This is an automated email from the ASF dual-hosted git repository.

acassis pushed a commit to branch releases/13.1
in repository https://gitbox.apache.org/repos/asf/nuttx.git

commit 8e9e01cb6e031a2d34a3f2e55e0c26211918852c
Author: yushuailong <[email protected]>
AuthorDate: Mon Sep 21 20:20:30 2026 +0800

    sched/irq: Fix a line buffer overread in /proc/irqs.
    
    irq_callback() passed snprintf()'s would-have-written length to
    procfs_memcpy(). If an IRQ line exceeded IRQ_LINELEN, the copy could read
    beyond the formatting buffer.
    
    Use procfs_snprintf() so the copy is limited to the bytes actually written.
    
    Assisted-by: OpenAI Codex
    Signed-off-by: yushuailong <[email protected]>
---
 sched/irq/irq_procfs.c | 12 ++++++------
 1 file changed, 6 insertions(+), 6 deletions(-)

diff --git a/sched/irq/irq_procfs.c b/sched/irq/irq_procfs.c
index 89a5b03893a..e5d6ae06f09 100644
--- a/sched/irq/irq_procfs.c
+++ b/sched/irq/irq_procfs.c
@@ -231,12 +231,12 @@ static int irq_callback(int irq, FAR struct irq_info_s 
*info,
 
   /* Output information about this interrupt */
 
-  linesize = snprintf(irqfile->line, IRQ_LINELEN, IRQ_FMT,
-                      (unsigned int)irq,
-                      (unsigned long)((uintptr_t)copy.handler),
-                      (unsigned long)((uintptr_t)copy.arg),
-                      count, intpart, fracpart,
-                      (unsigned long)delta.tv_nsec / 1000);
+  linesize = procfs_snprintf(irqfile->line, IRQ_LINELEN, IRQ_FMT,
+                             (unsigned int)irq,
+                             (unsigned long)((uintptr_t)copy.handler),
+                             (unsigned long)((uintptr_t)copy.arg),
+                             count, intpart, fracpart,
+                             (unsigned long)delta.tv_nsec / 1000);
 
   copysize  = procfs_memcpy(irqfile->line, linesize, irqfile->buffer,
                             irqfile->remaining, &irqfile->offset);

Reply via email to