From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-pj2-f12.google.com (mail-pj2-f12.google.com [74.125.227.140]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id C029E2D0629 for ; Wed, 9 Sep 2026 03:50:48 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=74.125.227.140 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788925850; cv=none; b=gFnWdzBrJuIIH9UI44Q52x0UskjiRqXulxV8fVVrcwLbY2Yx+EPtML72JDOaW+3wjTq90tTzVD6tqU9Gy9CaLl9vaAXa8q+66fPcCGZ1WNsNNgsXI5iI0ytjK95u3NQxiX1+lP+Qh4XOX21SBr4LcesSUuE2/W4OmYx0BYdksgU= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788925850; c=relaxed/simple; bh=AhuEEJfJXAW5jJEXow7KlfpNuompEqNNGI+LEVIIOeA=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=J9KckB/Ad0nvP4yyy/GAZbHw71d2fWZUZ8hs5aj+39F/DAqNaHTmYx0Vg+F9VRATIWRgCgfC2CQ+CXDXyBMzlJDo6SPLFOwIJILwc/RqlBC2Yim9jFzl+fHKmBEnpkYdQEz4J1AW0Xdu4QHEaNUyTtafqBpWjv8uzf02i2ItOj4= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=ABejMCLT; arc=none smtp.client-ip=74.125.227.140 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="ABejMCLT" Received: by mail-pj2-f12.google.com with SMTP id d9443c01a7336-2d747f066d8so5759555ad.1 for ; Tue, 08 Sep 2026 20:50:48 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1788925848; x=1789530648; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=zeqg9OVR1P74ongtyOgESAhm4/yUelGPhQFrlEwPtQ4=; b=ABejMCLT+YSq/uajZsu4FucKyFTyGR79My7JbADliri2v4coCko/aLKR57pzrnYaqK TZZVgA5bdDMdqsJOIfUGqmz6DUHn7iDwpr5d2nCSwcjV/fId+79S8E2rHdc/K7M92vry fBVufdfLjo8b0/LieFNtYob7k7YjGiuSvUelH9cLHH4/j2ChkqkGbutS6iwc2BWerZoi WQThzZFhmcF0E939xW720c9gfxbNLrJhNy2Otrk4HLMhe0b4vqIAm9sUuLceWyAIs8Rq MwlSQqTmGcNpAjmAYejrYID5UOiAlIPDOqlYsLb18BgyMSPiNk+YBHOSQL/KyY2Zarjm JYUg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788925848; x=1789530648; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=zeqg9OVR1P74ongtyOgESAhm4/yUelGPhQFrlEwPtQ4=; b=kAZzMoFRTJYkLNp79ejD+HcLipBN2YLamR0EtpYRN1IpKYazudeQPUmNNer41o2fQW XhEgVK10R6+KeZw59Fnb1EiES9DAcwKQqI+Ft2Wd6jkLWmihOvNV7EGDzRMfkNz+bGdb dyFAShDmgh7zj/AOWr/CiOPzMtd3rAbpHn9m39TRXq2y92CXI88cyxVy9VJqg0qpdAdC HSQ2TAg1RAwHTf8VfQdU/DKTaPFZwHuU3eiPm6cJgNFqELO8mqiG/0j/yacanJ2HwZze ZbIrjOvGzbOvG1O+/EC2WFAH6a480lEqEveihVbIBr8dp0HQc52TsykwZAZqCSA2AKDd /Pug== X-Forwarded-Encrypted: i=1; AKwUvByfHTULIp8lSj91wjKe4SYNASHS4Z1R83evhMjW0qseD5muntlj5EV0lZKxH3qD8gpj3E6WoZQaSpU=@vger.kernel.org X-Gm-Message-State: AFuF++nt1dEXfgFfZd/V8mx0L9YzocgFTjGJz67Utm0tsA60Fqbbu2Pw qfKAYaV5nG/I8uVzJkdk26vLIJUw5kCOTbGIj3oqeBYlyk1Fn3IplR9m X-Gm-Gg: AYBFou16AGLN8n10cJL85cLCMA/Uq1+U3/NyxNsH+1lRwiimheDYk65RSlcvjjjF9XH luvbJHL/o7+rz0x1YVMO0R4JC45ZVwo4Ctwblp89WVaeMZUwaZklD9oebGmQ/lNlKAVh10sz1du CMXltgUgW7tdlysFZxyRH8jY/bhmJP6uo9RCaeayXj3qqNJkBmGvJkdaJCkj5PW8ogAcZBIBSnC W6I3fAszQYLsn8jf/WAUi7xiTxypWNXknP/VLPfdu5MOeQ/uDtdFMPt5w8DdaCUD85tmrFWwEZR yTx6LpEbD7CViRU2LhcAT2be0cBCnpk4sT8lSwvH320srft3dpWH9icFuBtTZIg0cPt25pNbG4u