From nobody Tue Sep 29 05:35:11 2026 Received: from sg-2-5.ptr.blmpb.com (sg-2-5.ptr.blmpb.com [71.18.227.5]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id E7CB73ACF05 for ; Wed, 12 Aug 2026 07:59:10 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=71.18.227.5 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786521553; cv=none; b=PkL53GOO59K5uPTK5JD7gM2kK4XhAWmbvZEW/KKv38Bz0NREQ96irRzeiHIW1qUkr4vLMdJxuskF7akOY6d29s7wvYvmd+zR+8v+6hiENffgYbxrxHu0BEXNjWmW+Vr45HFI1OC4yzDVc8jiGHw4s4TMgJaqHBlZQ44zbGEmyUw= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786521553; c=relaxed/simple; bh=GeMMm1VvuHQc5O/Qc1ZF934cmcKFtcsga93zBQT8JVI=; h=Subject:In-Reply-To:Content-Type:To:From:Date:Message-Id: References:Cc:Mime-Version; b=Hiub16sQpffrLkMRQRgIgQ4aCvGQkIDfRwrIbHedEjqwvaE7L0sInxdLntBF9CnD/MB7BcddWAZfDaqlxLXj73riKSCs0YROfJLyGTz/F37w9hJUxbVJkFM7+D+D0hdJEwy0Q05qTix7tLM+h3dCZbUug+MyqzqmJRIwP3QnQ+s= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=cherr.cc; spf=pass smtp.mailfrom=cherr.cc; dkim=pass (2048-bit key) header.d=cherr.cc header.i=@cherr.cc header.b=cejp/GOa; arc=none smtp.client-ip=71.18.227.5 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=cherr.cc Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=cherr.cc Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=cherr.cc header.i=@cherr.cc header.b="cejp/GOa" DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; s=feishu2604220257; d=cherr.cc; t=1786521538; h=from:subject: mime-version:from:date:message-id:subject:to:cc:reply-to:content-type: mime-version:in-reply-to:message-id; bh=Tw9iG1KtVJQ7+SktZV1lQpXLURpBc5juHplZa6eihjM=; b=cejp/GOaxIW30TOCRIdRQQRiY9YQlMMeSsd6Xxhpqp6pKr6f15qMYUNGrbMVhqiSIwdqeA Okb5/QqLhX+kGx6VPYUzDo4Wgw+O+lhSf9urG9o/A/pSK8659aSEMu09ZLfLuYItZKrjdC OoYAHg/IhiM5Do05W9k3UdIy/ZRTnbM00vPcb4nuu41z4ewktvN8DwG6dkOvaZh8VAydH9 p9r/dcinFVa9xEGoWxQ8H+h4cZQk05gUm/5JBY7DyicfeZYdSaxw+g2/l0h3fSFT7AoJyQ ma66q6o6tVbHebNZb6pJUK7J+hHmHbcXoEZZfR65arxnhx+8iUC4Ws39BG6smA== Subject: [PATCH v2 1/2] iio: accel: adxl380: reject out-of-range FIFO entry count In-Reply-To: <20260812-adxl-fifo-v2-0-86bea20faf1c@cherr.cc> X-Lms-Return-Path: X-Original-From: Shengzhuo Wei X-Mailer: b4 0.14.2 To: "Ramona Gradinariu" , "Antoniu Miclaus" , =?utf-8?q?Nuno_S=C3=A1?= , "Michael Hennerich" , "Jonathan Cameron" , "David Lechner" , "Andy Shevchenko" , "Marcelo Schmitt" From: "Shengzhuo Wei" Date: Wed, 12 Aug 2026 15:58:49 +0800 Message-Id: <20260812-adxl-fifo-v2-1-86bea20faf1c@cherr.cc> References: <20260812-adxl-fifo-v2-0-86bea20faf1c@cherr.cc> Cc: , , , "Shengzhuo Wei" Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 Received: from [192.168.9.107] ([111.42.148.52]) by smtp.feishu.cn with ESMTPS; Wed, 12 Aug 2026 15:58:55 +0800 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" The FIFO entry count is a 9-bit device-reported value, so it can be as large as 