Re: [PATCH] thunderbolt: validate DROM entry lengths
From: Mika Westerberg
Date: Mon Jul 27 2026 - 07:38:36 EST
On Mon, Jul 06, 2026 at 05:15:32PM +0800, Pengpeng Hou wrote:
> From: Pengpeng <pengpeng@xxxxxxxxxxx>
>
> tb_drom_parse_entries() checks that a DROM entry does not run past the
> end of the DROM, but it did not require the declared entry length to
> cover the entry header itself.
>
> Require each entry to contain its two-byte header before dispatching to
> the type-specific DROM entry parsers.
>
> Signed-off-by: Pengpeng <pengpeng@xxxxxxxxxxx>
Can you add your full name to the From and SoB?
> ---
> drivers/thunderbolt/eeprom.c | 12 +++++++++---
> 1 file changed, 9 insertions(+), 3 deletions(-)
>
> diff --git a/drivers/thunderbolt/eeprom.c b/drivers/thunderbolt/eeprom.c
> index 5681c17f82ec..270bb34aff42 100644
> --- a/drivers/thunderbolt/eeprom.c
> +++ b/drivers/thunderbolt/eeprom.c
> @@ -414,9 +414,15 @@ static int tb_drom_parse_entries(struct tb_switch *sw, size_t header_size)
> int res;
>
> while (pos < drom_size) {
> - struct tb_drom_entry_header *entry = (void *) (sw->drom + pos);
> - if (pos + 1 == drom_size || pos + entry->len > drom_size
> - || !entry->len) {
> + struct tb_drom_entry_header *entry;
> +
> + if (drom_size - pos < sizeof(*entry)) {
> + tb_sw_warn(sw, "DROM buffer overrun\n");
> + return -EIO;
> + }
> +
> + entry = (void *)(sw->drom + pos);
> + if (entry->len < sizeof(*entry) || entry->len > drom_size - pos) {
> tb_sw_warn(sw, "DROM buffer overrun\n");
> return -EIO;
> }
> --
> 2.43.0