[PATCH 2/3] wifi: ath12k: Reserve space for a string terminator
Jiale Yao
yaojiale02 at 163.com
Sat Sep 26 05:12:49 PDT 2026
ath12k_write_htt_stats_type() accepts count == size, which fills the
zero-initialized buffer without a terminating NUL. sscanf() then reads
beyond the buffer.
Reject input that leaves no room for the trailing NUL.
Fixes: 8c7a5031a6b0 ("wifi: ath12k: Fix buffer overflow in debugfs")
Signed-off-by: Jiale Yao <yaojiale02 at 163.com>
---
drivers/net/wireless/ath/ath12k/debugfs_htt_stats.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/net/wireless/ath/ath12k/debugfs_htt_stats.c b/drivers/net/wireless/ath/ath12k/debugfs_htt_stats.c
index b772181a496e..f84f1828275a 100644
--- a/drivers/net/wireless/ath/ath12k/debugfs_htt_stats.c
+++ b/drivers/net/wireless/ath/ath12k/debugfs_htt_stats.c
@@ -6190,7 +6190,7 @@ static ssize_t ath12k_write_htt_stats_type(struct file *file,
const int size = 32;
int num_args;
- if (count > size)
+ if (count >= size)
return -EINVAL;
char *buf __free(kfree) = kzalloc(size, GFP_KERNEL);
--
2.34.1
More information about the ath12k
mailing list