]> Gentwo Git Trees - linux/.git/commit
usb: storage: sddr55: Reject out-of-bound new_pba
authorTianchu Chen <flynnnchen@tencent.com>
Sun, 16 Nov 2025 04:46:18 +0000 (12:46 +0800)
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Fri, 21 Nov 2025 14:15:24 +0000 (15:15 +0100)
commitb59d4fda7e7d0aff1043a7f742487cb829f5aac1
treef6db7be6b5a394ecc9885a5441d66f92cdaa59d5
parent2e558d86e0975fdfb048bd600e253993edc068fe
usb: storage: sddr55: Reject out-of-bound new_pba

Discovered by Atuin - Automated Vulnerability Discovery Engine.

new_pba comes from the status packet returned after each write.
A bogus device could report values beyond the block count derived
from info->capacity, letting the driver walk off the end of
pba_to_lba[] and corrupt heap memory.

Reject PBAs that exceed the computed block count and fail the
transfer so we avoid touching out-of-range mapping entries.

Signed-off-by: Tianchu Chen <flynnnchen@tencent.com>
Cc: stable <stable@kernel.org>
Link: https://patch.msgid.link/B2DC73A3EE1E3A1D+202511161322001664687@tencent.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
drivers/usb/storage/sddr55.c