diff options
| author | Linmao Li <lilinmao@kylinos.cn> | 2026-07-31 10:59:52 +0800 |
|---|---|---|
| committer | Greg Kroah-Hartman <gregkh@linuxfoundation.org> | 2026-07-31 14:27:46 +0200 |
| commit | 220190f97da558e67cd01c62f1b84fe77b267a5a (patch) | |
| tree | 1e5a018581aa9979170ae32f01e2e5d3539b405d /tools/perf/scripts/python/parallel-perf.py | |
| parent | 9bcb5dbf0d0284c982613ebce7d2fda726159589 (diff) | |
misc: issei: check bus message length before reading the command
__issei_ham_process_ham_rsp() dispatches on hdr->cmd before the message
length is validated. The length comes from the firmware-owned DMA header
read in issei_dma_read(), which only bounds it from above, so firmware
sending a short bus message reaches the dispatch with less than
sizeof(struct ham_bus_message) bytes available.
For a zero-length message kmemdup() returns ZERO_SIZE_PTR, which passes
the NULL check in issei_dma_read(), and the dispatch dereferences it. A
length of one to three bytes gives a slab out-of-bounds read instead.
Reject bus messages shorter than the header before touching it, the way
the individual response handlers already validate their own length.
Fixes: 7bd4b9991db20 ("issei: implement main thread and ham messages")
Signed-off-by: Linmao Li <lilinmao@kylinos.cn>
Link: https://patch.msgid.link/20260731025952.3505287-1-lilinmao@kylinos.cn
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Diffstat (limited to 'tools/perf/scripts/python/parallel-perf.py')
0 files changed, 0 insertions, 0 deletions