pv8oiZ4DwcKxi24lXtgoSqtxhETprQWlr7EbU05EhXEnOxP1nKK/nkNTCXqBwQMePnVY/6qTQ0D JaQMSJNFij1jejv0GPSYfNbBB0K+hG+TLz2T3vVUeI44zdVRccqhMkyWkwCQq/uJ1ZYDANqmgW0 i9yx5YIGnlG X-Received: by 2002:a17:902:c40b:b0:2d7:4bc8:41a4 with SMTP id d9443c01a7336-2db701f6af8mr93965615ad.10.1788925847884; Tue, 08 Sep 2026 20:50:47 -0700 (PDT) Received: from ancienth-X870E-Nova-WiFi ([125.186.72.2]) by smtp.gmail.com with ESMTPSA id d9443c01a7336-2db14ae7637sm65891705ad.79.2026.09.08.20.50.45 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 08 Sep 2026 20:50:47 -0700 (PDT) From: Daehyeon Ko <4ncienth@gmail.com> To: Mika Westerberg Cc: Andreas Noever , Yehezkel Bernat , linux-usb@vger.kernel.org, linux-kernel@vger.kernel.org Subject: [PATCH 0/2] thunderbolt: Validate router-provided port numbers Date: Wed, 9 Sep 2026 12:50:38 +0900 Message-ID: <20260909035040.2929285-1-4ncienth@gmail.com> X-Mailer: git-send-email 2.55.0 Precedence: bulk X-Mailing-List: linux-usb@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit Two six-bit port numbers received from a router are used to index the router's sw->ports array without first comparing them with max_port_number. The array contains only max_port_number + 1 entries. Patch 1 validates the port in a DP bandwidth notification before tb_handle_dp_bandwidth_request() calls tb_port_is_dpin(). Patch 2 validates HOPS out_port at all three path-discovery sites and performs the construction-pass check before allocating an input HopID. I tested a private synthetic KUnit reproducer on current mainline 893e11787f78. It allocates ports 0 through 12 and supplies port 63. On x86_64, struct tb_port is 200 bytes, so the requested allocation is 2,600 bytes and the selected object starts at offset 12,600. The unmodified accesses produced: - a four-byte KASAN slab-out-of-bounds read in tb_port_is_dpin(), 3/3 boots; - an eight-byte KASAN slab-out-of-bounds read of out_port->remote, 3/3 boots. With this series, both controls pass 3/3 with no KASAN report and the complete Thunderbolt KUnit suite passes 47/47. drivers/thunderbolt/tb.o and path.o also build with W=1 without warnings. I have not performed hardware control-channel or HOPS injection. The DP notification index is used before tunnel lookup or bandwidth-mode validation. The HOPS sites are used to discover already enabled preboot tunnels and during resume discovery; ordinary hotplug path construction uses tb_path_alloc() instead. The private reproducer is available to the maintainers on request and is not included in this public series. Daehyeon Ko (2): thunderbolt: Validate DP bandwidth notification port thunderbolt: Validate output ports while discovering paths drivers/thunderbolt/path.c | 27 ++++++++++++++++++++++----- drivers/thunderbolt/tb.c | 5 +++++ 2 files changed, 27 insertions(+), 5 deletions(-) base-commit: 893e11787f78e43b534e252249ac3fff4d1333f8 -- 2.55.0