Linux SCSI subsystem development
 help / color / mirror / Atom feed
* [PATCH] scsi: efct: validate firmware header size
@ 2026-08-30 13:20 Pengpeng Hou
  2026-08-30 13:31 ` sashiko-bot
  0 siblings, 1 reply; 2+ messages in thread
From: Pengpeng Hou @ 2026-08-30 13:20 UTC (permalink / raw)
  To: Ram Vegesna
  Cc: Pengpeng Hou, James E . J . Bottomley, Martin K . Petersen,
	linux-scsi, target-devel, linux-kernel

The optional firmware update path casts the firmware blob to
efct_hw_grp_hdr and reads its revision before checking that the blob covers
the complete header.

Reject undersized firmware images before accessing header fields.

Fixes: 4df84e846624 ("scsi: elx: efct: Driver initialization routines")
Signed-off-by: Pengpeng Hou <pengpeng@iscas.ac.cn>
---
 drivers/scsi/elx/efct/efct_driver.c | 4 ++++
 1 file changed, 4 insertions(+)

diff --git a/drivers/scsi/elx/efct/efct_driver.c b/drivers/scsi/elx/efct/efct_driver.c
index 07c2f453459e1..b0d8ca58daebe 100644
--- a/drivers/scsi/elx/efct/efct_driver.c
+++ b/drivers/scsi/elx/efct/efct_driver.c
@@ -338,6 +338,10 @@ efct_request_firmware_update(struct efct *efct)
 		efc_log_debug(efct, "Firmware file(%s) not found.\n", file_name);
 		return rc;
 	}
+	if (fw->size < sizeof(*fw_image)) {
+		rc = -EINVAL;
+		goto exit;
+	}
 
 	fw_image = (struct efct_hw_grp_hdr *)fw->data;

base-commit: 08dbfad3f5040f5bdb6c529da20d6d4e81fefd72
-- 
2.50.1


^ permalink raw reply related	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2026-08-30 13:31 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-08-30 13:20 [PATCH] scsi: efct: validate firmware header size Pengpeng Hou
2026-08-30 13:31 ` sashiko-bot

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox