-Encoding: MIME-Version:References:In-Reply-To:Message-Id:Date:Subject:Cc:To:From: Reply-To:Content-Type:Content-ID:Content-Description:Resent-Date:Resent-From: Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:List-Owner; bh=31AX/cwM8/OnRF/yeYpJQfvdlOv5vgEP2EVvQZ6gI+o=; b=KKVI1hMcKOCsofLCWDypBN7eyR AXM/P2Tic+dXOHN0MDqK7MRj7LGlZ3LhxxbmSzQPX6HNh4Zk8tbtDTVNi0fVR971ZxcKMI4/tPQs1 wC497Qo705T1IZl00mB3oIof2HY+qn10QKfkHzDJ+AbcApjLeANIBf2K3weiK0vvemf2FIktdmJ7B EYkV+W9uIcgnWce2LDWeqRxRO+hgfz8m67LJDor8U9yROgteUs7pIPicn8DffGGTD2QA4mbZbenJT Qdm6C2ZHtfNJYwMqqwx/k+CKTMUxqyOJMchsb1BxIiyR+vhcTzdndQlNXUt6dfXUn3aWSkQ6uC4FF VrI7p3LQ==; Received: from localhost ([::1] helo=bombadil.infradead.org) by bombadil.infradead.org with esmtp (Exim 4.99.1 #2 (Red Hat Linux)) id 1xA7VS-0000000DhdE-0HS8; Fri, 25 Sep 2026 15:06:34 +0000 Received: from m16.mail.163.com ([117.135.210.4]) by bombadil.infradead.org with esmtps (Exim 4.99.1 #2 (Red Hat Linux)) id 1xA7VE-0000000DhVD-44mh; Fri, 25 Sep 2026 15:06:25 +0000 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=163.com; s=s110527; h=From:To:Subject:Date:Message-Id:MIME-Version; bh=31 AX/cwM8/OnRF/yeYpJQfvdlOv5vgEP2EVvQZ6gI+o=; b=NVERoFOce+O9R/f4x2 hvWRcvmqTNOrJI3K+/OW+OCIMFyKId47ONck8G5sKMUbjPMf/wYuAhKSqP9WTy9b s2o6EBmwymm514LveNBMrSaz50lFI0galmlPA2PuqRQRrKKyg+p+lcmgd+hFPzOg sWJZW6UOdFcBPdJ5IEBEC9Vuo= Received: from pc.localdomain (unknown []) by gzga-smtp-mtada-g0-3 (Coremail) with SMTP id _____wD3J8zYjbZq2yQpAw--.5414S4; Fri, 25 Sep 2026 23:06:05 +0800 (CST) From: Jiale Yao To: Felix Fietkau , Lorenzo Bianconi , Ryder Lee , Shayne Chen , Sean Wang , Matthias Brugger , AngeloGioacchino Del Regno , Johan Hovold , linux-wireless@vger.kernel.org, linux-kernel@vger.kernel.org, linux-arm-kernel@lists.infradead.org, linux-mediatek@lists.infradead.org Cc: Jiale Yao Subject: [PATCH 2/2] wifi: mt76: mt7615: usb: fix source overread in mt7663u_copy Date: Fri, 25 Sep 2026 23:05:55 +0800 Message-Id: <20260925150556.2304003-3-yaojiale02@163.com> X-Mailer: git-send-email 2.34.1 In-Reply-To: <20260925150556.2304003-1-yaojiale02@163.com> References: <20260925150556.2304003-1-yaojiale02@163.com> MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-CM-TRANSID: _____wD3J8zYjbZq2yQpAw--.5414S4 X-Coremail-Antispam: 1Uf129KBjvJXoW7Ww4UWFy5ZFW5uw45Cw13XFb_yoW8Cr47pF yxKF9IvrsxGF17t34xAa15AF95ua9ak34DKrZ3Za4fZ348Aw1YkFW0qFyjkr1j9w4F9r1j qrnxtryxW34DAaDanT9S1TB71UUUUU7qnTZGkaVYY2UrUUUUjbIjqfuFe4nvWSU5nxnvy2 9KBjDUYxBIdaVFxhVjvjDU0xZFpf9x0pK-eoAUUUUU= X-CM-SenderInfo: x1dryxhdohiji6rwjhhfrp/xtbC7x3iHWq2jd0jqAAA3K X-CRM114-Version: 20100106-BlameMichelson ( TRE 0.9.0 (BSD) ) MR-646709E3 X-CRM114-CacheID: sfid-20260925_080621_842978_BE481C82 X-CRM114-Status: GOOD ( 12.75 ) X-BeenThere: linux-arm-kernel@lists.infradead.org X-Mailman-Version: 2.1.34 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Sender: "linux-arm-kernel" Errors-To: linux-arm-kernel-bounces+linux-arm-kernel=archiver.kernel.org@lists.infradead.org mt7663u_copy() rounds up len to a multiple of four and uses the rounded length as the bound for memcpy() from the source buffer. When the caller's length is not four-byte aligned, the final copy reads up to three bytes past the source buffer. Keep the original length for the source copy and zero the remaining bytes in the transmit buffer so that the hardware access width remains four-byte aligned. Fixes: 6cb596ba84e3 ("mt76: usb: introduce __mt76u_init utility routine") Signed-off-by: Jiale Yao --- drivers/net/wireless/mediatek/mt76/mt7615/usb.c | 17 ++++++++++++----- 1 file changed, 12 insertions(+), 5 deletions(-) diff --git a/drivers/net/wireless/mediatek/mt76/mt7615/usb.c b/drivers/net/wireless/mediatek/mt76/mt7615/usb.c index bab7b91f14be..3629e3d9bf47 100644 --- a/drivers/net/wireless/mediatek/mt76/mt7615/usb.c +++ b/drivers/net/wireless/mediatek/mt76/mt7615/usb.c @@ -58,15 +58,22 @@ static void mt7663u_copy(struct mt76_dev *dev, u32 offset, const void *data, int len) { struct mt76_usb *usb = &dev->usb; - int ret, i = 0, batch_len; const u8 *val = data; + int len_aligned; + int batch_len; + int copy_len; + int ret; + int i = 0; - len = round_up(len, 4); + len_aligned = round_up(len, 4); mutex_lock(&usb->usb_ctrl_mtx); - while (i < len) { - batch_len = min_t(int, usb->data_len, len - i); - memcpy(usb->data, val + i, batch_len); + while (i < len_aligned) { + batch_len = min_t(int, usb->data_len, len_aligned - i); + copy_len = min_t(int, batch_len, len - i); + memcpy(usb->data, val + i, copy_len); + if (copy_len < batch_len) + memset(usb->data + copy_len, 0, batch_len - copy_len); ret = __mt76u_vendor_request(dev, MT_VEND_WRITE_EXT, USB_DIR_OUT | USB_TYPE_VENDOR, (offset + i) >> 16, offset + i, -- 2.34.1