From: Jamin Lin via <qemu-devel@nongnu.org>
To: "Cédric Le Goater" <clg@kaod.org>,
"Peter Maydell" <peter.maydell@linaro.org>,
"Steven Lee" <steven_lee@aspeedtech.com>,
"Troy Lee" <leetroy@gmail.com>,
"Andrew Jeffery" <andrew@codeconstruct.com.au>,
"Joel Stanley" <joel@jms.id.au>,
"Fabiano Rosas" <farosas@suse.de>,
"Laurent Vivier" <lvivier@redhat.com>,
"Paolo Bonzini" <pbonzini@redhat.com>,
"open list:ASPEED BMCs" <qemu-arm@nongnu.org>,
"open list:All patches CC here" <qemu-devel@nongnu.org>
Cc: <jamin_lin@aspeedtech.com>, <troy_lee@aspeedtech.com>
Subject: [PATCH v1 02/22] hw/misc/aspeed_hace: Fix buffer overflow in has_padding function
Date: Fri, 21 Mar 2025 17:25:58 +0800 [thread overview]
Message-ID: <20250321092623.2097234-3-jamin_lin@aspeedtech.com> (raw)
In-Reply-To: <20250321092623.2097234-1-jamin_lin@aspeedtech.com>
The maximum padding size is either 64 or 128 bytes and should always be smaller
than "req_len". If "padding_size" exceeds "req_len", then
"req_len - padding_size" underflows due to "uint32_t" data type, leading to a
large incorrect value (e.g., `0xFFXXXXXX`). This causes an out-of-bounds memory
access, potentially leading to a buffer overflow.
Added a check to ensure "padding_size" does not exceed "req_len" before
computing "pad_offset". This prevents "req_len - padding_size" from underflowing
and avoids accessing invalid memory.
Signed-off-by: Jamin Lin <jamin_lin@aspeedtech.com>
---
hw/misc/aspeed_hace.c | 5 +++++
1 file changed, 5 insertions(+)
diff --git a/hw/misc/aspeed_hace.c b/hw/misc/aspeed_hace.c
index 8e7e8113a5..d8b5f048bb 100644
--- a/hw/misc/aspeed_hace.c
+++ b/hw/misc/aspeed_hace.c
@@ -128,6 +128,11 @@ static bool has_padding(AspeedHACEState *s, struct iovec *iov,
if (*total_msg_len <= s->total_req_len) {
uint32_t padding_size = s->total_req_len - *total_msg_len;
uint8_t *padding = iov->iov_base;
+
+ if (padding_size > req_len) {
+ return false;
+ }
+
*pad_offset = req_len - padding_size;
if (padding[*pad_offset] == 0x80) {
return true;
--
2.43.0
next prev parent reply other threads:[~2025-03-21 9:27 UTC|newest]
Thread overview: 82+ messages / expand[flat|nested] mbox.gz Atom feed top
2025-03-21 9:25 [PATCH v1 00/22] Fix incorrect hash results on AST2700 Jamin Lin via
2025-03-21 9:25 ` [PATCH v1 01/22] hw/misc/aspeed_hace: Remove unused code for better readability Jamin Lin via
2025-04-01 13:08 ` Cédric Le Goater
2025-05-05 3:28 ` Jamin Lin
2025-05-06 9:01 ` Cédric Le Goater
2025-03-21 9:25 ` Jamin Lin via [this message]
2025-03-21 9:47 ` [PATCH v1 02/22] hw/misc/aspeed_hace: Fix buffer overflow in has_padding function Jamin Lin
2025-03-22 20:52 ` Cédric Le Goater
2025-03-21 9:25 ` [PATCH v1 03/22] hw/misc/aspeed_hace: Improve readability and consistency in variable naming Jamin Lin via
2025-04-01 13:17 ` Cédric Le Goater
2025-05-09 6:57 ` Jamin Lin
2025-03-21 9:26 ` [PATCH v1 04/22] hw/misc/aspeed_hace: Update hash source address handling to 64-bit for AST2700 Jamin Lin via
2025-04-01 13:52 ` Cédric Le Goater
2025-05-09 6:49 ` Jamin Lin
2025-03-21 9:26 ` [PATCH v1 05/22] hw/misc/aspeed_hace: Introduce 64-bit digest_addr variable " Jamin Lin via
2025-04-01 13:55 ` Cédric Le Goater
2025-05-09 4:01 ` Jamin Lin
2025-03-21 9:26 ` [PATCH v1 06/22] hw/misc/aspeed_hace: Support accumulative mode for direct access mode Jamin Lin via
2025-03-21 9:26 ` Jamin Lin via
2025-04-01 13:57 ` Cédric Le Goater
2025-05-09 6:55 ` Jamin Lin
2025-05-10 6:12 ` Cédric Le Goater
2025-03-21 9:26 ` [PATCH v1 07/22] hw/misc/aspeed_hace: Add support for source, digest, key buffer 64 bit addresses Jamin Lin via
2025-04-01 16:19 ` Cédric Le Goater
