get:
Show a patch.

patch:
Update a patch.

put:
Update a patch.

GET /api/1.2/patches/2223500/?format=api
HTTP 200 OK
Allow: GET, PUT, PATCH, HEAD, OPTIONS
Content-Type: application/json
Vary: Accept

{
    "id": 2223500,
    "url": "http://patchwork.ozlabs.org/api/1.2/patches/2223500/?format=api",
    "web_url": "http://patchwork.ozlabs.org/project/linux-i2c/patch/20260415114752.1181079-1-bsevens@google.com/",
    "project": {
        "id": 35,
        "url": "http://patchwork.ozlabs.org/api/1.2/projects/35/?format=api",
        "name": "Linux I2C development",
        "link_name": "linux-i2c",
        "list_id": "linux-i2c.vger.kernel.org",
        "list_email": "linux-i2c@vger.kernel.org",
        "web_url": "",
        "scm_url": "",
        "webscm_url": "",
        "list_archive_url": "",
        "list_archive_url_format": "",
        "commit_url_format": ""
    },
    "msgid": "<20260415114752.1181079-1-bsevens@google.com>",
    "list_archive_url": null,
    "date": "2026-04-15T11:47:51",
    "name": "HID: mcp2221: Fix heap buffer overflow in mcp2221_raw_event()",
    "commit_ref": null,
    "pull_url": null,
    "state": "new",
    "archived": false,
    "hash": "6b2a19a5b2177e7265e906795b41b8f0c557c5c2",
    "submitter": {
        "id": 93160,
        "url": "http://patchwork.ozlabs.org/api/1.2/people/93160/?format=api",
        "name": "Benoit Sevens",
        "email": "bsevens@google.com"
    },
    "delegate": null,
    "mbox": "http://patchwork.ozlabs.org/project/linux-i2c/patch/20260415114752.1181079-1-bsevens@google.com/mbox/",
    "series": [
        {
            "id": 499982,
            "url": "http://patchwork.ozlabs.org/api/1.2/series/499982/?format=api",
            "web_url": "http://patchwork.ozlabs.org/project/linux-i2c/list/?series=499982",
            "date": "2026-04-15T11:47:51",
            "name": "HID: mcp2221: Fix heap buffer overflow in mcp2221_raw_event()",
            "version": 1,
            "mbox": "http://patchwork.ozlabs.org/series/499982/mbox/"
        }
    ],
    "comments": "http://patchwork.ozlabs.org/api/patches/2223500/comments/",
    "check": "pending",
    "checks": "http://patchwork.ozlabs.org/api/patches/2223500/checks/",
    "tags": {},
    "related": [],
    "headers": {
        "Return-Path": "\n <linux-i2c+bounces-17065-incoming=patchwork.ozlabs.org@vger.kernel.org>",
        "X-Original-To": [
            "incoming@patchwork.ozlabs.org",
            "linux-i2c@vger.kernel.org"
        ],
        "Delivered-To": "patchwork-incoming@legolas.ozlabs.org",
        "Authentication-Results": [
            "legolas.ozlabs.org;\n\tdkim=pass (2048-bit key;\n unprotected) header.d=google.com header.i=@google.com header.a=rsa-sha256\n header.s=20251104 header.b=pzzQ0EgW;\n\tdkim-atps=neutral",
