From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from bombadil.infradead.org (bombadil.infradead.org [198.137.202.133]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.lore.kernel.org (Postfix) with ESMTPS id 79BDDC88E50 for ; Mon, 14 Sep 2026 11:30:21 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=lists.infradead.org; s=bombadil.20210309; h=Sender: Content-Transfer-Encoding:Content-Type:List-Subscribe:List-Help:List-Post: List-Archive:List-Unsubscribe:List-Id:MIME-Version:References:In-Reply-To: Message-ID:Date:Subject:Cc:To:From:Reply-To:Content-ID:Content-Description: Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID: List-Owner; bh=CwvBu2ZLf2CdpPLcV20hnC0PAjKHAPEkaDtWLuj5wTs=; b=TUsUrTRsIx9SJV KhucvdUhVqGbgxpWIpD0nFAKBvguVwq+bKVXbDpUOgVZTuge2QxUxKt9EG1KrfBt+ePAOFqLUg2QD R3OkQrAKJVh19kmpHFglm9pYC2YN0Jt3V2LVfWP4HejH/BXiTv6C/5ziv7iyJoRMuKiswvccZhna0 bqS6q77iY9xj33xvjAsJFNCHLz+KPB/BEDZ1V6sGkrtIVvVlRnmOZyoBNyBdIZ7zkGejniDAfvs1c LukHOy2eYtmhfS0D8nJBDBAiTVpB/zzf4FhQSpY1pziFYi2bwvjUpwqabnoIiWUjCWCJ5sD4LWp0L UyTJeO7UCfQhPKNPm46w==; Received: from localhost ([::1] helo=bombadil.infradead.org) by bombadil.infradead.org with esmtp (Exim 4.99.1 #2 (Red Hat Linux)) id 1x64tB-00000003F3x-0XZe; Mon, 14 Sep 2026 11:30:21 +0000 Received: from mgamail.intel.com ([192.198.163.15]) by bombadil.infradead.org with esmtps (Exim 4.99.1 #2 (Red Hat Linux)) id 1x64t7-00000003F2I-49d0 for linux-i3c@lists.infradead.org; Mon, 14 Sep 2026 11:30:19 +0000 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=intel.com; i=@intel.com; q=dns/txt; s=Intel; t=1789385418; x=1820921418; h=from:to:cc:subject:date:message-id:in-reply-to: references:mime-version:content-transfer-encoding; bh=aVG8ApbrMeITL2vobZYuzF9rR5qtyehLwSaBRnUoQIw=; b=D7npPajCCAZNJSr0n33d0fAsDfvKBMFmxVLUHFNsefkmoyWZUNo7blUo 1ylwuusbmbYHAqlTgxg4bhS7RfAn3ciQYXW3HBQUjIZS3kB70quwIoTbd e9fjnzmbHboAFyR6KN/1Wxn9248F+8c2/xTSVUD9Wo0ID26zWBpCUrgdW oonYXPSh+rpUbh3Xoh6ghFf2a51y3/gqTQ5xs1iYaBR7KWfnhMv2KPKnc lO2cukAnfMOyf4VJXQpCYIFF4RTmIUO87xIyl2OuNfEKm+ziI9YXn25KF lBpMztIFH+wNXNo6MCwbjFz27poLldZADcJz37K5kWV/MLnt4d7/kWMQf g==; X-CSE-ConnectionGUID: i76S447fSsisG7ZuAZAamA== X-CSE-MsgGUID: XpWBEXH6RXmBKstdgCVTvQ== X-IronPort-AV: E=McAfee;i="6800,10657,11904"; a="89864408" X-IronPort-AV: E=Sophos;i="6.27,102,1787036400"; d="scan'208";a="89864408" Received: from orviesa009.jf.intel.com ([10.64.159.149]) by fmvoesa109.fm.intel.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 14 Sep 2026 04:30:17 -0700 X-CSE-ConnectionGUID: HXP2fMbxStGHVn4ZSJatIg== X-CSE-MsgGUID: 8Ux+fK0pTpa2osbIOJH+RA== X-ExtLoop1: 1 X-IronPort-AV: E=Sophos;i="6.27,102,1787036400"; d="scan'208";a="273133021" Received: from mkosciow-mobl1.ger.corp.intel.com (HELO ahunter6-desk) ([10.245.245.35]) by orviesa009-auth.jf.intel.