From nobody Fri Oct 2 04:27:53 2026 Received: from mout01.posteo.de (mout01.posteo.de [185.67.36.65]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id D04E63DD532 for ; Wed, 5 Aug 2026 07:19:28 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=185.67.36.65 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785914371; cv=none; b=BmabE9L9wBs45+ETd8EQsMuk0IS5if4rdfejIwgwAO0hYlf0AEaKk/hPQAr2eQ0K/VqaW403cZFCKVZ1TK+M0qs+aOfiwRT3frT8M6bCv2mijdu03OcY5UjJV4m90b8urhxPs+LeX0RgBXeq9eeZHAOkRinKN8vHqX7U7gFb9IQ= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785914371; c=relaxed/simple; bh=2oarunofIitNGHsvRdX8ynsA0UjH/P83LFftPyDtbEI=; h=Date:From:To:Cc:Subject:Message-ID:MIME-Version:Content-Type: Content-Disposition; b=kZ786aXj2TdI8GY4nYVsw4mr/evBTOhRYwnTS/RCq1diV1ALq6RhltLQ5cJuNOMcSVBolq7abvEpsjUanX3DgBtkVnHdrQ1IL6rXrNX9xGicbHukyNbRvutuxdjreF2iv37+UDm7xNWlyjrK05tA4mUPx53LEzyiVaKM6AfBZt0= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=posteo.net; spf=pass smtp.mailfrom=posteo.net; dkim=pass (2048-bit key) header.d=posteo.net header.i=@posteo.net header.b=GXLtHmol; arc=none smtp.client-ip=185.67.36.65 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=posteo.net Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=posteo.net Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=posteo.net header.i=@posteo.net header.b="GXLtHmol" Received: from submission (posteo.de [185.67.36.169]) by mout01.posteo.de (Postfix) with ESMTPS id 9D6DB240027 for ; Wed, 5 Aug 2026 09:19:20 +0200 (CEST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=posteo.net; s=1984.8680eb; t=1785914360; bh=cRnJltpsyJ+e75vATyEi43129mtePB+PUvX0ryGqwEA=; h=Date:From:To:Cc:Subject:Message-ID:MIME-Version:Content-Type: Content-Disposition:From; b=GXLtHmolKk1cVZRVCDVODEjVvIvbCcaDszoewLImxoXNwVSd8w8U6IMdgb/cdlrgy tuiaA3zgErCAuGXYtQevMiBRZ6aN537UNIJhWypvq5OtNMv/HRAYjY5mag3FcOxC54 dAJOSsvg2ewolF2nqKUECurXh0fGkQ+NniDfbJqUrbC++eIh8SbsK/4AcMhEtw+QF1 JkDG6+a9o18R20XDAYapCCufYiM4niCwT3Wrb/B9nmcQ2PujlgKE+EztqukHARVpJB PS8jtEaREzWx06C2gV4DuJr8r/9A7XpkTSGDBU2onMI9KHJzXRn57o2orII5U6A3S2 3zk/coZdePLxg== Received: from customer (localhost [127.0.0.1]) by submission (posteo.de) with ESMTPSA id 4hFMGw0Ymwz9rxP; Wed, 5 Aug 2026 09:19:19 +0200 (CEST) Date: Wed, 05 Aug 2026 07:19:20 +0000 From: Wilken Gottwalt To: linux-kernel@vger.kernel.org Cc: Guenter Roeck , linux-hwmon@vger.kernel.org Subject: [PATCH] hwmon: corsair-psu: fix possible out-of-bounds access on missing string termination Message-ID: Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Disposition: inline Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" In theory it could be possible that the REPLY_SIZE sized buffers for holding the vendor and product strings could be end up missing the null termination (for example by malicious hardware built on purpose) required by the seq_printf() call. That limits the debugfs printf calls to a maximum string length of REPLY_SIZE. Fixes: d115b51e0e567 ("hwmon: add Corsair PSU HID controller driver") Signed-off-by: Wilken Gottwalt --- drivers/hwmon/corsair-psu.c | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/drivers/hwmon/corsair-psu.c b/drivers/hwmon/corsair-psu.c index ce958cdaef58..3cb0ba592250 100644 --- a/drivers/hwmon/corsair-psu.c +++ b/drivers/hwmon/corsair-psu.c @@ -701,7 +701,7 @@ static int vendor_show(struct seq_file *seqf, void *unu= sed) { struct corsairpsu_data *priv =3D seqf->private; =20 - seq_printf(seqf, "%s\n", priv->vendor); + seq_printf(seqf, "%.*s\n", REPLY_SIZE, priv->vendor); =20 return 0; } @@ -711,7 +711,7 @@ static int product_show(struct seq_file *seqf, void *un= used) { struct corsairpsu_data *priv =3D seqf->private; =20 - seq_printf(seqf, "%s\n", priv->product); + seq_printf(seqf, "%.*s\n", REPLY_SIZE, priv->product); =20 return 0; } --=20 2.55.0