diff options
| author | Linmao Li <lilinmao@kylinos.cn> | 2026-07-31 10:59:52 +0800 |
|---|---|---|
| committer | Greg Kroah-Hartman <gregkh@linuxfoundation.org> | 2026-07-31 14:27:46 +0200 |
| commit | 220190f97da558e67cd01c62f1b84fe77b267a5a (patch) | |
| tree | 1e5a018581aa9979170ae32f01e2e5d3539b405d | |
| parent | 9bcb5dbf0d0284c982613ebce7d2fda726159589 (diff) | |
| download | linux-next-220190f97da558e67cd01c62f1b84fe77b267a5a.tar.gz linux-next-220190f97da558e67cd01c62f1b84fe77b267a5a.zip | |
misc: issei: check bus message length before reading the command
__issei_ham_process_ham_rsp() dispatches on hdr->cmd before the message
length is validated. The length comes from the firmware-owned DMA header
read in issei_dma_read(), which only bounds it from above, so firmware
sending a short bus message reaches the dispatch with less than
sizeof(struct ham_bus_message) bytes available.
For a zero-length message kmemdup() returns ZERO_SIZE_PTR, which passes
the NULL check in issei_dma_read(), and the dispatch dereferences it. A
length of one to three bytes gives a slab out-of-bounds read instead.
Reject bus messages shorter than the header before touching it, the way
the individual response handlers already validate their own length.
Fixes: 7bd4b9991db20 ("issei: implement main thread and ham messages")
Signed-off-by: Linmao Li <lilinmao@kylinos.cn>
Link: https://patch.msgid.link/20260731025952.3505287-1-lilinmao@kylinos.cn
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
| -rw-r--r-- | drivers/misc/issei/ham.c | 6 |
1 files changed, 6 insertions, 0 deletions
diff --git a/drivers/misc/issei/ham.c b/drivers/misc/issei/ham.c index 17eae91f077d..674d9733d16c 100644 --- a/drivers/misc/issei/ham.c +++ b/drivers/misc/issei/ham.c @@ -132,6 +132,12 @@ static int __issei_ham_process_ham_rsp(struct issei_device *idev, const u8 *buf, { struct ham_bus_message *hdr = (struct ham_bus_message *)buf; + if (length < sizeof(*hdr)) { + dev_err(&idev->dev, "Small bus message size %zu < %zu\n", + length, sizeof(*hdr)); + return -EPROTO; + } + switch (hdr->cmd) { case HAM_BUS_CMD_START_RSP: return issei_ham_start_rsp(idev, buf, length); |
