From nobody Fri Aug 14 15:50:38 2026 Received: from mail-pl1-f182.google.com (mail-pl1-f182.google.com [209.85.214.182]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id AC3B846D2AC for ; Fri, 14 Aug 2026 13:25:42 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.214.182 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786713943; cv=none; b=lq7UD29q0zAoiTLMk0+RG20WINcTrg8a8MpXy0LrR75bbpazBNCclMrwS/2v6jc30BiiYfdfJIV+j50NkQo/Kj+dZatFHCx59ddYD3FuD6UlSUXmzDbHQmJHBezV8Ddzt7mCcNTKJNPE0LR56JAglwprHYTDzAPiRvU59l5VzgM= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786713943; c=relaxed/simple; bh=1JczU84B8rmiuf0LymRFab/jM+TRSyiW7sJkBS9HHcU=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=WUTmYl7RKSV+w1kg8a6PbuZ15dMOkua1MEMbSmuN4ZNll+SyRvMQVPn4O2YUCH+l5RFd9OLdP9kj7pSEw3BKaCnU4VPuDhO24yAzK172TjgT2AGUSQIkqqhRcXq9ZdsE9nTejMHv3sZTbPEasfOnTPMijgbWkLnnccqz5js8Thw= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=n/6r8ES/; arc=none smtp.client-ip=209.85.214.182 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="n/6r8ES/" Received: by mail-pl1-f182.google.com with SMTP id d9443c01a7336-2ccf2360620so10193505ad.3 for ; Fri, 14 Aug 2026 06:25:42 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1786713942; x=1787318742; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=adjv8vZUdzZ0w4vt4IlqvnT0//3yukWKBpOwksiqJ2s=; b=n/6r8ES/zwXX9QJvxORJYtt3fBQ2eMwmB4sew6m7rJ8Hc7UMJqIQT/kQ7ae3Yde7z0 +uwei/DijzTGmtd9SHHB1bJTiMydoPECPihD8wr3VaAMNui39Qg+xCcOa5Y+BGehAVLx PjSx2KZOocuWFUcEIRUO6NttjBcsiuRdne7JvxRxJsLzZAf0T2eKmWtP/kkFZ+8ME6lO AYUiPSoOEJEowqE8BG9SqKX9xX1zZ59CEP5mWm18Y6jTfcW3S563Ay4zSmRP4f1dZrF0 Vo/kAYXDjvky8VhB16+DUnbfyk66qiLUvBizxl/obXKLScYoNUYShqAHWhv7Z4caK/34 W9xw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786713942; x=1787318742; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=adjv8vZUdzZ0w4vt4IlqvnT0//3yukWKBpOwksiqJ2s=; b=lObjSEgqWLxc1jTADYs4Q5sUnwwk4DYLqJpUf9AsYwRuohWxUtv42mJ2jBnAu2xiFU HVLCPYiIQYl9Nr5Wk/uxtAf6U79miTXDd6FMldDbYaLvKhV8u9UYK/R+rGBZ/zXr9gfk LCIP8G1cQk/s0VqVw4XFX0+hKul4DqLFVz9wTpcBUtM+JCa3+0ud+8JMf+kmTJLigBU5 va0kbMuGJNM9v8n+3tAh9h+athAMvaLwGr01TAhdk5NA94Yw8rvMLkkYSuu02fBWMqKP vCVqnvdZgd3+PdrBBI5T0vltmoQsUQL6PhuQ/5k4mnLYiWwXBYLNzbsPaHQMMHM2ZDPk OREA== X-Forwarded-Encrypted: i=1; AHgh+RpwxR3g07u69s0F6iEt5OXsFogj8cm+8NTd2KhzGtPn7p4h7szqit3+IqGgFdlz07B3bLSqFTzbncEKg9c=@vger.kernel.org X-Gm-Message-State: AOJu0YywtYbXKNAkEo3AFlrw+LHB30DWKYD/sTVe5SFX7LrI2Y7cNSyi QETyXG7IWXaXWUGrDuAzSQo+fEE2F4YyNYMTGmeWinoMjrZkvkecy1I6 X-Gm-Gg: AR+sD100XSVlnN9R8BWImSNp0oFutTjNdYN1WTXF2Qy7AzrT5ONFJmaEQShpucJ3LbG rO4WCiP3AiH4V5crRQP6kv2WEwpvzTok9luqh4hWrZisEEErlR2MYLot0rkE0B/UKeeavzqLhyE kt0ZMNOH8aAP1lSZmId8t5X+G5ICQ10p9mz50Y4E1kL6KzInOnZjk0o1AYr+WpVA0U+EK6aNaEF ksd9O0peyknb7nle9bhCdSYiYHXWaUWCftKx28T58HZKbi0WXP9lpebZYpEqO2eiyDmET9hkfip 9qig26Un9tSXp0kboizLY0L82Oh6xwq/OAC26eEaI6dKeAlHYX6z3lHnhdz5633HGFNb6DPbNp0 