Re: [PATCH v3 0/3] wifi: carl9170: firmware trust boundary hardening

From: Jeff Johnson

Date: Mon Jul 13 2026 - 10:27:01 EST



On Tue, 21 Apr 2026 13:49:25 +0000, Tristan Madani wrote:
> From: Tristan Madani <tristan@xxxxxxxxxxxxxxxxxxx>
>
> This series adds missing bounds checks for firmware-controlled fields
> in the carl9170 USB driver.
>
> Patch 1 bounds the cmd callback memcpy to prevent heap overflow from
> an oversized firmware response. Patch 2 fixes an off-by-two in the TX
> status handler. Patch 3 caps the failover copy to rx_failover_missing
> bytes, using min_t per Christian Lamparter.
>
> [...]

Applied, thanks!

[1/3] wifi: carl9170: bound memcpy length in cmd callback to prevent OOB read
commit: 4cde55b2feff9504d1f993ab80e84e7ccb62791c
[2/3] wifi: carl9170: fix OOB read from off-by-two in TX status handler
commit: a3f42f1049ad80c65560d2b078ad426c3134f78d
[3/3] wifi: carl9170: fix buffer overflow in rx_stream failover path
commit: a1a21995c2e1cc2ca6b2226cfe4f5f018370182a

Best regards,
--
Jeff Johnson <jeff.johnson@xxxxxxxxxxxxxxxx>