drivers/staging/greybus/audio_codec.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-)
intf_name and dir are 32-byte buffers. Parsing a module-provided AIF
stream name with unbounded %s conversions can cause buffer-overwrites.
Limit each conversion to 31 characters.
Fixes: 60e7327d54b2 ("greybus: audio: Find data connection based on id")
Cc: stable@vger.kernel.org
Signed-off-by: Yudi Yang <2000jedi@gmail.com>
---
drivers/staging/greybus/audio_codec.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/staging/greybus/audio_codec.c b/drivers/staging/greybus/audio_codec.c
index 6daa4e706792..c3fefe1414f9 100644
--- a/drivers/staging/greybus/audio_codec.c
+++ b/drivers/staging/greybus/audio_codec.c
@@ -311,7 +311,7 @@ int gbaudio_module_update(struct gbaudio_codec_info *codec,
}
/* parse dai_id from AIF widget's stream_name */
- if (sscanf(w->sname, "%s %d %s", intf_name, &dai_id, dir) != 3) {
+ if (sscanf(w->sname, "%31s %d %31s", intf_name, &dai_id, dir) != 3) {
dev_err(codec->dev, "Error while parsing dai_id for %s\n", w->name);
return -EINVAL;
}
--
2.43.0
On Tue, Sep 01, 2026 at 01:56:00PM -0500, Yudi Yang wrote:
> intf_name and dir are 32-byte buffers. Parsing a module-provided AIF
> stream name with unbounded %s conversions can cause buffer-overwrites.
> Limit each conversion to 31 characters.
>
> Fixes: 60e7327d54b2 ("greybus: audio: Find data connection based on id")
> Cc: stable@vger.kernel.org
> Signed-off-by: Yudi Yang <2000jedi@gmail.com>
> ---
> drivers/staging/greybus/audio_codec.c | 2 +-
> 1 file changed, 1 insertion(+), 1 deletion(-)
How was this found and tested?
thanks,
greg k-h
I found this with an internal program-analysis tool that I cannot disclose
yet, then manually verified the finding. intf_name and dir are 32-byte
arrays, while the unbounded %s conversions allow tokens from w->sname
longer than 31 characters to overflow them. Using %31s limits each
conversion to 31 characters.
I do not have Greybus hardware, so testing was limited to building the
affected object and running checkpatch.pl
Yudi
On Wed, Sep 2, 2026 at 12:55 AM Greg KH <gregkh@linuxfoundation.org> wrote:
>
> On Tue, Sep 01, 2026 at 01:56:00PM -0500, Yudi Yang wrote:
> > intf_name and dir are 32-byte buffers. Parsing a module-provided AIF
> > stream name with unbounded %s conversions can cause buffer-overwrites.
> > Limit each conversion to 31 characters.
> >
> > Fixes: 60e7327d54b2 ("greybus: audio: Find data connection based on id")
> > Cc: stable@vger.kernel.org
> > Signed-off-by: Yudi Yang <2000jedi@gmail.com>
> > ---
> > drivers/staging/greybus/audio_codec.c | 2 +-
> > 1 file changed, 1 insertion(+), 1 deletion(-)
>
> How was this found and tested?
>
> thanks,
>
> greg k-h
On Wed, Sep 02, 2026 at 10:17:00AM -0500, Yudi Yang wrote: > I found this with an internal program-analysis tool that I cannot disclose > yet, then manually verified the finding. intf_name and dir are 32-byte > arrays, while the unbounded %s conversions allow tokens from w->sname > longer than 31 characters to overflow them. Using %31s limits each > conversion to 31 characters. Please read our documentation which describes how you need to identify when you use tools like this. > I do not have Greybus hardware, so testing was limited to building the > affected object and running checkpatch.pl That's not really testing the code :( Please resubmit based on the documentation requirements. thanks, greg k-h
© 2016 - 2026 Red Hat, Inc.