RE: [PATCH v3 2/3] Bluetooth: btintel: bound firmware ID by TLV length
From: K, Kiran
Date: Mon Aug 31 2026 - 07:06:36 EST
Hi Luiz,
>Subject: [PATCH v3 2/3] Bluetooth: btintel: bound firmware ID by TLV length
>
>The firmware ID is treated as a NUL-terminated string even though the TLV
>length is its only boundary. If the value does not contain a NUL terminator,
>snprintf() can read beyond the received response.
>
>Limit the conversion to the advertised TLV value length.
>
>Fixes: 164c62f958f8 ("Bluetooth: btintel: Add firmware ID to firmware name")
>Reviewed-by: Ali Ahmet Memis <ali@xxxxxxxxxxxxxx>
>Signed-off-by: Laxman Acharya Padhya <acharyalaxman8848@xxxxxxxxx>
>---
> drivers/bluetooth/btintel.c | 2 +-
> 1 file changed, 1 insertion(+), 1 deletion(-)
>
>diff --git a/drivers/bluetooth/btintel.c b/drivers/bluetooth/btintel.c index
>998c99b17..887170534 100644
>--- a/drivers/bluetooth/btintel.c
>+++ b/drivers/bluetooth/btintel.c
>@@ -704,7 +704,7 @@ int btintel_parse_version_tlv(struct hci_dev *hdev,
> break;
> case INTEL_TLV_FW_ID:
> snprintf(version->fw_id, sizeof(version->fw_id),
>- "%s", tlv->val);
>+ "%.*s", tlv->len, tlv->val);
> break;
> default:
> /* Ignore rest of information */
>--
>2.51.2
Tested-by: Kiran K <kiran.k@xxxxxxxxx>
Thanks,
Kiran