            "legolas.ozlabs.org;\n spf=pass (sender SPF authorized) smtp.mailfrom=vger.kernel.org\n (client-ip=2600:3c0a:e001:db::12fc:5321; helo=sea.lore.kernel.org;\n envelope-from=linux-i2c+bounces-17065-incoming=patchwork.ozlabs.org@vger.kernel.org;\n receiver=patchwork.ozlabs.org)",
            "smtp.subspace.kernel.org;\n\tdkim=pass (2048-bit key) header.d=google.com header.i=@google.com\n header.b=\"pzzQ0EgW\"",
            "smtp.subspace.kernel.org;\n arc=none smtp.client-ip=209.85.128.73",
            "smtp.subspace.kernel.org;\n dmarc=pass (p=reject dis=none) header.from=google.com",
            "smtp.subspace.kernel.org;\n spf=pass smtp.mailfrom=flex--bsevens.bounces.google.com"
        ],
        "Received": [
            "from sea.lore.kernel.org (sea.lore.kernel.org\n [IPv6:2600:3c0a:e001:db::12fc:5321])\n\t(using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)\n\t key-exchange x25519 server-signature ECDSA (secp384r1) server-digest SHA384)\n\t(No client certificate requested)\n\tby legolas.ozlabs.org (Postfix) with ESMTPS id 4fwfZH1Hm9z1yDF\n\tfor <incoming@patchwork.ozlabs.org>; Wed, 15 Apr 2026 21:49:27 +1000 (AEST)",
            "from smtp.subspace.kernel.org (conduit.subspace.kernel.org\n [100.90.174.1])\n\tby sea.lore.kernel.org (Postfix) with ESMTP id C8DC73092F68\n\tfor <incoming@patchwork.ozlabs.org>; Wed, 15 Apr 2026 11:48:06 +0000 (UTC)",
            "from localhost.localdomain (localhost.localdomain [127.0.0.1])\n\tby smtp.subspace.kernel.org (Postfix) with ESMTP id 1EDCE37CD47;\n\tWed, 15 Apr 2026 11:48:06 +0000 (UTC)",
            "from mail-wm1-f73.google.com (mail-wm1-f73.google.com\n [209.85.128.73])\n\t(using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits))\n\t(No client certificate requested)\n\tby smtp.subspace.kernel.org (Postfix) with ESMTPS id 6D49237A488\n\tfor <linux-i2c@vger.kernel.org>; Wed, 15 Apr 2026 11:48:03 +0000 (UTC)",
            "by mail-wm1-f73.google.com with SMTP id\n 5b1f17b1804b1-488bd1ee9e7so40660005e9.1\n        for <linux-i2c@vger.kernel.org>; Wed, 15 Apr 2026 04:48:03 -0700 (PDT)"
        ],
        "ARC-Seal": "i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116;\n\tt=1776253685; cv=none;\n b=T/rD6LuLviYoLeEwdlVTDLTlixHYZErbKJ0vDRvHpmgIm8y36fd8BNJe9oyf9f3BwCUBkyoaC98VgAOl/RDsX3SZUHrwgU/y2+D/6fKwphQVZp6vKPcrJKRpzb2g1NV1wJS8MGdrYRK3vG70/NxJXVlbNRKDzd3RfAPX26OAxqA=",
        "ARC-Message-Signature": "i=1; a=rsa-sha256; d=subspace.kernel.org;\n\ts=arc-20240116; t=1776253685; c=relaxed/simple;\n\tbh=wYBYWS0U3wn+JrPKpLtSjLr8wl2VYLOC3vTu/H5RgJ0=;\n\th=Date:Mime-Version:Message-ID:Subject:From:To:Cc:Content-Type;\n b=jVVh5b1h7aIxZAxKW3F54LDb/ULKLGnj3+ZcC7kDcn4j7Kg30LU6caqZ4TxHfiMC3gBB6sgikgO75bDhHhXKjfjGAjuhgFNECnEOxQ2jV5DnTeFoGl9fayGXf67umIR7YfwhxWLgGUa63/03AFrcymsSNETJ7D9gaQVMus+Cjlg=",
        "ARC-Authentication-Results": "i=1; smtp.subspace.kernel.org;\n dmarc=pass (p=reject dis=none) header.from=google.com;\n spf=pass smtp.mailfrom=flex--bsevens.bounces.google.com;\n dkim=pass (2048-bit key) header.d=google.com header.i=@google.com\n header.b=pzzQ0EgW; arc=none smtp.client-ip=209.85.128.73",
