All of lore.kernel.org
 help / color / mirror / Atom feed
From: David Laight <david.laight.linux@gmail.com>
To: op-tee@lists.trustedfirmware.org
Subject: Re: [PATCH] tee: Prevent size calculation wraparound on 32-bit kernels
Date: Thu, 01 May 2025 21:01:58 +0100	[thread overview]
Message-ID: <20250501210158.5b2c86a7@pumpkin> (raw)
In-Reply-To: <20250428-tee-sizecheck-v1-1-5c3c25a2fa79@google.com>

[-- Attachment #1: Type: text/plain, Size: 3280 bytes --]

On Mon, 28 Apr 2025 15:06:43 +0200
Jann Horn <jannh@google.com> wrote:

> The current code around TEE_IOCTL_PARAM_SIZE() is a bit wrong on
> 32-bit kernels: Multiplying a user-provided 32-bit value with the
> size of a structure can wrap around on such platforms.
> 
> Fix it by using saturating arithmetic for the size calculation.

Why not just add a sanity check on 'num_params' after it is read.
Max is 31 (1024-32)/32), but any sane limit will do because of
the buf.buf_len test.

	David

> 
> This has no security consequences because, in all users of
> TEE_IOCTL_PARAM_SIZE(), the subsequent kcalloc() implicitly checks
> for wrapping.
> 
> Signed-off-by: Jann Horn <jannh@google.com>
> ---
> Note that I don't have a test device with a TEE; I only compile-tested
> the change on an x86-64 build.
> ---
>  drivers/tee/tee_core.c | 11 ++++++-----
>  1 file changed, 6 insertions(+), 5 deletions(-)
> 
> diff --git a/drivers/tee/tee_core.c b/drivers/tee/tee_core.c
> index d113679b1e2d..acc7998758ad 100644
> --- a/drivers/tee/tee_core.c
> +++ b/drivers/tee/tee_core.c
> @@ -10,6 +10,7 @@
>  #include <linux/fs.h>
>  #include <linux/idr.h>
>  #include <linux/module.h>
> +#include <linux/overflow.h>
>  #include <linux/slab.h>
>  #include <linux/tee_core.h>
>  #include <linux/uaccess.h>
> @@ -19,7 +20,7 @@
>  
>  #define TEE_NUM_DEVICES	32
>  
> -#define TEE_IOCTL_PARAM_SIZE(x) (sizeof(struct tee_param) * (x))
> +#define TEE_IOCTL_PARAM_SIZE(x) (size_mul(sizeof(struct tee_param), (x)))
>  
>  #define TEE_UUID_NS_NAME_SIZE	128
>  
> @@ -487,7 +488,7 @@ static int tee_ioctl_open_session(struct tee_context *ctx,
>  	if (copy_from_user(&arg, uarg, sizeof(arg)))
>  		return -EFAULT;
>  
> -	if (sizeof(arg) + TEE_IOCTL_PARAM_SIZE(arg.num_params) != buf.buf_len)
> +	if (size_add(sizeof(arg), TEE_IOCTL_PARAM_SIZE(arg.num_params)) != buf.buf_len)
>  		return -EINVAL;
>  
>  	if (arg.num_params) {
> @@ -565,7 +566,7 @@ static int tee_ioctl_invoke(struct tee_context *ctx,
>  	if (copy_from_user(&arg, uarg, sizeof(arg)))
>  		return -EFAULT;
>  
> -	if (sizeof(arg) + TEE_IOCTL_PARAM_SIZE(arg.num_params) != buf.buf_len)
> +	if (size_add(sizeof(arg), TEE_IOCTL_PARAM_SIZE(arg.num_params)) != buf.buf_len)
>  		return -EINVAL;
>  
>  	if (arg.num_params) {
> @@ -699,7 +700,7 @@ static int tee_ioctl_supp_recv(struct tee_context *ctx,
>  	if (get_user(num_params, &uarg->num_params))
>  		return -EFAULT;
>  
> -	if (sizeof(*uarg) + TEE_IOCTL_PARAM_SIZE(num_params) != buf.buf_len)
> +	if (size_add(sizeof(*uarg), TEE_IOCTL_PARAM_SIZE(num_params)) != buf.buf_len)
>  		return -EINVAL;
>  
>  	params = kcalloc(num_params, sizeof(struct tee_param), GFP_KERNEL);
> @@ -798,7 +799,7 @@ static int tee_ioctl_supp_send(struct tee_context *ctx,
>  	    get_user(num_params, &uarg->num_params))
>  		return -EFAULT;
>  
> -	if (sizeof(*uarg) + TEE_IOCTL_PARAM_SIZE(num_params) > buf.buf_len)
> +	if (size_add(sizeof(*uarg), TEE_IOCTL_PARAM_SIZE(num_params)) > buf.buf_len)
>  		return -EINVAL;
>  
>  	params = kcalloc(num_params, sizeof(struct tee_param), GFP_KERNEL);
> 
> ---
> base-commit: b4432656b36e5cc1d50a1f2dc15357543add530e
> change-id: 20250428-tee-sizecheck-299d5eff8fc7
> 


