All of lore.kernel.org
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Dumitru Ceclan" <dumitru.ceclan@analog.com>
Cc: devicetree@vger.kernel.org, media-ci@linuxtv.org,
	conor+dt@kernel.org, robh@kernel.org
Subject: Re: [PATCH v17 20/22] media: i2c: maxim-serdes: add MAX96724 driver
Date: Wed, 09 Sep 2026 13:58:05 +0000	[thread overview]
Message-ID: <20260909135805.DCFBB1F00A3F@smtp.kernel.org> (raw)
In-Reply-To: <20260909-gmsl2-3_serdes-v17-20-002499e534e8@analog.com>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] TOCTOU race in stream enablement leads to a kernel stack out-of-bounds read and info leak via Virtual Channel mapping.
--

commit 09e380cc5beec37cc922ac65a1a89a282d99562a
Author: Cosmin Tanislav <demonsingur@gmail.com>
Subject: media: i2c: maxim-serdes: add MAX96724 driver

This commit adds a new MAX96724 driver that supports MAX96712, MAX96724F
and MAX96724R quad deserializers. It integrates the devices with the common
deserializer framework.

> diff --git a/drivers/media/i2c/maxim-serdes/max96724.c b/drivers/media/i2c/maxim-serdes/max96724.c
> new file mode 100644
> index 0000000000000..458e78f285111
> --- /dev/null
> +++ b/drivers/media/i2c/maxim-serdes/max96724.c

[ ... ]

> +static int max96724_set_pipe_remap(struct max_des *des,
> +				   struct max_des_pipe *pipe,
> +				   unsigned int i,
> +				   struct max_des_remap *remap)
> +{
> +	struct max96724_priv *priv = des_to_priv(des);
> +	struct max_des_phy *phy = &des->phys[remap->phy];
> +	unsigned int phy_id = max96724_phy_id(des, phy);
> +	unsigned int index = pipe->index;
> +	int ret;

[ ... ]

> +	/* Set destination Data Type and Virtual Channel. */
> +	/* TODO: implement extended Virtual Channel. */
> +	ret = regmap_write(priv->regmap, MAX96724_MIPI_TX14(index, i),
> +			   FIELD_PREP(MAX96724_MIPI_TX14_MAP_DST_DT,
> +				      remap->to_dt) |
> +			   FIELD_PREP(MAX96724_MIPI_TX14_MAP_DST_VC,
> +				      remap->to_vc));

[Severity: High]
Can a TOCTOU race in stream enablement lead to a kernel stack out-of-bounds
read and an information leak here?

When max_des_update_streams() is called, it fetches the remote sensor's frame
descriptor twice: first in max_des_populate_remap_context(), and later in
max_des_get_pipe_remaps(). If a concurrent V4L2 ioctl on the sensor changes
the Virtual Channel (vc) ID between these calls, a race occurs.

During the second pass, max_des_get_pipe_remaps() invokes the getter without
re-validating the newly fetched src_vc_id:

max_des_get_pipe_remaps() {
    ...
    ret = max_des_get_src_dst_vc_id(context, pipe->index, hw.phy->index,
                                    src_vc_id, &dst_vc_id);
}

Inside max_des_get_src_dst_vc_id(), this results in an out-of-bounds read
on the stack-allocated context array if src_vc_id is modified to bypass
bitmask checks (e.g., if it is a multiple of BITS_PER_LONG):

max_des_get_src_dst_vc_id() {
    ...
    *dst_vc_id = context->vc_ids_map[pipe_id][phy_id][src_vc_id];
}

The out-of-bounds stack data is then assigned to remap->to_vc and passed to
this hardware driver. By programming remap->to_vc into the hardware register
here, is it possible that up to 2 bits of kernel stack memory per race could
be leaked onto the observable MIPI CSI-2 bus?

> +	if (ret)
> +		return ret;
> +
> +	/* Set destination PHY. */
> +	return regmap_update_bits(priv->regmap, MAX96724_MIPI_TX45(index, i),
> +				  MAX96724_MIPI_TX45_MAP_DPHY_DEST(i),
> +				  field_prep(MAX96724_MIPI_TX45_MAP_DPHY_DEST(i),
> +					     phy_id));
> +}

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260909-gmsl2-3_serdes-v17-0-002499e534e8@analog.com?part=20

  reply	other threads:[~2026-09-09 13:58 UTC|newest]