        "DKIM-Signature": "v=1; a=rsa-sha256; c=relaxed/relaxed;\n        d=google.com; s=20251104; t=1776253682; x=1776858482;\n darn=vger.kernel.org;\n        h=content-transfer-encoding:cc:to:from:subject:message-id\n         :mime-version:date:from:to:cc:subject:date:message-id:reply-to;\n        bh=lP3RjDHSPzb1NPTjUWSB2m8qqv8z9lgjkWSUnxmWGgM=;\n        b=pzzQ0EgWxtT2kR2LjQW2dsV2LoCAh+7SLcufSfzCtuhYqvGqVCwLQIQGjnjL6YvCeZ\n         HDMCKrvnK2RjLCI4m0X6OqSIFM0G/Ugv8JQHmR3ZOcz3ScEJ75h1I+lYsPWLlc2tbMip\n         MxXKEzEma/hZml6vSi8q6P650WssvpSV8FWlagxMX6w2y+/Ae5UYMN6NJ2uLscXxXh6w\n         LuqisoL0EuoU27iv59Vsoh86//jZKZEcWV2h9F28i3VKDiPfSxhvk+Zs9qzmLCRugtvh\n         IZoPoT/iR9BProX8ytShB8mbKWBAbQSKKTjQWvenWtJ0SjFcvl5IZD94aOFf1F+pg2sW\n         koaQ==",
        "X-Google-DKIM-Signature": "v=1; a=rsa-sha256; c=relaxed/relaxed;\n        d=1e100.net; s=20251104; t=1776253682; x=1776858482;\n        h=content-transfer-encoding:cc:to:from:subject:message-id\n         :mime-version:date:x-gm-message-state:from:to:cc:subject:date\n         :message-id:reply-to;\n        bh=lP3RjDHSPzb1NPTjUWSB2m8qqv8z9lgjkWSUnxmWGgM=;\n        b=UZdW2kIq9ImyKuydi18t7GTYbRFZQvNIWb72BPKm7VYsRL9gahcuI8szdTx/MqHvwm\n         jEUf8lieABSPs9gV4+0vqd4ri1Ge3jUMkdDGDPi1W9A6E5j6Ahr2IP7jWwBaOUqscVKN\n         +5tmPRnLMw76971+vWm/pmYGbnJqH+LsURFoFrZ13Cg2vDsAur+zAZ3qxpbDcZQtnm1q\n         nPTi/vxvoY4Q75blgf7ngOopw0S2h5ac7Mm4OEstOkt7kAB/rj1DJ6Wo6OuMVopdY08+\n         zlZSJgrNveAcYx2Lmf5gy+oH+KsXPax7KtCfq0/8OqbOyQzb8+gnHil0DoOZpZvOjT9i\n         DqbQ==",
        "X-Gm-Message-State": "AOJu0YzBP81lD8biV80UEWHT1HNsU2xDJ2zR7SjlZX/5dnw6fVckaU8Y\n\tXz8pq8DyV8NQcMcGhrpp5+Hp2PavOYxgoTMB4N3jwNaMr6BqS/FIutsAtPe/LDgpPEtjFLr+lHe\n\tQUzzxmJOmsA==",
        "X-Received": "from wmpz8.prod.google.com ([2002:a05:600c:a08:b0:485:3a2f:2f7e])\n (user=bsevens job=prod-delivery.src-stubby-dispatcher) by\n 2002:a05:600c:3acf:b0:485:35a4:939f\n with SMTP id 5b1f17b1804b1-488d68a8275mr254811245e9.28.1776253681593; Wed, 15\n Apr 2026 04:48:01 -0700 (PDT)",
        "Date": "Wed, 15 Apr 2026 11:47:51 +0000",
        "Precedence": "bulk",
        "X-Mailing-List": "linux-i2c@vger.kernel.org",
        "List-Id": "<linux-i2c.vger.kernel.org>",
        "List-Subscribe": "<mailto:linux-i2c+subscribe@vger.kernel.org>",
        "List-Unsubscribe": "<mailto:linux-i2c+unsubscribe@vger.kernel.org>",
        "Mime-Version": "1.0",
        "X-Mailer": "git-send-email 2.54.0.rc0.605.g598a273b03-goog",
        "Message-ID": "<20260415114752.1181079-1-bsevens@google.com>",
        "Subject": "[PATCH] HID: mcp2221: Fix heap buffer overflow in mcp2221_raw_event()",
        "From": "Benoit Sevens <bsevens@google.com>",
        "To": "Rishi Gupta <gupt21@gmail.com>, Jiri Kosina <jikos@kernel.org>,\n\tBenjamin Tissoires <bentiss@kernel.org>",