SnLpLD4PmAIQ8gD5TEbASH+dH6lMsaPsQWbG4D7tqdWx1IiXnGVYFG39RbElk0JQCSH0NjAQO0N juf2pSxbH2UpJ4oDeY3dtAsoeHLJy2cfgbg29ywr9BNr+KYPUnIpngdLpIkND0EiKzM+dBfSU/w THMzNWDwPvS71eRezi3Qb5QySCfzXwh7jIu4mFrFXcWy5zRubw1GjfSrjUc0A1h X-Received: by 2002:a17:902:e752:b0:2cc:307c:51fc with SMTP id d9443c01a7336-2d3b0dd5affmr60397215ad.21.1786713941808; Fri, 14 Aug 2026 06:25:41 -0700 (PDT) Received: from nugod-NUC15CRHU5.tail9f095a.ts.net ([218.237.104.87]) by smtp.gmail.com with ESMTPSA id d9443c01a7336-2d3ae7a4521sm9636075ad.19.2026.08.14.06.25.39 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 14 Aug 2026 06:25:41 -0700 (PDT) From: HyeongJun An To: Prasanth Ksr , Hans de Goede , =?UTF-8?q?Ilpo=20J=C3=A4rvinen?= Cc: Mario Limonciello , Divya Bharathi , Dell.Client.Kernel@dell.com, platform-driver-x86@vger.kernel.org, linux-kernel@vger.kernel.org, HyeongJun An Subject: [PATCH] platform/x86: dell-wmi-sysman: Fix instance ID bounds Date: Fri, 14 Aug 2026 22:25:35 +0900 Message-ID: <20260814132535.4169956-1-sammiee5311@gmail.com> X-Mailer: git-send-email 2.43.0 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" The get_instance_id() macro walks the per-type attribute array with 'i <=3D instances_count'. Each array is allocated with exactly instances_count entries, so the valid range is [0, instances_count) and the last iteration reads one element past the end. On a name miss that out-of-bounds attribute_name is handed to strcmp(), which reads on until it finds a NUL byte. Every kobject in these ksets is built from an entry that was populated, so a miss does not look reachable from sysfs today. The bound is wrong either way and the read is out of bounds. The matching macro in hp-bioscfg carried the same off-by-one and was corrected by commit 25150715e0b0 ("platform/x86: hp-bioscfg: Fix kernel panic in GET_INSTANCE_ID macro"). That macro takes a kobject pointer out of the out-of-bounds element and dereferences it, so it could fault. This one reads a char array. Use '<' to match the allocation. Fixes: e8a60aa7404b ("platform/x86: Introduce support for Systems Managemen= t Driver over WMI for Dell Systems") Assisted-by: Claude:claude-opus-5 Signed-off-by: HyeongJun An --- drivers/platform/x86/dell/dell-wmi-sysman/dell-wmi-sysman.h | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/drivers/platform/x86/dell/dell-wmi-sysman/dell-wmi-sysman.h b/= drivers/platform/x86/dell/dell-wmi-sysman/dell-wmi-sysman.h index 3bddedad5eba..eb48ced55823 100644 --- a/drivers/platform/x86/dell/dell-wmi-sysman/dell-wmi-sysman.h +++ b/drivers/platform/x86/dell/dell-wmi-sysman/dell-wmi-sysman.h @@ -107,7 +107,7 @@ enum { static int get_##type##_instance_id(struct kobject *kobj) \ { \ int i; \ - for (i =3D 0; i <=3D wmi_priv.type##_instances_count; i++) { \ + for (i =3D 0; i < wmi_priv.type##_instances_count; i++) { \ if (!(strcmp(kobj->name, wmi_priv.type##_data[i].attribute_name)))\ return i; \ } \ --=20 2.43.0