From 7bb15a69f7db556fdcf697d59cf81270e08e5b2c Mon Sep 17 00:00:00 2001 From: morris Date: Tue, 30 Jun 2026 17:24:54 +0800 Subject: [PATCH] fix(sdspi): reject oversized pre-read data before block receive Guard start_command_read_blocks against cards that place TOKEN_BLOCK_START so early that extra_data_size exceeds the bytes expected on the current iteration. Without this check, the unsigned subtraction for will_receive underflows and propagates into memset, SPI transaction length, and memcpy counts against the fixed 516-byte block buffer. --- components/esp_driver_sdspi/src/sdspi_host.c | 7 ++++++- 1 file changed, 6 insertions(+), 1 deletion(-) diff --git a/components/esp_driver_sdspi/src/sdspi_host.c b/components/esp_driver_sdspi/src/sdspi_host.c index 99c2a0b5b5e..9ef4955bd71 100644 --- a/components/esp_driver_sdspi/src/sdspi_host.c +++ b/components/esp_driver_sdspi/src/sdspi_host.c @@ -810,7 +810,12 @@ static esp_err_t start_command_read_blocks(slot_info_t *slot, sdspi_hw_cmd_t *cm } // Arrange RX buffer - size_t will_receive = MIN(rx_length, SDSPI_MAX_DATA_LEN) - extra_data_size; + size_t expected_data_size = MIN(rx_length, SDSPI_MAX_DATA_LEN); + if (extra_data_size > expected_data_size) { + ESP_LOGD(TAG, "%s: invalid extra data size %u (expected <= %u)", __func__, (unsigned)extra_data_size, (unsigned)expected_data_size); + return ESP_ERR_INVALID_RESPONSE; + } + size_t will_receive = expected_data_size - extra_data_size; uint8_t* rx_data; ret = get_block_buf(slot, &rx_data); if (ret != ESP_OK) {