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 14 Sep 2026 04:30:16 -0700 From: Adrian Hunter To: alexandre.belloni@bootlin.com Cc: Frank.Li@nxp.com, billy_tsai@aspeedtech.com, linux-i3c@lists.infradead.org, linux-kernel@vger.kernel.org Subject: [PATCH 01/17] i3c: master: Fix out-of-bounds read in DMA bounce buffer setup Date: Mon, 14 Sep 2026 14:29:47 +0300 Message-ID: <20260914113003.183150-2-adrian.hunter@intel.com> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260914113003.183150-1-adrian.hunter@intel.com> References: <20260914113003.183150-1-adrian.hunter@intel.com> MIME-Version: 1.0 Organization: Intel Finland Oy, Registered Address: c/o Alberga Business Park, 6 krs, Bertel Jungin Aukio 5, 02600 Espoo, Business Identity Code: 0357606 - 4, Domiciled in Helsinki X-CRM114-Version: 20100106-BlameMichelson ( TRE 0.9.0 (BSD) ) MR-646709E3 X-CRM114-CacheID: sfid-20260914_043018_223493_645789D8 X-CRM114-Status: GOOD ( 11.98 ) X-BeenThere: linux-i3c@lists.infradead.org X-Mailman-Version: 2.1.34 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit Sender: "linux-i3c" Errors-To: linux-i3c-bounces+linux-i3c=archiver.kernel.org@lists.infradead.org When a bounce buffer is required for DMA_TO_DEVICE transfers, i3c_master_dma_map_single() rounds the DMA mapping length up to a cache-line boundary: map_len = ALIGN(len, cache_line_size()); It then allocates the bounce buffer with: kmemdup(buf, map_len, GFP_KERNEL); kmemdup() copies the full allocation size, causing it to read map_len bytes from buf even though only len bytes are valid. This results in an out-of-bounds read of up to cache_line_size() - 1 bytes past the end of the caller's buffer. Fix the issue by allocating the bounce buffer with kzalloc() and copying only len bytes from the original buffer. The remaining bytes up to map_len stay zero-filled, avoiding both the out-of-bounds read and exposure of unrelated memory contents to the DMA engine. Fixes: f8d9e56aeb87 ("i3c: master: Add helpers for DMA mapping and bounce buffer handling") Cc: stable@vger.kernel.org Signed-off-by: Adrian Hunter --- drivers/i3c/master.c | 7 +++---- 1 file changed, 3 insertions(+), 4 deletions(-) diff --git a/drivers/i3c/master.c b/drivers/i3c/master.c index afcd7a21a3e6..f9a6c8560fab 100644 --- a/drivers/i3c/master.c +++ b/drivers/i3c/master.c @@ -2216,12 +2216,11 @@ struct i3c_dma *i3c_master_dma_map_single(struct device *dev, void *buf, if (force_bounce) { dma_xfer->map_len = ALIGN(len, cache_line_size()); - if (dir == DMA_FROM_DEVICE) - bounce = kzalloc(dma_xfer->map_len, GFP_KERNEL); - else - bounce = kmemdup(buf, dma_xfer->map_len, GFP_KERNEL); + bounce = kzalloc(dma_xfer->map_len, GFP_KERNEL); if (!bounce) return NULL; + if (dir != DMA_FROM_DEVICE) + memcpy(bounce, buf, len); dma_buf = bounce; } -- 2.53.0 -- linux-i3c mailing list linux-i3c@lists.infradead.org http://lists.infradead.org/mailman/listinfo/linux-i3c