511, but fifo_buf[] only has room for ADXL380_FIFO_SAMPLES (315) entries. adxl380_irq_handler() uses the reported count directly as the length of a bulk FIFO read, so a count above ADXL380_FIFO_SAMPLES overflows fifo_buf, a heap out-of-bounds write of up to 392 bytes into adjacent memory. Rather than clamp the count and silently drop the excess, abort the read: a count beyond the FIFO size means the device is returning garbage, so the data cannot be trusted. The message is ratelimited because a stuck device can raise the watermark IRQ repeatedly. Assisted-by: GLM:5.2 Signed-off-by: Shengzhuo Wei --- drivers/iio/accel/adxl380.c | 7 +++++++ 1 file changed, 7 insertions(+) diff --git a/drivers/iio/accel/adxl380.c b/drivers/iio/accel/adxl380.c index 7dca5523091fc4c6a3c3bf7e388d5d0d507bee19..8518ee23e114901ee02933e91b8= bdf8d7c83008c 100644 --- a/drivers/iio/accel/adxl380.c +++ b/drivers/iio/accel/adxl380.c @@ -966,6 +966,13 @@ static irqreturn_t adxl380_irq_handler(int irq, void = *p) if (ret) return IRQ_HANDLED; =20 + if (fifo_entries > ADXL380_FIFO_SAMPLES) { + dev_err_ratelimited(st->dev, + "FIFO entry count %u exceeds FIFO size %lu\n", + fifo_entries, ADXL380_FIFO_SAMPLES); + return IRQ_HANDLED; + } + fifo_entries =3D rounddown(fifo_entries, st->fifo_set_size); ret =3D regmap_noinc_read(st->regmap, ADXL380_FIFO_DATA, &st->fifo_buf, sizeof(*st->fifo_buf) * fifo_entries); --=20 2.47.3 From nobody Tue Sep 29 05:35:11 2026 Received: from sg-2-3.ptr.blmpb.com (sg-2-3.ptr.blmpb.com [71.18.227.3]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id A9B4D399899 for ; Wed, 12 Aug 2026 07:59:06 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=71.18.227.3 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786521549; cv=none; b=Gh/b8OHhjh+T9K1QqG5xyrSsn8bnGz+N1WUNl/7hhV4eVk/CQ79FDbn1KnI5k5QfcAm5eVzlRxMH2b3q649rJs3d9lTcGhsnzQ3lwJvGrmqB0YVz70+tAia+9FhjZ0w/Lp5Zvfqx3wEV/fUXluFlOshRZxP74ksup3nBGFs5p6o= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786521549; c=relaxed/simple; bh=75+FhvgZvHiJP4mRloJbM/2PVzFlJgOMPnn/g1sxz6c=; h=Subject:In-Reply-To:Mime-Version:Content-Type:To:Cc:From: Message-Id:References:Date; b=PCrbrSdKu0Eu83+NO8+Ze1u/TgYCEG13TvaYks/O6RJFUuOmSvB38fPnFrxatyS4sf/dO1HPNFsBL4AFqI9uahx5LDxIFlTUa8WecJUXbYj2iPnoy91jAfxR4AuAPXRvgzOA/WjnpS9WPU5bUk8x5v9yJO++4PDZ5qEC9dUEiqc= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=cherr.cc; spf=pass smtp.mailfrom=cherr.cc; dkim=pass (2048-bit key) header.d=cherr.cc header.i=@cherr.cc header.b=GPTePD3V; arc=none smtp.client-ip=71.18.227.3 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=cherr.cc Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=cherr.cc Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=cherr.cc header.i=@cherr.cc header.b="GPTePD3V" DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; s=feishu2604220257; d=cherr.cc; t=1786521541; h=from:subject: