Re: [PATCH] mtd: spi-nor: debugfs: fix out-of-bounds read in spi_nor_params_show()
From: Miquel Raynal
Date: Tue Apr 21 2026 - 03:38:58 EST
Hi Tudor,
On 17/04/2026 at 15:24:39 GMT, Tudor Ambarus <tudor.ambarus@xxxxxxxxxx> wrote:
> Sashiko noticed an out-of-bounds read [1].
[...]
> Cc: stable@xxxxxxxxxxxxxxx
> Fixes: 0257be79fc4a ("mtd: spi-nor: expose internal parameters via debugfs")
> Closes: https://sashiko.dev/#/patchset/20260417-die-erase-fix-v2-1-73bb7004ebad%40infineon.com [1]
> Signed-off-by: Tudor Ambarus <tudor.ambarus@xxxxxxxxxx>
> ---
> We shall assign a CVE to this. I'll look into how next week.
They are assigned automatically to every fix, no?
If spi-nor folks want to ack, I might take it through an mtd/fixes PR.
Thanks,
Miquèl