Thread overview: 54+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-09 13:27 [PATCH v17 00/22] media: i2c: add Maxim GMSL2/3 serializer and deserializer drivers Dumitru Ceclan via B4 Relay
2026-09-09 13:27 ` Dumitru Ceclan
2026-09-09 13:27 ` [PATCH v17 01/22] media: mc: Add INTERNAL pad flag Dumitru Ceclan via B4 Relay
2026-09-09 13:27   ` Dumitru Ceclan
2026-09-09 13:27 ` [PATCH v17 02/22] dt-bindings: media: i2c: max96717: add support for I2C ATR Dumitru Ceclan via B4 Relay
2026-09-09 13:27   ` Dumitru Ceclan
2026-09-09 13:27 ` [PATCH v17 03/22] dt-bindings: media: i2c: max96717: add support for pinctrl/pinconf Dumitru Ceclan via B4 Relay
2026-09-09 13:27   ` Dumitru Ceclan
2026-09-09 13:27 ` [PATCH v17 04/22] dt-bindings: media: i2c: max96717: add support for MAX9295A Dumitru Ceclan via B4 Relay
2026-09-09 13:27   ` Dumitru Ceclan
2026-09-09 13:27 ` [PATCH v17 05/22] dt-bindings: media: i2c: max96717: add support for MAX96793 Dumitru Ceclan via B4 Relay
2026-09-09 13:27   ` Dumitru Ceclan
2026-09-09 13:27 ` [PATCH v17 06/22] dt-bindings: media: i2c: max96712: use pattern properties for ports Dumitru Ceclan via B4 Relay
2026-09-09 13:27   ` Dumitru Ceclan
2026-09-09 13:27 ` [PATCH v17 07/22] dt-bindings: media: i2c: max96712: add support for I2C ATR Dumitru Ceclan via B4 Relay
2026-09-09 13:27   ` Dumitru Ceclan
2026-09-09 13:27 ` [PATCH v17 08/22] dt-bindings: media: i2c: max96712: add support for POC supplies Dumitru Ceclan via B4 Relay
2026-09-09 13:27   ` Dumitru Ceclan
2026-09-09 13:27 ` [PATCH v17 09/22] dt-bindings: media: i2c: max96712: add support for MAX96724F/R Dumitru Ceclan via B4 Relay
2026-09-09 13:27   ` Dumitru Ceclan
2026-09-09 13:27 ` [PATCH v17 10/22] dt-bindings: media: i2c: max96712: add control-channel-port property Dumitru Ceclan via B4 Relay
2026-09-09 13:27   ` Dumitru Ceclan
2026-09-09 13:27 ` [PATCH v17 11/22] dt-bindings: media: i2c: max96714: add support for MAX96714R Dumitru Ceclan via B4 Relay
2026-09-09 13:27   ` Dumitru Ceclan
2026-09-09 13:27 ` [PATCH v17 12/22] dt-bindings: media: i2c: add MAX9296A, MAX96716A, MAX96792A Dumitru Ceclan via B4 Relay
2026-09-09 13:27   ` Dumitru Ceclan
2026-09-09 13:38   ` sashiko-bot
2026-09-09 13:27 ` [PATCH v17 13/22] media: i2c: add Maxim GMSL2/3 serializer and deserializer framework Dumitru Ceclan via B4 Relay
2026-09-09 13:27   ` Dumitru Ceclan
2026-09-09 13:27 ` [PATCH v17 14/22] media: i2c: add Maxim GMSL2/3 serializer framework Dumitru Ceclan via B4 Relay
2026-09-09 13:27   ` Dumitru Ceclan
2026-09-09 13:49   ` sashiko-bot
2026-09-09 13:27 ` [PATCH v17 15/22] media: i2c: add Maxim GMSL2/3 deserializer framework Dumitru Ceclan via B4 Relay
2026-09-09 13:27   ` Dumitru Ceclan
2026-09-09 13:50   ` sashiko-bot
2026-09-12  3:26   ` Quentin Freimanis
2026-09-09 13:27 ` [PATCH v17 16/22] media: i2c: remove MAX96717 driver Dumitru Ceclan via B4 Relay
2026-09-09 13:27   ` Dumitru Ceclan
2026-09-09 13:27 ` [PATCH v17 17/22] media: i2c: maxim-serdes: add " Dumitru Ceclan via B4 Relay
2026-09-09 13:27   ` Dumitru Ceclan
2026-09-09 13:49   ` sashiko-bot
2026-09-09 13:27 ` [PATCH v17 18/22] arm64: defconfig: disable deprecated MAX96712 driver Dumitru Ceclan via B4 Relay
2026-09-09 13:27   ` Dumitru Ceclan
2026-09-09 13:42   ` sashiko-bot
2026-09-09 13:27 ` [PATCH v17 19/22] staging: media: remove " Dumitru Ceclan via B4 Relay
2026-09-09 13:27   ` Dumitru Ceclan
2026-09-09 13:27 ` [PATCH v17 20/22] media: i2c: maxim-serdes: add MAX96724 driver Dumitru Ceclan via B4 Relay
2026-09-09 13:27   ` Dumitru Ceclan
2026-09-09 13:58   ` sashiko-bot [this message]
2026-09-09 13:27 ` [PATCH v17 21/22] media: i2c: remove MAX96714 driver Dumitru Ceclan via B4 Relay
2026-09-09 13:27   ` Dumitru Ceclan
2026-09-09 13:27 ` [PATCH v17 22/22] media: i2c: maxim-serdes: add MAX9296A driver Dumitru Ceclan via B4 Relay
2026-09-09 13:27   ` Dumitru Ceclan
2026-09-09 13:53   ` sashiko-bot

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260909135805.DCFBB1F00A3F@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=conor+dt@kernel.org \
    --cc=devicetree@vger.kernel.org \
    --cc=dumitru.ceclan@analog.com \
    --cc=media-ci@linuxtv.org \
    --cc=robh@kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.