From nobody Sat Jul 25 02:11:49 2026 Received: from mail-pl1-f175.google.com (mail-pl1-f175.google.com [209.85.214.175]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 7914842A7BD for ; Mon, 20 Jul 2026 14:13:06 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.214.175 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784556787; cv=none; b=Nft61NzAJcbENzrUZvH2y4SejgbJS5XTICuMJpLFiyYvVKBfKgM6VLPPWie5iwq1aPJAARguMjUsAoPpJXqC0EgKKT3JStUFQHz12HX2YeRPF/P0r0kUvognzH38amYkn4v15asBpbvfdpIO6adP0CpvST8VIHBLKBlnVxtYtFo= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784556787; c=relaxed/simple; bh=ll/49uWw98HtG13jkCuju/9QKWipJ0XC4X80ruQl+0g=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=WHOOPgPXvoirgZPSneAarYPeXbl0M+DHgAjO62ShKpPObGQx0Ev5qO1ajBosxXlsGWeQ/NtRrCk0li50bnCv7J0WEz0wFZYXGzUqcMP5g3O8szs98dHZZaCQBeGXLLzvGcvjm3Ds730aJ+TiPiLOjSTujKoBthzggt6sw6494Bw= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=YUvz6sRX; arc=none smtp.client-ip=209.85.214.175 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="YUvz6sRX" Received: by mail-pl1-f175.google.com with SMTP id d9443c01a7336-2caea3f742bso122051865ad.0 for ; Mon, 20 Jul 2026 07:13:06 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1784556786; x=1785161586; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=8N2Eh9+kjraqWaH+OPY3y8zXKExuWvOOjFqxAzkUc8Y=; b=YUvz6sRXLCKIUbvPwsr3z682faCfkRgi809np2S4wfrofdvICjkcq2Fkwb6Bx0+8Zl kS73aJylM9lfn2hP9knK4rphUQQ951M8NrC218NUdA2Wh/Csv5K8rNw6Ee/WvhCIDG/b Rzp8a0qGuLlgY0zsywmS6PdQ7/AbcB1eTFcu+kB1r+hFW6nT+wiRK2H6pDTVucQ358kG 2KIqUiJ2WAF6UE2Ff9utOYASZkJlepvWC0nOxCouikF4YjpuWu24WTbtyDO0YhECL+y2 BvqENTjpt/Ner8+8/YkxAr/P1NsBofKmbgskiD2zirVusvwYB1kQvcS/RLOVSJ8UC4zX kXQw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784556786; x=1785161586; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=8N2Eh9+kjraqWaH+OPY3y8zXKExuWvOOjFqxAzkUc8Y=; b=btwXJBlpSVAA0gFT12yTaWFlDKFmfe6u6U4WYEyNGHPjB8gJbW3+3owtlSm9iyYyvX wnE2+HyeoVeDOrUfrHDChj+6Tpbki5pInSemJ6lle1bvQNObiqu1XdOYjDTNbRcUkGa7 wni3EY+5CO72amm0A+eGUYF1hycy1UVGzUGvhvFA1MyMgREvhltQ70MGnGOXZ2aoM+3P 19wKkZke7PAxtg+PBbl/toppXgxP7DrNsSe/Zi07Cch+D2lZQLXslX7gUh2Ur4JnSXpn AfYnqV/mFJLui56g0Sfe9lPgK9J4/iZJXlR5ey3xhu0SZXW9Y+/tkIc5c/eUlBqlS+rx 4nKg== X-Forwarded-Encrypted: i=1; AHgh+RpjbxH/WQ1pxqt7Y3YBqC8+pE/lu9ywU/7e7IlpsPieQErTZinG0w5F3fe59FCPwb3uJnZPzKCKlLQ0Ses=@vger.kernel.org X-Gm-Message-State: AOJu0YzSQyIlrkbgePZYVzAoxBEaj9QjPUyJPEE3HNyyTJ8eVFV8LmTQ 5NJBmnILCaMkUAcAkL3AtBCfQD8/acpf1KtdKiE7nVla8akmSLUijgNE X-Gm-Gg: AR+sD12oX4NngAxYik8HCQVTxAzhX1/ND3F/XwFBfXT9S3PLlWQnrdmyljAvpez6Avn 8MwA09lamHV4nqWnWXPb9UDigwobfVjomt66ZldYZ7m/e0mIPJdc5ISHb4lfX6c76IudABRK7WY lOrIvZVojJIjBXGD2bu/PyiAJTWjm8q0A2ljSulOjGbd+/qRPYW+VqsFnb3QeZJjV1MG8+UecKn xjX35l5cWSGd4NabAb/TuG2MpK0SuhUYm1gcCSLhWFE0sry7zvkHW+csxiu+xrMdgtPAJUdtVps Rke7gkdcYDTWYmhYZvJc1Oba6potmJhhzkzMVhDB0LXVuJRSD+ORe5vUume+vN8sDVatRCO5pDm Vv8qFScYu5ML9xRB4rFn8itHPII4Zs5FQKLoR/zIlDO/D4Cv8gS4W4taGYxIFskWjYfyXIgfmby