        "Cc": "linux-i2c@vger.kernel.org, linux-input@vger.kernel.org,\n  linux-kernel@vger.kernel.org,\n  \" =?utf-8?q?Beno=C3=AEt_Sevens?= \" <bsevens@google.com>",
        "Content-Type": "text/plain; charset=\"UTF-8\"",
        "Content-Transfer-Encoding": "quoted-printable"
    },
    "content": "From: Benoît Sevens <bsevens@google.com>\n\nA heap buffer overflow can occur in the mcp2221_raw_event() function\nwhen handling I2C read responses. The driver failed to check if the\ntotal incoming data length fits within the originally allocated buffer\n`mcp->rxbuf`.\n\nFix this by introducing `rxbuf_len` to `struct mcp2221` to keep track\nof the allocated buffer size. Initialize it in `mcp_i2c_smbus_read()`\nand `mcp_smbus_xfer()`, and ensure the copied data length combined with\nthe current index does not exceed this length in `mcp2221_raw_event()`.\n\nSigned-off-by: Benoît Sevens <bsevens@google.com>\n---\n drivers/hid/hid-mcp2221.c | 9 ++++++++-\n 1 file changed, 8 insertions(+), 1 deletion(-)",
    "diff": "diff --git a/drivers/hid/hid-mcp2221.c b/drivers/hid/hid-mcp2221.c\nindex ef3b5c77c38e..744561e65079 100644\n--- a/drivers/hid/hid-mcp2221.c\n+++ b/drivers/hid/hid-mcp2221.c\n@@ -119,6 +119,7 @@ struct mcp2221 {\n \tstruct completion wait_in_report;\n \tstruct delayed_work init_work;\n \tu8 *rxbuf;\n+\tint rxbuf_len;\n \tu8 txbuf[64];\n \tint rxbuf_idx;\n \tint status;\n@@ -323,12 +324,14 @@ static int mcp_i2c_smbus_read(struct mcp2221 *mcp,\n \t\tmcp->txbuf[3] = (u8)(msg->addr << 1);\n \t\ttotal_len = msg->len;\n \t\tmcp->rxbuf = msg->buf;\n+\t\tmcp->rxbuf_len = msg->len;\n \t} else {\n \t\tmcp->txbuf[1] = smbus_len;\n \t\tmcp->txbuf[2] = 0;\n \t\tmcp->txbuf[3] = (u8)(smbus_addr << 1);\n \t\ttotal_len = smbus_len;\n \t\tmcp->rxbuf = smbus_buf;\n+\t\tmcp->rxbuf_len = smbus_len;\n \t}\n \n \tret = mcp_send_data_req_status(mcp, mcp->txbuf, 4);\n@@ -538,6 +541,7 @@ static int mcp_smbus_xfer(struct i2c_adapter *adapter, u16 addr,\n \n \t\t\tmcp->rxbuf_idx = 0;\n \t\t\tmcp->rxbuf = data->block;\n+\t\t\tmcp->rxbuf_len = sizeof(data->block);\n \t\t\tmcp->txbuf[0] = MCP2221_I2C_GET_DATA;\n \t\t\tret = mcp_send_data_req_status(mcp, mcp->txbuf, 1);\n \t\t\tif (ret)\n@@ -561,6 +565,7 @@ static int mcp_smbus_xfer(struct i2c_adapter *adapter, u16 addr,\n \n \t\t\tmcp->rxbuf_idx = 0;\n \t\t\tmcp->rxbuf = data->block;\n+\t\t\tmcp->rxbuf_len = sizeof(data->block);\n \t\t\tmcp->txbuf[0] = MCP2221_I2C_GET_DATA;\n \t\t\tret = mcp_send_data_req_status(mcp, mcp->txbuf, 1);\n \t\t\tif (ret)\n@@ -908,7 +913,9 @@ static int mcp2221_raw_event(struct hid_device *hdev,\n \t\t\t}\n \t\t\tif (data[2] == MCP2221_I2C_READ_COMPL ||\n \t\t\t    data[2] == MCP2221_I2C_READ_PARTIAL) {\n-\t\t\t\tif (!mcp->rxbuf || mcp->rxbuf_idx < 0 || data[3] > 60) {\n+\t\t\t\tif (!mcp->rxbuf || mcp->rxbuf_idx < 0 ||\n+\t\t\t\t    data[3] > 60 ||\n+\t\t\t\t    mcp->rxbuf_idx + data[3] > mcp->rxbuf_len) {\n \t\t\t\t\tmcp->status = -EINVAL;\n \t\t\t\t\tbreak;\n \t\t\t\t}\n",
    "prefixes": []
}