usb: host: xhci: use snprintf() in xhci_decode_trb()
authorSergey Shtylyov <s.shtylyov@omp.ru>
Thu, 30 Jun 2022 12:46:45 +0000 (15:46 +0300)
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Wed, 17 Aug 2022 12:23:46 +0000 (14:23 +0200)
[ Upstream commit 1ce69c35b86038dd11d3a6115a04501c5b89a940 ]

Commit cbf286e8ef83 ("xhci: fix unsafe memory usage in xhci tracing")
apparently missed one sprintf() call in xhci_decode_trb() -- replace
it with the snprintf() call as well...

Found by Linux Verification Center (linuxtesting.org) with the SVACE static
analysis tool.

Fixes: cbf286e8ef83 ("xhci: fix unsafe memory usage in xhci tracing")
Signed-off-by: Sergey Shtylyov <s.shtylyov@omp.ru>
Signed-off-by: Mathias Nyman <mathias.nyman@linux.intel.com>
Link: https://lore.kernel.org/r/20220630124645.1805902-2-mathias.nyman@linux.intel.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
drivers/usb/host/xhci.h

index 79fa34f..101f195 100644 (file)
@@ -2395,7 +2395,7 @@ static inline const char *xhci_decode_trb(char *str, size_t size,
                        field3 & TRB_CYCLE ? 'C' : 'c');
                break;
        case TRB_STOP_RING:
-               sprintf(str,
+               snprintf(str, size,
                        "%s: slot %d sp %d ep %d flags %c",
                        xhci_trb_type_string(type),
                        TRB_TO_SLOT_ID(field3),