qPCOa1NDLx5Qlq7mQc1YjRZpuzjrnA6ywkwagnSxUWr38LdUuHzl2mN0O5TVt8iuaeWjc= X-Received: by 2002:a17:903:3243:b0:2ca:ca48:c36a with SMTP id d9443c01a7336-2cf348f9dc4mr150032705ad.18.1784556785760; Mon, 20 Jul 2026 07:13:05 -0700 (PDT) Received: from nugod-NUC15CRHU5.tail9f095a.ts.net ([218.237.104.87]) by smtp.gmail.com with ESMTPSA id d9443c01a7336-2cf34730e35sm57578155ad.64.2026.07.20.07.13.02 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 20 Jul 2026 07:13:05 -0700 (PDT) From: HyeongJun An To: pratyush@kernel.org, mwalle@kernel.org, tudor.ambarus@linaro.org, miquel.raynal@bootlin.com, richard@nod.at, vigneshr@ti.com Cc: takahiro.kuwano@infineon.com, linux-mtd@lists.infradead.org, linux-kernel@vger.kernel.org, stable@vger.kernel.org, HyeongJun An Subject: [PATCH v2 1/2] mtd: spi-nor: sfdp: check the length of the xSPI Profile 1.0 table Date: Mon, 20 Jul 2026 23:11:03 +0900 Message-ID: <20260720141104.2054417-2-sammiee5311@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260720141104.2054417-1-sammiee5311@gmail.com> References: <20260720141104.2054417-1-sammiee5311@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" The spi_nor_parse_profile1() sizes its buffer from the table length the flash reports in the SFDP parameter header. But it then reads DWORD1, DWORD4 and DWORD5 without ever checking the table is that long. So if a flash reports a length of one, the buffer is only four bytes while DWORD4 and DWORD5 sit at byte offsets 12 and 16. With a length of zero kmalloc() returns ZERO_SIZE_PTR rather than an error, so the NULL check doesn't catch it and the first read dereferences it. And the value doesn't just get thrown away. It ends up as the dummy cycle count for 8D-8D-8D fast reads. To fix this, reject a table that's too short for the highest DWORD the parser reads, the way spi_nor_parse_4bait() already does. The table is optional, so this isn't fatal. The spi_nor_parse_sfdp() warns and carries on. Fixes: fb27f198971a ("mtd: spi-nor: sfdp: parse xSPI Profile 1.0 table") Cc: stable@vger.kernel.org Assisted-by: Claude:claude-opus-4-8 Signed-off-by: HyeongJun An --- drivers/mtd/spi-nor/sfdp.c | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/drivers/mtd/spi-nor/sfdp.c b/drivers/mtd/spi-nor/sfdp.c index 4600983cb579..ece8bbd4bc47 100644 --- a/drivers/mtd/spi-nor/sfdp.c +++ b/drivers/mtd/spi-nor/sfdp.c @@ -1175,6 +1175,7 @@ static int spi_nor_parse_4bait(struct spi_nor *nor, #define PROFILE1_DWORD5_DUMMY_166MHZ GENMASK(31, 27) #define PROFILE1_DWORD5_DUMMY_133MHZ GENMASK(21, 17) #define PROFILE1_DWORD5_DUMMY_100MHZ GENMASK(11, 7) +#define SFDP_PROFILE1_DWORD_MIN 5 =20 /** * spi_nor_parse_profile1() - parse the xSPI Profile 1.0 table @@ -1192,6 +1193,9 @@ static int spi_nor_parse_profile1(struct spi_nor *nor, int ret; u8 dummy, opcode; =20 + if (profile1_header->length < SFDP_PROFILE1_DWORD_MIN) + return -EINVAL; + len =3D profile1_header->length * sizeof(*dwords); dwords =3D kmalloc(len, GFP_KERNEL); if (!dwords) --=20 2.43.0 From nobody Sat Jul 25 02:11:49 2026 Received: from mail-pl1-f175.google.com (mail-pl1-f175.google.com [209.85.214.175]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id AC88442B32D for ; Mon, 20 Jul 2026 14:13:11 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.214.175 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784556792; cv=none; b=IdV2jh9gQQOuthR3XojVaPxPXSpTKyNMSXEz97tR86QsvfphG5dNWIkg/66k+N5b3eNs4/MXjOosx4vQJY5yfrwIFjueW/XxY5YCoWkLaZCBs4BE6u+9uLE+DWmvluqjelpIl3kVSGiEukXaGRN21yU3UVTc1FosYhtsTD9jVno= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784556792; c=relaxed/simple; bh=itB2O4GUgGv95QM0OP7pQVex4/safeVqHqwTGlJLAw8=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=DQE+vEtqkf3TsXBGC/ScGbYKpUw98VbznE6WqZtU7UFHD1YrsoESiR8AeVrKH8JOCbpiQzjl17omY9+0E0jexv6C2tFjfz+zD+0VCMfEv1kXoh16a7i0CBWu3SmCtosegETqDjKxN+1mSmylPHPcvpDnzljg1qG/rAIqjPapmgQ= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=T1zv1Glt; arc=none smtp.client-ip=209.85.214.175 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="T1zv1Glt" Received: by mail-pl1-f175.google.com with SMTP id d9443c01a7336-2ceaf8a1265so98989335ad.2 for ; Mon, 20 Jul 2026 07:13:11 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1784556791; x=1785161591; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=b8XF7nrzvK9JY0N2y+Fglwp5PAhvkeA4CdEStxZj/5I=; b=T1zv1Glt7Jkta70E8ULlx0lpkHv+I2u/NFaaP/FhIolf0jJFVyVan7q0w/wS9hGBpu 5mH5azZ6cR7sSdkagz43S6NCeBQW/a1QJ3fVyd1bB6U3S7M7gsDHawy8ToJDtGxzO3+z 0PiDZLtVMEaNOK+OYC8jQGTabZ2yxrtzHHMY6g6H4ebWcdNPN0Tni4D9gWq8pUHJMLUg wQ5asiBvelb3Isy2AfkbW+zMn+G8vkSsTXLQUUZyO0nm+Ec3t1UGRCpVQqvrV29+1frH Ro5jbAxcHD5HZo8lDDJNEpBUGwWgkBjmskRVKYTGIpoZfs9U4PHi65qtj2GQ4+VIE8e0 N/Sw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784556791; x=1785161591; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=b8XF7nrzvK9JY0N2y+Fglwp5PAhvkeA4CdEStxZj/5I=; b=eQH5K9ohd0xBjln9XO2nCylPIrYWfoHkhxo2T6WW1gVhioYUm/UrJ3utp+nDVbEyMD aI2J3grocJuvPQePL7L5JoOvFX4c9utpMB9P3DWPv5Hf9PJ+882fhjtt316fLbB03VYz 8xRQl/CctDMrk3kZqLI97t+fEWbem8joTRAbX67jy1jW4x+YH0BY+Pai7B+jr6T+/4sy GB5GcV7Kx9c1V+Ol9e7am0tCmSXYrWQnXPL+JCfyeS6xifE1Q6HKegehfmtoir6USOAd vKjiTzsObKxxHT+UF4EAj9AuRoMFhePqGoF5fboJsa5sr0MlILO9E5xF/Cn8fip+IJPt CrpA== X-Forwarded-Encrypted: i=1; AHgh+Rr0cIrtky75p/eFYpnEpE/xHoprlIXeXWAy+2/vVh6J7ahz9lj154s5BbamAfSANvMORH2jhXDnfgxICxs=@vger.kernel.org X-Gm-Message-State: AOJu0YzsqEsh2X8Kl1cpJ6vjULEAt80hJ/9Qf9t3/3wf53uVsu/iCyPK mR/UYEUlMB5suHQ3t6a8SBmZNP/5OYwQic7pKqnMDcS6QcwprTZh8SXY X-Gm-Gg: AR+sD10sNBRC6/KHQCiU08UsRlWO15erZrKaw6L+FRdMaax4nTnRpJigCAbmIZdvzeC S/Iacxmktu8isc1yhfkM4WxUXm91hcVk8pk/LjpnlfdqcprboVwnBN3pqFQUZdiWFESBIk3lXqs etiWh5dxCSqOqdIhFJDU0F8gRUusrYoYyr8qhyzfhomo5E+j4+Bss/tjv6ObkKpH27YjfZ/R14P bsKsTJeQXsj0tK6cQW4M62IHQjGJNQK391F6xn+u2TUsz4nODzQTWG3XTDLyIhV+MSkvsN7Njm3 L9VVvI0h0E8PELieH6F//ZvXBU1I5FNIgostCQCojIKTyQs4dOAylAek+PKXDvM3bCJcyhBUXPs 70tYJZb//2rCl8QL37/V/jn5iQPmNtW8+/WuTnNldQkQHfTRMYrTPTzE41GCvTk+Cjy+G6fZrkX