Skip to content

Commit f9118e5

Browse files
committed
scsi: lpfc: Use memcpy() for BIOS version
jira VULN-72456 jira VULN-72455 cve CVE-2025-38332 commit-author Daniel Wagner <wagi@kernel.org> commit ae82eaf The strlcat() with FORTIFY support is triggering a panic because it thinks the target buffer will overflow although the correct target buffer size is passed in. Anyway, instead of memset() with 0 followed by a strlcat(), just use memcpy() and ensure that the resulting buffer is NULL terminated. BIOSVersion is only used for the lpfc_printf_log() which expects a properly terminated string. Signed-off-by: Daniel Wagner <wagi@kernel.org> Link: https://lore.kernel.org/r/20250409-fix-lpfc-bios-str-v1-1-05dac9e51e13@kernel.org Reviewed-by: Justin Tee <justin.tee@broadcom.com> Signed-off-by: Martin K. Petersen <martin.petersen@oracle.com> (cherry picked from commit ae82eaf) Signed-off-by: Jonathan Maple <jmaple@ciq.com>
1 parent d70efbf commit f9118e5

File tree

1 file changed

+2
-2
lines changed

1 file changed

+2
-2
lines changed

drivers/scsi/lpfc/lpfc_sli.c

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -5970,9 +5970,9 @@ lpfc_sli4_get_ctl_attr(struct lpfc_hba *phba)
59705970
phba->sli4_hba.flash_id = bf_get(lpfc_cntl_attr_flash_id, cntl_attr);
59715971
phba->sli4_hba.asic_rev = bf_get(lpfc_cntl_attr_asic_rev, cntl_attr);
59725972

5973-
memset(phba->BIOSVersion, 0, sizeof(phba->BIOSVersion));
5974-
strlcat(phba->BIOSVersion, (char *)cntl_attr->bios_ver_str,
5973+
memcpy(phba->BIOSVersion, cntl_attr->bios_ver_str,
59755974
sizeof(phba->BIOSVersion));
5975+
phba->BIOSVersion[sizeof(phba->BIOSVersion) - 1] = '\0';
59765976

59775977
lpfc_printf_log(phba, KERN_INFO, LOG_SLI,
59785978
"3086 lnk_type:%d, lnk_numb:%d, bios_ver:%s, "

0 commit comments

Comments
 (0)