All of lore.kernel.org
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "David Hildenbrand" <david@kernel.org>,
	"Vlastimil Babka" <vbabka@kernel.org>,
	"Naoya Horiguchi" <nao.horiguchi@gmail.com>,
	"Breno Leitao" <leitao@debian.org>,
	"Mike Rapoport" <rppt@kernel.org>,
	"Michal Hocko" <mhocko@suse.com>,
	"Ingo Molnar" <mingo@redhat.com>, "Zi Yan" <ziy@nvidia.com>,
	"Dave Hansen" <dave.hansen@linux.intel.com>,
	"Thomas Gleixner" <tglx@kernel.org>,
	"Borislav Petkov" <bp@alien8.de>,
	"Johannes Weiner" <hannes@cmpxchg.org>,
	"H. Peter Anvin" <hpa@zytor.com>,
	"Lorenzo Stoakes" <ljs@kernel.org>,
	"Miaohe Lin" <linmiaohe@huawei.com>,
	"Andrew Morton" <akpm@linux-foundation.org>,
	"Ard Biesheuvel" <ardb@kernel.org>,
	kas@kernel.org, "Ilias Apalodimas" <ilias.apalodimas@linaro.org>,
	"Liam R. Howlett" <liam@infradead.org>,
	x86@kernel.org, "Suren Baghdasaryan" <surenb@google.com>,
	"Brendan Jackman" <brendan.jackman@linux.dev>
Cc: harry@kernel.org, linux-efi@vger.kernel.org, riel@surriel.com,
	linux-kernel@vger.kernel.org, linux-mm@kvack.org,
	kexec@lists.infradead.org, rmikey@meta.com, kernel-team@meta.com
Subject: Re: [PATCH v4 2/5] mm/memory-failure: libstub: install the poisoned-memory EFI table
Date: Wed, 09 Sep 2026 13:19:11 +0000	[thread overview]
Message-ID: <20260909131911.76D361F00A3A@smtp.kernel.org> (raw)
In-Reply-To: <20260909-hwpoison-kho-v4-2-359313564495@debian.org>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [Critical] Integer truncation in efi_poison_alloc leads to a massive heap buffer overflow during memset on 32-bit or mixed-mode systems.
--

commit 626632820fe1fdcddc73aaeb109705cbddc9828c
Author: Breno Leitao <leitao@debian.org>
Subject: mm/memory-failure: libstub: install the poisoned-memory EFI table

This patch introduces functionality in the EFI stub to create and install a
poisoned-memory EFI configuration table. It walks the UEFI memory map to find
the RAM range and allocates a bitmap to track poisoned memory granules.

> diff --git a/drivers/firmware/efi/libstub/efi-stub-helper.c b/drivers/firmware/efi/libstub/efi-stub-helper.c
> index 48f93f7758e9e..5cbe675491333 100644
> --- a/drivers/firmware/efi/libstub/efi-stub-helper.c
> +++ b/drivers/firmware/efi/libstub/efi-stub-helper.c
[ ... ]
> +static struct linux_efi_poisoned_memory *efi_poison_alloc(u64 phys_base,
> +							  u64 bitmap_size)
> +{
> +	struct linux_efi_poisoned_memory *pm;
> +	efi_status_t status;
> +
> +	status = efi_bs_call(allocate_pool, EFI_ACPI_RECLAIM_MEMORY,
> +			     sizeof(*pm) + bitmap_size, (void **)&pm);

[Severity: Critical]
Could sizeof(*pm) + bitmap_size overflow 32 bits on 32-bit or mixed-mode
systems? If the EFI memory map describes a very large physical address space
(such as a 32PB physical address provided by an untrusted hypervisor in a
TDX/SEV environment), bitmap_size could approach 4GB.

Because the size argument to allocate_pool is a UINTN, a value like
0x100000008 (sizeof(*pm) + 0xFFFFFFF0) would truncate to 8 bytes on 32-bit
EFI systems, resulting in an undersized allocation.