QPXlXaPk78/Lk+TuG6faXwIapwLotSnk2wSN+0ddHSUTJOaZLMtkMwWgXW+/GTVYdrAvk= X-Received: by 2002:a17:902:cecd:b0:2c9:9a19:10c with SMTP id d9443c01a7336-2cf34a4c9d7mr151190115ad.40.1784556790807; Mon, 20 Jul 2026 07:13:10 -0700 (PDT) Received: from nugod-NUC15CRHU5.tail9f095a.ts.net ([218.237.104.87]) by smtp.gmail.com with ESMTPSA id d9443c01a7336-2cf34730e35sm57578155ad.64.2026.07.20.07.13.07 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 20 Jul 2026 07:13:10 -0700 (PDT) From: HyeongJun An To: pratyush@kernel.org, mwalle@kernel.org, tudor.ambarus@linaro.org, miquel.raynal@bootlin.com, richard@nod.at, vigneshr@ti.com Cc: takahiro.kuwano@infineon.com, linux-mtd@lists.infradead.org, linux-kernel@vger.kernel.org, stable@vger.kernel.org, HyeongJun An Subject: [PATCH v2 2/2] mtd: spi-nor: sfdp: check the length of the SCCR map Date: Mon, 20 Jul 2026 23:11:04 +0900 Message-ID: <20260720141104.2054417-3-sammiee5311@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260720141104.2054417-1-sammiee5311@gmail.com> References: <20260720141104.2054417-1-sammiee5311@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" The spi_nor_parse_sccr() sizes its buffer from the table length the flash reports in the SFDP parameter header. But it then reads DWORD1 and DWORD22 without ever checking the table is that long. So if a flash reports a length of one, the buffer is only four bytes while DWORD22 sits at byte offset 84. With a length of zero kmalloc() returns ZERO_SIZE_PTR rather than an error, so the NULL check doesn't catch it and the first read dereferences it. To fix this, reject a table that's too short for the highest DWORD the parser reads, the way spi_nor_parse_4bait() already does. The table is optional, so this isn't fatal. The spi_nor_parse_sfdp() warns and carries on. The spi_nor_parse_sccr_mc() doesn't need the same check. It works out the number of dice from the length it allocated with, so its highest index stays inside the buffer. Fixes: 7ab8b810757a ("mtd: spi-nor: sfdp: Add support for SCCR map for mult= i-chip device") Cc: stable@vger.kernel.org Assisted-by: Claude:claude-opus-4-8 Signed-off-by: HyeongJun An --- drivers/mtd/spi-nor/sfdp.c | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/drivers/mtd/spi-nor/sfdp.c b/drivers/mtd/spi-nor/sfdp.c index ece8bbd4bc47..98559536d41b 100644 --- a/drivers/mtd/spi-nor/sfdp.c +++ b/drivers/mtd/spi-nor/sfdp.c @@ -1266,6 +1266,7 @@ static int spi_nor_parse_profile1(struct spi_nor *nor, } =20 #define SCCR_DWORD22_OCTAL_DTR_EN_VOLATILE BIT(31) +#define SFDP_SCCR_DWORD_MIN 22 =20 /** * spi_nor_parse_sccr() - Parse the Status, Control and Configuration Regi= ster @@ -1284,6 +1285,9 @@ static int spi_nor_parse_sccr(struct spi_nor *nor, size_t len; int ret; =20 + if (sccr_header->length < SFDP_SCCR_DWORD_MIN) + return -EINVAL; + len =3D sccr_header->length * sizeof(*dwords); dwords =3D kmalloc(len, GFP_KERNEL); if (!dwords) --=20 2.43.0