From: HyeongJun An <sammiee5311@gmail.com>
To: pratyush@kernel.org, mwalle@kernel.org, tudor.ambarus@linaro.org,
miquel.raynal@bootlin.com, richard@nod.at, vigneshr@ti.com
Cc: takahiro.kuwano@infineon.com, linux-mtd@lists.infradead.org,
linux-kernel@vger.kernel.org, stable@vger.kernel.org,
HyeongJun An <sammiee5311@gmail.com>
Subject: [PATCH v2 0/2] mtd: spi-nor: sfdp: bound two optional parameter tables
Date: Mon, 20 Jul 2026 23:11:02 +0900 [thread overview]
Message-ID: <20260720141104.2054417-1-sammiee5311@gmail.com> (raw)
Two of the optional SFDP parameter table parsers size a buffer from the
table length the flash reports, then index it at fixed offsets without
checking the table is long enough.
spi_nor_parse_profile1() reads up to DWORD5, never checks the length
spi_nor_parse_sccr() reads up to DWORD22, never checks the length
The spi_nor_parse_4bait() already guards its table this way, so both
patches apply the same check. The two parsers were added at different
times, so they carry different Fixes tags and get one patch each.
Found by code inspection. I have no xSPI or multi-die part to reproduce
this on, so this is not runtime tested.
changes since v1:
- reworded both commit messages to be more precise
- renamed the two constants from _DWORD_MAX to _DWORD_MIN
- Link to v1: https://lore.kernel.org/linux-mtd/20260719010820.1924739-1-sammiee5311@gmail.com/
HyeongJun An (2):
mtd: spi-nor: sfdp: check the length of the xSPI Profile 1.0 table
mtd: spi-nor: sfdp: check the length of the SCCR map
drivers/mtd/spi-nor/sfdp.c | 8 ++++++++
1 file changed, 8 insertions(+)
--
2.43.0
______________________________________________________
Linux MTD discussion mailing list
http://lists.infradead.org/mailman/listinfo/linux-mtd/
next reply other threads:[~2026-07-20 14:13 UTC|newest]
Thread overview: 3+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-07-20 14:11 HyeongJun An [this message]
2026-07-20 14:11 ` [PATCH v2 1/2] mtd: spi-nor: sfdp: check the length of the xSPI Profile 1.0 table HyeongJun An
2026-07-20 14:11 ` [PATCH v2 2/2] mtd: spi-nor: sfdp: check the length of the SCCR map HyeongJun An
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260720141104.2054417-1-sammiee5311@gmail.com \
--to=sammiee5311@gmail.com \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-mtd@lists.infradead.org \
--cc=miquel.raynal@bootlin.com \
--cc=mwalle@kernel.org \
--cc=pratyush@kernel.org \
--cc=richard@nod.at \
--cc=stable@vger.kernel.org \
--cc=takahiro.kuwano@infineon.com \
--cc=tudor.ambarus@linaro.org \
--cc=vigneshr@ti.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox