From: Pali Rohár Date: Mon, 27 Jul 2020 13:38:34 +0000 (+0200) Subject: mmc: sdio: Check for CISTPL_VERS_1 buffer size X-Git-Url: http://git.maquefel.me/?a=commitdiff_plain;h=8ebe2607965d3e2dc02029e8c7dd35fbe508ffd0;p=linux.git mmc: sdio: Check for CISTPL_VERS_1 buffer size Before parsing CISTPL_VERS_1 structure check that its size is at least two bytes to prevent buffer overflow. Signed-off-by: Pali Rohár Link: https://lore.kernel.org/r/20200727133837.19086-2-pali@kernel.org Signed-off-by: Ulf Hansson --- diff --git a/drivers/mmc/core/sdio_cis.c b/drivers/mmc/core/sdio_cis.c index e0655278c5c32..3efaa9534a777 100644 --- a/drivers/mmc/core/sdio_cis.c +++ b/drivers/mmc/core/sdio_cis.c @@ -26,6 +26,9 @@ static int cistpl_vers_1(struct mmc_card *card, struct sdio_func *func, unsigned i, nr_strings; char **buffer, *string; + if (size < 2) + return 0; + /* Find all null-terminated (including zero length) strings in the TPLLV1_INFO field. Trailing garbage is ignored. */ buf += 2;