[PATCH v2] iio: proximity: hx9023s: validate firmware size

From: Laxman Acharya Padhya

Date: Fri Jul 10 2026 - 11:34:49 EST


hx9023s_send_cfg() copies the firmware into a counted flexible array and
then reads fixed offsets from the copied data before walking register/value
pairs starting at FW_DATA_OFFSET. A truncated firmware image can therefore
make the driver read past the copied buffer during probe-time configuration
loading.

Reject firmware images that cannot contain the fixed header, reject images
too large for the u16 fw_size field, and validate that the advertised
register count fits in the remaining payload.

Fixes: e9ed97be4fcc ("iio: proximity: hx9023s: Added firmware file parsing functionality")
Cc: stable@xxxxxxxxxxxxxxx
Reviewed-by: Joshua Crofts <joshua.crofts1@xxxxxxxxx>
Signed-off-by: Laxman Acharya Padhya <acharyalaxman8848@xxxxxxxxx>
---
drivers/iio/proximity/hx9023s.c | 10 ++++++++--
1 file changed, 8 insertions(+), 2 deletions(-)

diff --git a/drivers/iio/proximity/hx9023s.c b/drivers/iio/proximity/hx9023s.c
index a6ff7cbe9e6..9d91ce681ac 100644
--- a/drivers/iio/proximity/hx9023s.c
+++ b/drivers/iio/proximity/hx9023s.c
@@ -18,6 +18,7 @@
#include <linux/i2c.h>
#include <linux/interrupt.h>
#include <linux/irqreturn.h>
+#include <linux/limits.h>
#include <linux/math64.h>
#include <linux/module.h>
#include <linux/mutex.h>
@@ -1031,8 +1032,11 @@ static int hx9023s_bin_load(struct hx9023s_data *data, struct hx9023s_bin *bin)

static int hx9023s_send_cfg(const struct firmware *fw, struct hx9023s_data *data)
{
+ if (fw->size < FW_DATA_OFFSET || fw->size > U16_MAX)
+ return -EINVAL;
+
struct hx9023s_bin *bin __free(kfree) =
- kzalloc(fw->size + sizeof(*bin), GFP_KERNEL);
+ kzalloc(sizeof(*bin) + fw->size, GFP_KERNEL);
if (!bin)
return -ENOMEM;

@@ -1041,7 +1045,8 @@ static int hx9023s_send_cfg(const struct firmware *fw, struct hx9023s_data *data
bin->fw_ver = bin->data[FW_VER_OFFSET];
bin->reg_count = get_unaligned_le16(bin->data + FW_REG_CNT_OFFSET);

- release_firmware(fw);
+ if (bin->reg_count > (bin->fw_size - FW_DATA_OFFSET) / 2)
+ return -EINVAL;

return hx9023s_bin_load(data, bin);
}
@@ -1058,6 +1063,7 @@ static void hx9023s_cfg_update(const struct firmware *fw, void *context)
}

ret = hx9023s_send_cfg(fw, data);
+ release_firmware(fw);
if (ret) {
dev_warn(dev, "Firmware update failed: %d\n", ret);
goto no_fw;
--
2.51.2