Re: [PATCH] w1: ds28e17: reject an oversize length on an I2C block read
From: Krzysztof Kozlowski
Date: Fri Jul 03 2026 - 05:52:33 EST
On Mon, 29 Jun 2026 20:10:43 +0800, Maoyi Xie wrote:
> w1_f19_i2c_master_transfer() is the master_xfer for the DS28E17 1-Wire
> to I2C bridge. On an I2C_M_RECV_LEN read, it takes the length from the
> device. The downstream slave puts a length byte in buf[0]. The driver
> then reads that many bytes into buf[1] with w1_f19_i2c_read().
>
> buf[0] is controlled by the device and can be 0 to 255.
> w1_f19_i2c_read() only rejects a zero count. The caller buffer is
> I2C_SMBUS_BLOCK_MAX + 2, so 34 bytes. A length above 32 makes the read
> run past it, up to about 222 bytes out of bounds.
>
> [...]
Applied, thanks!
[1/1] w1: ds28e17: reject an oversize length on an I2C block read
https://git.kernel.org/krzk/linux-w1/c/487eca6535cab91944ade06a155e9d789591a1e5
Best regards,
--
Krzysztof Kozlowski <krzk@xxxxxxxxxx>