From: Karl Mehltretter <kmehltretter@gmail.com>
To: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Cc: Karl Mehltretter <kmehltretter@gmail.com>,
John Paul Adrian Glaubitz <glaubitz@physik.fu-berlin.de>,
linux-usb@vger.kernel.org, linux-sh@vger.kernel.org,
linux-kernel@vger.kernel.org
Subject: [PATCH] usb: r8a66597-hcd: fix buffer overflow on odd-length FIFO reads
Date: Fri, 2 Oct 2026 23:32:25 +0200 [thread overview]
Message-ID: <20261002213225.27834-1-kmehltretter@gmail.com> (raw)
For an external R8A66597 (pdata->on_chip is false), the driver accesses
the FIFO 16 bits at a time. It rounds an odd byte count up to the next
word and passes that word count to ioread16_rep(), which stores both bytes
of every word in the caller's buffer. The final word therefore writes one
byte beyond an odd-length read, past the end of the buffer when the read
fills it.
This is visible while enumerating a USB device on an SH7785LCR. The USB
core allocates nine bytes for the configuration descriptor header, and
the controller driver stores ten bytes in it. SLUB reports the first
redzone byte changing from 0xcc to 0x09 in usb_get_configuration().
Odd-sized HID report descriptors trigger the same overwrite.
Section 2.8.5 of the R8A66597 datasheet requires software to discard the
excess byte after a 16-bit FIFO read when DTLN is odd. Read the trailing
byte through a temporary word and copy only that byte.
Fixes: 5d3043586db4 ("USB: r8a66597-hcd: host controller driver for R8A66597")
Cc: stable@vger.kernel.org
Reported-by: John Paul Adrian Glaubitz <glaubitz@physik.fu-berlin.de>
Link: https://lore.kernel.org/all/3bd32eaf159db61ed1d423e1d52a869b3689c682.camel@physik.fu-berlin.de/
Assisted-by: LLM
Signed-off-by: Karl Mehltretter <kmehltretter@gmail.com>
---
Reproduced with 32-bit and 29-bit SH7785LCR kernels against a local
R8A66597 QEMU model. Before this patch, slub_debug=FZPU reports overflows
for the 9-byte configuration header and the 63-byte HID report descriptor.
An A/B test of this patch with the 32-bit kernel enumerates the keyboard
and removes both reports.
Testing the fix on real hardware is welcome.
drivers/usb/host/r8a66597.h | 11 +++++++++--
1 file changed, 9 insertions(+), 2 deletions(-)
diff --git a/drivers/usb/host/r8a66597.h b/drivers/usb/host/r8a66597.h
--- a/drivers/usb/host/r8a66597.h
+++ b/drivers/usb/host/r8a66597.h
@@ -178,8 +178,15 @@ static inline void r8a66597_read_fifo(struct r8a66597 *r8a66597,
len & 0x03);
}
} else {
- len = (len + 1) / 2;
- ioread16_rep(fifoaddr, buf, len);
+ count = len / 2;
+ ioread16_rep(fifoaddr, buf, count);
+
+ if (len & 0x00000001) {
+ u16 tmp;
+
+ ioread16_rep(fifoaddr, &tmp, 1);
+ memcpy((unsigned char *)buf + count * 2, &tmp, 1);
+ }
}
}
--
2.53.0
next reply other threads:[~2026-10-02 21:32 UTC|newest]
Thread overview: 6+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-02 21:32 Karl Mehltretter [this message]
2026-10-03 7:29 ` [PATCH] usb: r8a66597-hcd: fix buffer overflow on odd-length FIFO reads John Paul Adrian Glaubitz
2026-10-03 12:42 ` Geert Uytterhoeven
2026-10-05 4:25 ` Karl Mehltretter
2026-10-05 13:57 ` Geert Uytterhoeven
2026-10-05 20:21 ` Karl Mehltretter
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20261002213225.27834-1-kmehltretter@gmail.com \
--to=kmehltretter@gmail.com \
--cc=glaubitz@physik.fu-berlin.de \
--cc=gregkh@linuxfoundation.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-sh@vger.kernel.org \
--cc=linux-usb@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox