diff options
| author | Bryam Vargas <hexlabsecurity@proton.me> | 2026-06-22 03:55:13 -0500 |
|---|---|---|
| committer | Jonathan Cameron <jic23@kernel.org> | 2026-07-02 20:38:26 +0100 |
| commit | 97e20f3d8630510a1fbb3e066c0f9bf02d8befde (patch) | |
| tree | dedc6a9b0f0fab8c56409538675d74c9c024b35f /tools/perf/scripts/python/bin/stackcollapse-record | |
| parent | eb787019c42072cf13470afca673dab0b49cabb6 (diff) | |
iio: imu: inv_icm45600: clamp the device-reported FIFO sample count
inv_icm45600_buffer_fifo_read() uses the FIFO_COUNT the device reports,
unclamped, as the length of a regmap_noinc_read() into the fixed
INV_ICM45600_FIFO_SIZE_MAX (8 KiB) st->fifo.data buffer. The only bound is
the caller's "max", which the interrupt path skips (it passes 0). A device,
or an attacker on the bus, reporting up to 65535 makes the read as large as
~1 MiB: a heap out-of-bounds write of device-controlled data.
Clamp st->fifo.count to the buffer capacity before the read, and allocate
the buffer with the same INV_ICM45600_FIFO_SIZE_MAX define, so the bound
and the allocation reference one constant. The clamp is a no-op for
conforming hardware.
Signed-off-by: Bryam Vargas <hexlabsecurity@proton.me>
Signed-off-by: Jonathan Cameron <jic23@kernel.org>
Diffstat (limited to 'tools/perf/scripts/python/bin/stackcollapse-record')
0 files changed, 0 insertions, 0 deletions
