[PATCH v2] USB: serial: io_ti: reject oversized boot-mode firmware

Pengpeng Hou posted 1 patch 4 days, 14 hours ago
drivers/usb/serial/io_ti.c | 6 ++++++
1 file changed, 6 insertions(+)
[PATCH v2] USB: serial: io_ti: reject oversized boot-mode firmware
Posted by Pengpeng Hou 4 days, 14 hours ago
do_boot_mode() copies the firmware payload, excluding its four-byte prefix,
into a fixed 15.5 KiB staging buffer. check_fw_sanity() already proves that
the image contains its seven-byte header and validates the declared image
length and checksum, but it does not impose this boot-mode destination
limit.

Reject images whose payload does not fit before allocating and filling the
staging buffer.

Fixes: d12b219a228e ("edgeport-ti: use request_firmware()")
Signed-off-by: Pengpeng Hou <pengpeng@iscas.ac.cn>
---
Changes since v1: https://lore.kernel.org/all/20260701053535.39951-1-pengpeng@iscas.ac.cn/
- drop the redundant short-image check already provided by check_fw_sanity()
- state that the issue was found by source review
- add the requested Fixes tag
- rebase onto v7.2-rc4

 drivers/usb/serial/io_ti.c | 6 ++++++
 1 file changed, 6 insertions(+)

diff --git a/drivers/usb/serial/io_ti.c b/drivers/usb/serial/io_ti.c
index 07c0eff3bef4..cc28f5869a3e 100644
--- a/drivers/usb/serial/io_ti.c
+++ b/drivers/usb/serial/io_ti.c
@@ -1464,6 +1464,12 @@ static int do_boot_mode(struct edgeport_serial *serial,
 		/* Allocate a 15.5k buffer + 3 byte header */
 		buffer_size = (((1024 * 16) - 512) +
 					sizeof(struct ti_i2c_image_header));
+		if (fw->size - 4 > buffer_size) {
+			dev_err(dev, "%s - firmware image is too large\n",
+				__func__);
+			return -EINVAL;
+		}
+
 		buffer = kmalloc(buffer_size, GFP_KERNEL);
 		if (!buffer)
 			return -ENOMEM;
Re: [PATCH v2] USB: serial: io_ti: reject oversized boot-mode firmware
Posted by Johan Hovold 4 days, 11 hours ago
On Mon, Jul 20, 2026 at 07:48:17PM +0800, Pengpeng Hou wrote:
> do_boot_mode() copies the firmware payload, excluding its four-byte prefix,
> into a fixed 15.5 KiB staging buffer. check_fw_sanity() already proves that
> the image contains its seven-byte header and validates the declared image
> length and checksum, but it does not impose this boot-mode destination
> limit.
> 
> Reject images whose payload does not fit before allocating and filling the
> staging buffer.
> 
> Fixes: d12b219a228e ("edgeport-ti: use request_firmware()")
> Signed-off-by: Pengpeng Hou <pengpeng@iscas.ac.cn>
> ---
> Changes since v1: https://lore.kernel.org/all/20260701053535.39951-1-pengpeng@iscas.ac.cn/
> - drop the redundant short-image check already provided by check_fw_sanity()
> - state that the issue was found by source review
> - add the requested Fixes tag
> - rebase onto v7.2-rc4

Applied, thanks.

Johan