[PATCH 2/3] wifi: ath12k: Reserve space for a string terminator

Rameshkumar Sundaram rameshkumar.sundaram at oss.qualcomm.com
Mon Sep 28 10:36:06 PDT 2026


On 9/26/2026 5:42 PM, Jiale Yao wrote:
> ath12k_write_htt_stats_type() accepts count == size, which fills the
> zero-initialized buffer without a terminating NUL. sscanf() then reads
> beyond the buffer.
> 
> Reject input that leaves no room for the trailing NUL.
> 
> Fixes: 8c7a5031a6b0 ("wifi: ath12k: Fix buffer overflow in debugfs")
> Signed-off-by: Jiale Yao <yaojiale02 at 163.com>
> ---
>   drivers/net/wireless/ath/ath12k/debugfs_htt_stats.c | 2 +-
>   1 file changed, 1 insertion(+), 1 deletion(-)
> 
> diff --git a/drivers/net/wireless/ath/ath12k/debugfs_htt_stats.c b/drivers/net/wireless/ath/ath12k/debugfs_htt_stats.c
> index b772181a496e..f84f1828275a 100644
> --- a/drivers/net/wireless/ath/ath12k/debugfs_htt_stats.c
> +++ b/drivers/net/wireless/ath/ath12k/debugfs_htt_stats.c
> @@ -6190,7 +6190,7 @@ static ssize_t ath12k_write_htt_stats_type(struct file *file,
>   	const int size = 32;
>   	int num_args;
>   
> -	if (count > size)
> +	if (count >= size)
>   		return -EINVAL;
>   
>   	char *buf __free(kfree) = kzalloc(size, GFP_KERNEL);


Reviewed-by: Rameshkumar Sundaram <rameshkumar.sundaram at oss.qualcomm.com>



More information about the ath12k mailing list