mime-version:from:date:message-id:subject:to:cc:reply-to:content-type: mime-version:in-reply-to:message-id; bh=wI2Ad98c9KKRqH+lpOMl2Ygtab5lbfNg/qA/hfqkkEY=; b=GPTePD3VVSPKvwi0cwC6afKN0YdPSSvADFZAxGArQuDH4ccUpQNJ713qT4uTDU/3QxnvwQ wIdLo8ZemdCyE4F6vAvMy1Z/ii5bc4H3pLp+lSWeAzGPkTTruTs/TbxGAO/Lkeeqc+MpRI RGHW+KT2LqenzpJ3R09NLpuf6/ZuOhLJBHdgZ4IJYCq5wswBCDfhY4VS/eXlGroawWR8x1 VUbVHVt8KMwzCINajwAVvc7JVo9DA+bMsrI2yKflZpLh93oE4v0MhYHc3GigeSeQwkTpKJ mT5Zs5g+A5zD/a49dQDOUv9xOajs1gw6aJKbeHiGg8ESyXJcjzwcGUJOreBXlg== Subject: [PATCH v2 2/2] iio: accel: adxl367: reject out-of-range FIFO entry count Received: from [192.168.9.107] ([111.42.148.52]) by smtp.feishu.cn with ESMTPS; Wed, 12 Aug 2026 15:58:58 +0800 In-Reply-To: <20260812-adxl-fifo-v2-0-86bea20faf1c@cherr.cc> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 X-Original-From: Shengzhuo Wei Content-Transfer-Encoding: quoted-printable To: "Ramona Gradinariu" , "Antoniu Miclaus" , =?utf-8?q?Nuno_S=C3=A1?= , "Michael Hennerich" , "Jonathan Cameron" , "David Lechner" , "Andy Shevchenko" , "Marcelo Schmitt" Cc: , , , "Shengzhuo Wei" From: "Shengzhuo Wei" Message-Id: <20260812-adxl-fifo-v2-2-86bea20faf1c@cherr.cc> References: <20260812-adxl-fifo-v2-0-86bea20faf1c@cherr.cc> X-Lms-Return-Path: Date: Wed, 12 Aug 2026 15:58:50 +0800 X-Mailer: b4 0.14.2 Content-Type: text/plain; charset="utf-8" The FIFO entry count reported by the device can be as large as 1023 (the low byte plus the low two bits of the high byte), but fifo_buf[] only has room for ADXL367_FIFO_SIZE (512) entries. adxl367_push_fifo_data() passes the reported count straight to the FIFO read, so a count above ADXL367_FIFO_SIZE overflows fifo_buf, a heap out-of-bounds write of up to 1022 bytes into adjacent memory. Rather than clamp the count and silently drop the excess, abort the read: a count beyond the FIFO size means the device is returning garbage, so the data cannot be trusted. The message is ratelimited because a stuck device can raise the IRQ repeatedly. Assisted-by: GLM:5.2 Signed-off-by: Shengzhuo Wei --- drivers/iio/accel/adxl367.c | 8 ++++++++ 1 file changed, 8 insertions(+) diff --git a/drivers/iio/accel/adxl367.c b/drivers/iio/accel/adxl367.c index 8c3de11a10a37d228f8758b688156e3ee958c4e9..270d6feede2f60f4274dead7b39= 74cd04abb14a6 100644 --- a/drivers/iio/accel/adxl367.c +++ b/drivers/iio/accel/adxl367.c @@ -787,6 +787,14 @@ static bool adxl367_push_fifo_data(struct iio_dev *ind= io_dev, u8 status, if (!FIELD_GET(ADXL367_STATUS_FIFO_FULL_MASK, status)) return false; =20 + if (fifo_entries > ADXL367_FIFO_SIZE) { + dev_err_ratelimited(st->dev, + "FIFO entry count %u exceeds FIFO size %lu\n", + fifo_entries, + (unsigned long)ADXL367_FIFO_SIZE); + return true; + } + fifo_entries -=3D fifo_entries % st->fifo_set_size; =20 ret =3D st->ops->read_fifo(st->context, st->fifo_buf, fifo_entries); --=20 2.47.3