Re: [PATCH v2] wifi: brcmfmac: bound NVRAM comment parsing
From: Arend van Spriel
Date: Sun Oct 04 2026 - 05:46:21 EST
On Sun, 20 Sep 2026 11:44:14 +0800, Pengpeng Hou wrote:
> The NVRAM comment handler searches for a newline with strchr() even
> though its input is a firmware buffer with an explicit length. A comment
> at the end of an unterminated buffer can make the search read past that
> input.
>
> Keep the input extent in the parser and use bounded searches for newline
> and NUL. Preserve the full input length: the capped size used to
> allocate the output is not a bound on the input, which may contain more
> than 64KiB of comments. Leave the outer parsing limit unchanged.
>
> The issue was found by our static-analysis tool.
>
> Fixes: 3e99b08ab53c ("brcmfmac: enhance nvram processing")
> Cc: stable@xxxxxxxxxxxxxxx
> Assisted-by: gpt 5
Acked-by: Arend van Spriel <arend.vanspriel@xxxxxxxxxxxx>
> Signed-off-by: Pengpeng Hou <hppiscas@xxxxxxx>
> ---
> .../broadcom/brcm80211/brcmfmac/firmware.c | 13 +++++++++----
> 1 file changed, 9 insertions(+), 4 deletions(-)