Message ID | 2dc0d93e-2ac7-3f5c-e22c-d5329ec2e7f5@omp.ru (mailing list archive) |
---|---|
State | Accepted |
Commit | 1ce69c35b86038dd11d3a6115a04501c5b89a940 |
Headers | show |
Series | usb: host: xhci: use snprintf() in xhci_decode_trb() | expand |
Hello! On 3/16/22 11:36 PM, Sergey Shtylyov wrote: > Commit cbf286e8ef83 ("xhci: fix unsafe memory usage in xhci tracing") > apparently missed one sprintf() call in xhci_decode_trb() -- replace > it with the snprintf() call as well... > > Found by Linux Verification Center (linuxtesting.org) with the SVACE static > analysis tool. > > Fixes: cbf286e8ef83 ("xhci: fix unsafe memory usage in xhci tracing") > Signed-off-by: Sergey Shtylyov <s.shtylyov@omp.ru> > > --- > This patch is against the 'usb-next' branch of Greg KH's 'usb.git' repo. Mathias, Greg, what's going on with this patch? It was posted 2 months ago and seemingly ignored... :-/ MBR, Sergey
On 17.5.2022 22.13, Sergey Shtylyov wrote: > Hello! > > On 3/16/22 11:36 PM, Sergey Shtylyov wrote: > >> Commit cbf286e8ef83 ("xhci: fix unsafe memory usage in xhci tracing") >> apparently missed one sprintf() call in xhci_decode_trb() -- replace >> it with the snprintf() call as well... >> >> Found by Linux Verification Center (linuxtesting.org) with the SVACE static >> analysis tool. >> >> Fixes: cbf286e8ef83 ("xhci: fix unsafe memory usage in xhci tracing") >> Signed-off-by: Sergey Shtylyov <s.shtylyov@omp.ru> >> >> --- >> This patch is against the 'usb-next' branch of Greg KH's 'usb.git' repo. > > Mathias, Greg, what's going on with this patch? It was posted 2 months ago > and seemingly ignored... :-/ > > MBR, Sergey Must have missed it I'll queue it up for 5.20 unless Greg still picks it up for 5.19. Not urgent. -Mathias
Index: usb/drivers/usb/host/xhci.h =================================================================== --- usb.orig/drivers/usb/host/xhci.h +++ usb/drivers/usb/host/xhci.h @@ -2391,7 +2391,7 @@ static inline const char *xhci_decode_tr field3 & TRB_CYCLE ? 'C' : 'c'); break; case TRB_STOP_RING: - sprintf(str, + snprintf(str, size, "%s: slot %d sp %d ep %d flags %c", xhci_trb_type_string(type), TRB_TO_SLOT_ID(field3),
Commit cbf286e8ef83 ("xhci: fix unsafe memory usage in xhci tracing") apparently missed one sprintf() call in xhci_decode_trb() -- replace it with the snprintf() call as well... Found by Linux Verification Center (linuxtesting.org) with the SVACE static analysis tool. Fixes: cbf286e8ef83 ("xhci: fix unsafe memory usage in xhci tracing") Signed-off-by: Sergey Shtylyov <s.shtylyov@omp.ru> --- This patch is against the 'usb-next' branch of Greg KH's 'usb.git' repo. drivers/usb/host/xhci.h | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-)