2025-05-12 8:06 ` Jamin Lin
2025-03-21 9:26 ` [PATCH v1 08/22] hw/misc/aspeed_hace: Support DMA 64 bits dram address Jamin Lin via
2025-03-21 9:26 ` Jamin Lin via
2025-04-02 7:41 ` Cédric Le Goater
2025-05-09 7:04 ` Jamin Lin
2025-05-10 6:15 ` Cédric Le Goater
2025-05-12 8:41 ` Jamin Lin
2025-05-15 7:11 ` Jamin Lin
2025-05-15 7:19 ` Jamin Lin
2025-03-21 9:26 ` [PATCH v1 09/22] hw/misc/aspeed_hace: Ensure HASH_IRQ is always set to prevent firmware hang Jamin Lin via
2025-04-02 9:35 ` Cédric Le Goater
2025-05-06 5:08 ` Jamin Lin
2025-03-21 9:26 ` [PATCH v1 10/22] hw/misc/aspeed_hace:: Support setting different memory size Jamin Lin via
2025-04-02 7:46 ` Cédric Le Goater
2025-03-21 9:26 ` [PATCH v1 11/22] hw/misc/aspeed_hace: Add trace-events for better debugging Jamin Lin via
2025-04-02 7:59 ` Cédric Le Goater
2025-05-12 1:34 ` Jamin Lin
2025-03-21 9:26 ` [PATCH v1 12/22] hw/misc/aspeed_hace Support to dump plaintext and digest " Jamin Lin via
2025-03-21 9:26 ` Jamin Lin via
2025-04-02 8:05 ` Cédric Le Goater
2025-05-12 5:22 ` Jamin Lin
2025-03-21 9:26 ` [PATCH v1 13/22] test/qtest: Introduce a new aspeed-hace-utils.c to place common testcases Jamin Lin via
2025-03-21 9:26 ` Jamin Lin via
2025-04-02 8:54 ` Cédric Le Goater
2025-05-05 6:42 ` Jamin Lin
2025-03-21 9:26 ` [PATCH v1 14/22] test/qtest/hace: Adjust test address range for AST1030 due to SRAM limitations Jamin Lin via
2025-03-21 9:26 ` Jamin Lin via
2025-04-02 9:43 ` Cédric Le Goater
2025-05-05 3:44 ` Jamin Lin
2025-03-21 9:26 ` [PATCH v1 15/22] test/qtest/hace: Add SHA-384 test cases for ASPEED HACE model Jamin Lin via
2025-03-21 9:26 ` Jamin Lin via
2025-04-02 9:02 ` Cédric Le Goater
2025-05-05 6:36 ` Jamin Lin
2025-05-05 6:51 ` Jamin Lin
2025-05-06 8:59 ` Cédric Le Goater
2025-03-21 9:26 ` [PATCH v1 16/22] test/qtest/hace: Add SHA-384 tests for AST2600 Jamin Lin via
2025-03-21 9:26 ` Jamin Lin via
2025-04-02 9:02 ` Cédric Le Goater
2025-03-21 9:26 ` [PATCH v1 17/22] test/qtest/hace: Add tests for AST1030 Jamin Lin via
2025-04-02 9:44 ` Cédric Le Goater
2025-03-21 9:26 ` [PATCH v1 18/22] test/qtest/hace: Update source data and digest data type to 64-bit Jamin Lin via
2025-03-21 9:26 ` Jamin Lin via
2025-04-02 9:05 ` Cédric Le Goater
2025-05-12 7:14 ` Jamin Lin
2025-03-21 9:26 ` [PATCH v1 19/22] test/qtest/hace: Support 64-bit source and digest addresses for AST2700 Jamin Lin via
2025-03-21 9:26 ` Jamin Lin via
2025-04-02 9:06 ` Cédric Le Goater
2025-03-21 9:26 ` [PATCH v1 20/22] test/qtest/hace: Support to test upper 32 bits of digest and source addresses Jamin Lin via
2025-03-21 9:26 ` Jamin Lin via
2025-04-02 9:12 ` Cédric Le Goater
2025-03-21 9:26 ` [PATCH v1 21/22] test/qtest/hace: Support to validate 64-bit hmac key buffer addresses Jamin Lin via
2025-04-02 9:12 ` Cédric Le Goater
2025-03-21 9:26 ` [PATCH v1 22/22] test/qtest/hace: Add tests for AST2700 Jamin Lin via
2025-03-21 9:26 ` Jamin Lin via
2025-04-02 9:16 ` Cédric Le Goater
2025-03-21 9:39 ` [PATCH v1 00/22] Fix incorrect hash results on AST2700 Cédric Le Goater
2025-04-02 9:47 ` Cédric Le Goater
2025-04-02 9:54 ` Jamin Lin
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20250321092623.2097234-3-jamin_lin@aspeedtech.com \
--to=qemu-devel@nongnu.org \
--cc=andrew@codeconstruct.com.au \
--cc=clg@kaod.org \
--cc=farosas@suse.de \
--cc=jamin_lin@aspeedtech.com \
--cc=joel@jms.id.au \
--cc=leetroy@gmail.com \
--cc=lvivier@redhat.com \
--cc=pbonzini@redhat.com \
--cc=peter.maydell@linaro.org \
--cc=qemu-arm@nongnu.org \
--cc=steven_lee@aspeedtech.com \
--cc=troy_lee@aspeedtech.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.