sierra_net_get_fw_attr() only checks usbnet_read_cmd() for negative
return values before converting attrdata and storing it in *datap.
A zero-length or one-byte response leaves attrdata wholly or partially
uninitialized.
Although sierra_net_bind() rejects responses of unexpected length, its
dev_dbg() call uses fwattr before that check. When the debug message is
enabled, the incomplete value may therefore be used in the debug output.
Require the return value to equal sizeof(attrdata) before accessing the
buffer. Return -EIO for short reads, retaining the existing handling of
negative errors and leaving the output parameter untouched on failure.
Found by manual code inspection with LLM assistance. The issue has not
been reproduced at runtime.
Fixes: eb4fd8cd355c ("net/usb: add sierra_net.c driver")
Signed-off-by: Xinsheng Zhu <redacted>
---
drivers/net/usb/sierra_net.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/net/usb/sierra_net.c b/drivers/net/usb/sierra_net.c
index 4d3ed642b3e7..95668a5ccd5f 100644
--- a/drivers/net/usb/sierra_net.c
+++ b/drivers/net/usb/sierra_net.c
@@ -637,7 +637,7 @@ static int sierra_net_get_fw_attr(struct usbnet *dev, u16 *datap)
sizeof(attrdata) /* __u16 size */
);
- if (result < 0)
+ if (result != sizeof(attrdata))
return -EIO;
*datap = le16_to_cpu(attrdata);
base-commit: 8b4e7209c842d8cb9516f1f5ef0a88aa2d8831a6
--
2.54.0 (Apple Git-157)