Re: [PATCH v2] iio: proximity: hx9023s: validate firmware size

From: Jonathan Cameron

Date: Fri Jul 10 2026 - 16:24:49 EST


On Fri, 10 Jul 2026 21:13:42 +0545
Laxman Acharya Padhya <acharyalaxman8848@xxxxxxxxx> wrote:

> hx9023s_send_cfg() copies the firmware into a counted flexible array and
> then reads fixed offsets from the copied data before walking register/value
> pairs starting at FW_DATA_OFFSET. A truncated firmware image can therefore
> make the driver read past the copied buffer during probe-time configuration
> loading.
>
> Reject firmware images that cannot contain the fixed header, reject images
> too large for the u16 fw_size field, and validate that the advertised
> register count fits in the remaining payload.
>
> Fixes: e9ed97be4fcc ("iio: proximity: hx9023s: Added firmware file parsing functionality")
> Cc: stable@xxxxxxxxxxxxxxx
> Reviewed-by: Joshua Crofts <joshua.crofts1@xxxxxxxxx>
> Signed-off-by: Laxman Acharya Padhya <acharyalaxman8848@xxxxxxxxx>
A few minor comments.

Thanks,

Jonathan

> ---
> drivers/iio/proximity/hx9023s.c | 10 ++++++++--
> 1 file changed, 8 insertions(+), 2 deletions(-)
>
> diff --git a/drivers/iio/proximity/hx9023s.c b/drivers/iio/proximity/hx9023s.c
> index a6ff7cbe9e6..9d91ce681ac 100644
> --- a/drivers/iio/proximity/hx9023s.c
> +++ b/drivers/iio/proximity/hx9023s.c
> @@ -18,6 +18,7 @@
> #include <linux/i2c.h>
> #include <linux/interrupt.h>
> #include <linux/irqreturn.h>
> +#include <linux/limits.h>
> #include <linux/math64.h>
> #include <linux/module.h>
> #include <linux/mutex.h>
> @@ -1031,8 +1032,11 @@ static int hx9023s_bin_load(struct hx9023s_data *data, struct hx9023s_bin *bin)
>
> static int hx9023s_send_cfg(const struct firmware *fw, struct hx9023s_data *data)
> {
> + if (fw->size < FW_DATA_OFFSET || fw->size > U16_MAX)

Add a comment on why you've picked that upper limit.

> + return -EINVAL;
> +
> struct hx9023s_bin *bin __free(kfree) =
> - kzalloc(fw->size + sizeof(*bin), GFP_KERNEL);
> + kzalloc(sizeof(*bin) + fw->size, GFP_KERNEL);

This doesn't belong in the fix given it is just a reorder. Maybe it makes sense
but if it does, separate patch with an explanation of why.

> if (!bin)
> return -ENOMEM;
>
> @@ -1041,7 +1045,8 @@ static int hx9023s_send_cfg(const struct firmware *fw, struct hx9023s_data *data
> bin->fw_ver = bin->data[FW_VER_OFFSET];
> bin->reg_count = get_unaligned_le16(bin->data + FW_REG_CNT_OFFSET);
>
> - release_firmware(fw);
> + if (bin->reg_count > (bin->fw_size - FW_DATA_OFFSET) / 2)
> + return -EINVAL;
>
> return hx9023s_bin_load(data, bin);
> }
> @@ -1058,6 +1063,7 @@ static void hx9023s_cfg_update(const struct firmware *fw, void *context)
> }
>
> ret = hx9023s_send_cfg(fw, data);
> + release_firmware(fw);
> if (ret) {
> dev_warn(dev, "Firmware update failed: %d\n", ret);
> goto no_fw;