WARNING: multiple messages have this Message-ID (diff)
From: David Laight <david.laight.linux@gmail.com>
To: Jann Horn <jannh@google.com>
Cc: Jens Wiklander <jens.wiklander@linaro.org>,
	Sumit Garg <sumit.garg@kernel.org>,
	op-tee@lists.trustedfirmware.org, linux-kernel@vger.kernel.org
Subject: Re: [PATCH] tee: Prevent size calculation wraparound on 32-bit kernels
Date: Thu, 1 May 2025 21:01:58 +0100	[thread overview]
Message-ID: <20250501210158.5b2c86a7@pumpkin> (raw)
In-Reply-To: <20250428-tee-sizecheck-v1-1-5c3c25a2fa79@google.com>

On Mon, 28 Apr 2025 15:06:43 +0200
Jann Horn <jannh@google.com> wrote:

> The current code around TEE_IOCTL_PARAM_SIZE() is a bit wrong on
> 32-bit kernels: Multiplying a user-provided 32-bit value with the
> size of a structure can wrap around on such platforms.
> 
> Fix it by using saturating arithmetic for the size calculation.

Why not just add a sanity check on 'num_params' after it is read.
Max is 31 (1024-32)/32), but any sane limit will do because of
the buf.buf_len test.

	David

> 
> This has no security consequences because, in all users of
> TEE_IOCTL_PARAM_SIZE(), the subsequent kcalloc() implicitly checks
> for wrapping.
> 
> Signed-off-by: Jann Horn <jannh@google.com>
> ---
> Note that I don't have a test device with a TEE; I only compile-tested
> the change on an x86-64 build.
> ---
>  drivers/tee/tee_core.c | 11 ++++++-----
>  1 file changed, 6 insertions(+), 5 deletions(-)
> 
> diff --git a/drivers/tee/tee_core.c b/drivers/tee/tee_core.c
> index d113679b1e2d..acc7998758ad 100644
> --- a/drivers/tee/tee_core.c
> +++ b/drivers/tee/tee_core.c
> @@ -10,6 +10,7 @@
>  #include <linux/fs.h>
>  #include <linux/idr.h>
>  #include <linux/module.h>
> +#include <linux/overflow.h>
>  #include <linux/slab.h>
>  #include <linux/tee_core.h>
>  #include <linux/uaccess.h>
> @@ -19,7 +20,7 @@
>  
>  #define TEE_NUM_DEVICES	32
>  
> -#define TEE_IOCTL_PARAM_SIZE(x) (sizeof(struct tee_param) * (x))
> +#define TEE_IOCTL_PARAM_SIZE(x) (size_mul(sizeof(struct tee_param), (x)))
>  
>  #define TEE_UUID_NS_NAME_SIZE	128
>  
> @@ -487,7 +488,7 @@ static int tee_ioctl_open_session(struct tee_context *ctx,
>  	if (copy_from_user(&arg, uarg, sizeof(arg)))
>  		return -EFAULT;
>  
> -	if (sizeof(arg) + TEE_IOCTL_PARAM_SIZE(arg.num_params) != buf.buf_len)
> +	if (size_add(sizeof(arg), TEE_IOCTL_PARAM_SIZE(arg.num_params)) != buf.buf_len)
>  		return -EINVAL;
