Repository navigation
seagate: clamp fw-activate-history entry count, bound JSON string copies - #3993
Merged
Merged
Conversation
…copy The 0xC2 vendor log page is device-supplied. Two lapses on the fw-activate-history display paths: - numValidFwActHisEnt (device u32) was used as the loop bound against the compiled-in fwActHisEnt[20] table. Clamp it to the table size right after the read so both the plain and JSON views can only walk the entries actually present. - the JSON view used sprintf(prev_fw, "%s", previousFW) into 8-byte buffers, but previousFW/newFW are fixed-width fields with no NUL guarantee, so a malformed page would walk past the buffer giving a device-controlled stack overflow. Switch to 9-byte zeroed buffers with an explicit size copy, mirroring the plain-print path. Signed-off-by: Prabhakar Pujeri <prabhakar.pujeri@dell.com>
Collaborator
|
Thanks! |
This was referenced Sep 15, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
The Seagate 0xC2 vendor log page is device-supplied, and the
fw-activate-historydisplay paths trusted two fields in it:numValidFwActHisEnt(a device u32) was used directly as the loopbound against the compiled-in
fwActHisEnt[20]table — a count >20 walks past the table in both the plain and JSON views.
previousFW/newFWwithsprintf(char[8], "%s", …)from fixed-widthu8[8]fields that carryno NUL guarantee — a malformed page gives a device-controlled stack
overflow (the plain view copies by size into 9-byte buffers and is
safe).
Fix
numValidFwActHisEntto the table size immediately after thesingle log read, so both display paths can only walk real entries.
zeroed buffers, exactly mirroring the plain-print path construction.
The clamp mutates only the local stack struct and only on the success
path; nothing prints the raw count afterwards, so the display simply
tops out at the table size.
Validation
adversarial fixtures (
numValidFwActHisEnt = 0xffffffff, 8-byte FWfields without NULs): pre-fix path reports
stack-buffer-overflowinold_json_path; fixed path passes clamp-max-20, pass-through onsmall counts, and 8-byte NUL-termination checks (4/4).