summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorLinmao Li <lilinmao@kylinos.cn>2026-07-31 10:59:52 +0800
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>2026-07-31 14:27:46 +0200
commit220190f97da558e67cd01c62f1b84fe77b267a5a (patch)
tree1e5a018581aa9979170ae32f01e2e5d3539b405d
parent9bcb5dbf0d0284c982613ebce7d2fda726159589 (diff)
downloadlinux-next-220190f97da558e67cd01c62f1b84fe77b267a5a.tar.gz
linux-next-220190f97da558e67cd01c62f1b84fe77b267a5a.zip
misc: issei: check bus message length before reading the command
__issei_ham_process_ham_rsp() dispatches on hdr->cmd before the message length is validated. The length comes from the firmware-owned DMA header read in issei_dma_read(), which only bounds it from above, so firmware sending a short bus message reaches the dispatch with less than sizeof(struct ham_bus_message) bytes available. For a zero-length message kmemdup() returns ZERO_SIZE_PTR, which passes the NULL check in issei_dma_read(), and the dispatch dereferences it. A length of one to three bytes gives a slab out-of-bounds read instead. Reject bus messages shorter than the header before touching it, the way the individual response handlers already validate their own length. Fixes: 7bd4b9991db20 ("issei: implement main thread and ham messages") Signed-off-by: Linmao Li <lilinmao@kylinos.cn> Link: https://patch.msgid.link/20260731025952.3505287-1-lilinmao@kylinos.cn Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
-rw-r--r--drivers/misc/issei/ham.c6
1 files changed, 6 insertions, 0 deletions
diff --git a/drivers/misc/issei/ham.c b/drivers/misc/issei/ham.c
index 17eae91f077d..674d9733d16c 100644
--- a/drivers/misc/issei/ham.c
+++ b/drivers/misc/issei/ham.c
@@ -132,6 +132,12 @@ static int __issei_ham_process_ham_rsp(struct issei_device *idev, const u8 *buf,
{
struct ham_bus_message *hdr = (struct ham_bus_message *)buf;
+ if (length < sizeof(*hdr)) {
+ dev_err(&idev->dev, "Small bus message size %zu < %zu\n",
+ length, sizeof(*hdr));
+ return -EPROTO;
+ }
+
switch (hdr->cmd) {
case HAM_BUS_CMD_START_RSP:
return issei_ham_start_rsp(idev, buf, length);