>  
>  	if (arg.num_params) {
> @@ -565,7 +566,7 @@ static int tee_ioctl_invoke(struct tee_context *ctx,
>  	if (copy_from_user(&arg, uarg, sizeof(arg)))
>  		return -EFAULT;
>  
> -	if (sizeof(arg) + TEE_IOCTL_PARAM_SIZE(arg.num_params) != buf.buf_len)
> +	if (size_add(sizeof(arg), TEE_IOCTL_PARAM_SIZE(arg.num_params)) != buf.buf_len)
>  		return -EINVAL;
>  
>  	if (arg.num_params) {
> @@ -699,7 +700,7 @@ static int tee_ioctl_supp_recv(struct tee_context *ctx,
>  	if (get_user(num_params, &uarg->num_params))
>  		return -EFAULT;
>  
> -	if (sizeof(*uarg) + TEE_IOCTL_PARAM_SIZE(num_params) != buf.buf_len)
> +	if (size_add(sizeof(*uarg), TEE_IOCTL_PARAM_SIZE(num_params)) != buf.buf_len)
>  		return -EINVAL;
>  
>  	params = kcalloc(num_params, sizeof(struct tee_param), GFP_KERNEL);
> @@ -798,7 +799,7 @@ static int tee_ioctl_supp_send(struct tee_context *ctx,
>  	    get_user(num_params, &uarg->num_params))
>  		return -EFAULT;
>  
> -	if (sizeof(*uarg) + TEE_IOCTL_PARAM_SIZE(num_params) > buf.buf_len)
> +	if (size_add(sizeof(*uarg), TEE_IOCTL_PARAM_SIZE(num_params)) > buf.buf_len)
>  		return -EINVAL;
>  
>  	params = kcalloc(num_params, sizeof(struct tee_param), GFP_KERNEL);
> 
> ---
> base-commit: b4432656b36e5cc1d50a1f2dc15357543add530e
> change-id: 20250428-tee-sizecheck-299d5eff8fc7
> 


  parent reply	other threads:[~2025-05-01 20:01 UTC|newest]

Thread overview: 14+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2025-04-28 13:06 [PATCH] tee: Prevent size calculation wraparound on 32-bit kernels Jann Horn
2025-04-28 13:06 ` Jann Horn
2025-04-30 11:52 ` Jens Wiklander
2025-04-30 11:52   ` Jens Wiklander
2025-05-01 20:01 ` David Laight [this message]
2025-05-01 20:01   ` David Laight
2025-05-02 12:28   ` Jann Horn
2025-05-02 12:28     ` Jann Horn
2025-05-02 12:40     ` David Laight
2025-05-02 12:41       ` David Laight
     [not found] < <CAHUa44E_JZdYnGrReP0zWCP1wdu2BdJ9DSZZ3a2OiobRj61ThQ@mail.gmail.com>
2025-04-30 12:12 ` Rouven Czerwinski
2025-04-30 12:12   ` Rouven Czerwinski
     [not found] < <CAK8z29XWCujUdLXcHz075+xcix8HV2Mp3EtxxX9GB7vGjwi3HA@mail.gmail.com>
2025-04-30 13:00 ` Jens Wiklander
2025-04-30 13:00   ` Jens Wiklander

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20250501210158.5b2c86a7@pumpkin \
    --to=david.laight.linux@gmail.com \
    --cc=op-tee@lists.trustedfirmware.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.