> +	if (status != EFI_SUCCESS)
> +		return NULL;
> +
> +	pm->version = 1;
> +	pm->unit_size = EFI_POISON_UNIT_SIZE;
> +	pm->phys_base = phys_base;
> +	pm->size = bitmap_size;
> +	memset(pm->bitmap, 0, bitmap_size);

[Severity: Critical]
If the allocate_pool calculation overflowed and truncated as described above,
does this memset trigger an out-of-bounds write regression?

Since bitmap_size (e.g., 0xFFFFFFF0) fits within a 32-bit size_t, memset
will use the large untruncated size, potentially overwriting up to 4GB of EFI
boot services memory following the undersized allocation.

> +
> +	return pm;
> +}

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260909-hwpoison-kho-v4-0-359313564495@debian.org?part=2

  reply	other threads:[~2026-09-09 13:19 UTC|newest]

Thread overview: 21+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-09 13:05 [PATCH v4 0/5] mm/memory-failure: keep hardware-poisoned pages out of the next kexec Breno Leitao
2026-09-09 13:05 ` [PATCH v4 1/5] mm/memory-failure: efi: add the LINUX_EFI_POISONED_MEMORY configuration table Breno Leitao
2026-09-09 13:13   ` sashiko-bot
2026-09-09 13:05 ` [PATCH v4 2/5] mm/memory-failure: libstub: install the poisoned-memory EFI table Breno Leitao
2026-09-09 13:19   ` sashiko-bot [this message]
2026-09-09 14:00     ` Breno Leitao
2026-09-09 14:47   ` Ard Biesheuvel
2026-09-10 13:11     ` Breno Leitao
2026-09-15  9:03       ` Breno Leitao
2026-09-15 12:12         ` Harry Yoo
2026-09-15 12:39           ` Breno Leitao
2026-09-15 13:31             ` Harry Yoo
2026-09-15 13:38               ` Breno Leitao
2026-09-15 14:35                 ` Harry Yoo
2026-09-09 13:05 ` [PATCH v4 3/5] mm/memory-failure: efi: record hardware-poisoned frames into the poisoned-memory table Breno Leitao
2026-09-09 13:21   ` sashiko-bot
2026-09-09 14:05     ` Breno Leitao
2026-09-09 13:05 ` [PATCH v4 4/5] mm/memory-failure: efi: answer whether a range is poisoned Breno Leitao
2026-09-09 13:17   ` sashiko-bot
2026-09-09 13:05 ` [PATCH v4 5/5] mm/memory-failure: keep inherited poisoned frames out of the buddy allocator Breno Leitao
2026-09-09 13:24   ` sashiko-bot

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260909131911.76D361F00A3A@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=akpm@linux-foundation.org \
    --cc=ardb@kernel.org \
    --cc=bp@alien8.de \
    --cc=brendan.jackman@linux.dev \
    --cc=dave.hansen@linux.intel.com \
    --cc=david@kernel.org \
    --cc=hannes@cmpxchg.org \
    --cc=harry@kernel.org \
    --cc=hpa@zytor.com \
    --cc=ilias.apalodimas@linaro.org \
    --cc=kas@kernel.org \
    --cc=kernel-team@meta.com \
    --cc=kexec@lists.infradead.org \
    --cc=leitao@debian.org \
    --cc=liam@infradead.org \
    --cc=linmiaohe@huawei.com \
    --cc=linux-efi@vger.kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-mm@kvack.org \
    --cc=ljs@kernel.org \
    --cc=mhocko@suse.com \
    --cc=mingo@redhat.com \
    --cc=nao.horiguchi@gmail.com \
    --cc=riel@surriel.com \
    --cc=rmikey@meta.com \
    --cc=rppt@kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    --cc=surenb@google.com \
    --cc=tglx@kernel.org \
    --cc=vbabka@kernel.org \
    --cc=x86@kernel.org \
    --cc=ziy@nvidia.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.