Re: [PATCH v2 1/6] scsi: ufs: core: Validate string descriptors

From: Peter Wang (王信友)

Date: Mon Jul 20 2026 - 05:20:52 EST


On Fri, 2026-07-17 at 23:39 +0800, Li Qiang wrote:
> The string descriptor length includes a two-byte header while the
> UTF-16 payload starts after it. utf16s_to_utf8s() expects a count
> of UTF-16 code units, not bytes. Passing the payload byte count can
> make it read beyond the descriptor buffer.
>
> Validate that the payload has an even byte count, pass a code-unit
> count to the converter, and allocate sufficient UTF-8 output space.
>
> The raw string buffer starts after the descriptor header but its size
> is bLength. Copying bLength bytes from that pointer can read beyond
> the response buffer.
>
> Allocate a zeroed bLength-sized buffer and copy only the UTF-16
> payload. This preserves the raw buffer size consumed by the RPMB
> device-ID ABI while avoiding the overread.
>
> Fixes: 4b828fe156a6 ("scsi: ufs: revamp string descriptor reading")
> Fixes: d794b499f948 ("scsi: ufs: core: fix incorrect buffer
> duplication in ufshcd_read_string_desc()")
> Signed-off-by: Li Qiang <liqiang01@xxxxxxxxxx>
> ---

Reviewed-by: Peter Wang <peter.wang@xxxxxxxxxxxx>