[PATCH] staging: greybus: audio_codec: fix stack overflow in stream name parsing

Yudi Yang posted 1 patch 3 weeks, 3 days ago
drivers/staging/greybus/audio_codec.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
[PATCH] staging: greybus: audio_codec: fix stack overflow in stream name parsing
Posted by Yudi Yang 3 weeks, 3 days ago
intf_name and dir are 32-byte buffers. Parsing a module-provided AIF
stream name with unbounded %s conversions can cause buffer-overwrites.
Limit each conversion to 31 characters.

Fixes: 60e7327d54b2 ("greybus: audio: Find data connection based on id")
Cc: stable@vger.kernel.org
Signed-off-by: Yudi Yang <2000jedi@gmail.com>
---
 drivers/staging/greybus/audio_codec.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/staging/greybus/audio_codec.c b/drivers/staging/greybus/audio_codec.c
index 6daa4e706792..c3fefe1414f9 100644
--- a/drivers/staging/greybus/audio_codec.c
+++ b/drivers/staging/greybus/audio_codec.c
@@ -311,7 +311,7 @@ int gbaudio_module_update(struct gbaudio_codec_info *codec,
 	}
 
 	/* parse dai_id from AIF widget's stream_name */
-	if (sscanf(w->sname, "%s %d %s", intf_name, &dai_id, dir) != 3) {
+	if (sscanf(w->sname, "%31s %d %31s", intf_name, &dai_id, dir) != 3) {
 		dev_err(codec->dev, "Error while parsing dai_id for %s\n", w->name);
 		return -EINVAL;
 	}
-- 
2.43.0
Re: [PATCH] staging: greybus: audio_codec: fix stack overflow in stream name parsing
Posted by Greg KH 3 weeks, 3 days ago
On Tue, Sep 01, 2026 at 01:56:00PM -0500, Yudi Yang wrote:
> intf_name and dir are 32-byte buffers. Parsing a module-provided AIF
> stream name with unbounded %s conversions can cause buffer-overwrites.
> Limit each conversion to 31 characters.
> 
> Fixes: 60e7327d54b2 ("greybus: audio: Find data connection based on id")
> Cc: stable@vger.kernel.org
> Signed-off-by: Yudi Yang <2000jedi@gmail.com>
> ---
>  drivers/staging/greybus/audio_codec.c | 2 +-
>  1 file changed, 1 insertion(+), 1 deletion(-)

How was this found and tested?

thanks,

greg k-h
Re: [PATCH] staging: greybus: audio_codec: fix stack overflow in stream name parsing
Posted by Yudi Yang 3 weeks, 2 days ago
I found this with an internal program-analysis tool that I cannot disclose
yet, then manually verified the finding. intf_name and dir are 32-byte
arrays, while the unbounded %s conversions allow tokens from w->sname
longer than 31 characters to overflow them. Using %31s limits each
conversion to 31 characters.

I do not have Greybus hardware, so testing was limited to building the
affected object and running checkpatch.pl

Yudi

On Wed, Sep 2, 2026 at 12:55 AM Greg KH <gregkh@linuxfoundation.org> wrote:
>
> On Tue, Sep 01, 2026 at 01:56:00PM -0500, Yudi Yang wrote:
> > intf_name and dir are 32-byte buffers. Parsing a module-provided AIF
> > stream name with unbounded %s conversions can cause buffer-overwrites.
> > Limit each conversion to 31 characters.
> >
> > Fixes: 60e7327d54b2 ("greybus: audio: Find data connection based on id")
> > Cc: stable@vger.kernel.org
> > Signed-off-by: Yudi Yang <2000jedi@gmail.com>
> > ---
> >  drivers/staging/greybus/audio_codec.c | 2 +-
> >  1 file changed, 1 insertion(+), 1 deletion(-)
>
> How was this found and tested?
>
> thanks,
>
> greg k-h
Re: [PATCH] staging: greybus: audio_codec: fix stack overflow in stream name parsing
Posted by Greg KH 3 weeks, 2 days ago
On Wed, Sep 02, 2026 at 10:17:00AM -0500, Yudi Yang wrote:
> I found this with an internal program-analysis tool that I cannot disclose
> yet, then manually verified the finding. intf_name and dir are 32-byte
> arrays, while the unbounded %s conversions allow tokens from w->sname
> longer than 31 characters to overflow them. Using %31s limits each
> conversion to 31 characters.

Please read our documentation which describes how you need to identify
when you use tools like this.

> I do not have Greybus hardware, so testing was limited to building the
> affected object and running checkpatch.pl

That's not really testing the code :(

Please resubmit based on the documentation requirements.

thanks,

greg k-h