From: "Pandey, Radhey Shyam" <radheys@amd.com>
To: Shubhrajyoti Datta <shubhrajyoti.datta@amd.com>,
linux-edac@vger.kernel.org
Cc: git@amd.com, shubhrajyoti.datta@gmail.com,
Michal Simek <michal.simek@amd.com>,
Borislav Petkov <bp@alien8.de>, Tony Luck <tony.luck@intel.com>,
linux-kernel@vger.kernel.org
Subject: Re: [PATCH 7/9] EDAC/versalnet: Add bounds validation in rpmsg_cb()
Date: Fri, 31 Jul 2026 19:26:19 +0530 [thread overview]
Message-ID: <4b17c6da-3eba-4591-910f-9fe26b4d422c@amd.com> (raw)
In-Reply-To: <20260724171945.2812749-8-shubhrajyoti.datta@amd.com>
On 7/24/2026 10:49 PM, Shubhrajyoti Datta wrote:
> The firmware-supplied offset and length values from the RPMsg payload
> are used without validation to index into mc_priv->regs[] (REG_MAX=152
> entries). A malformed or buggy firmware message could write past the end
> of the array, corrupting adjacent structure members and the kernel heap.
> Add check for the same.
>
> Signed-off-by: Shubhrajyoti Datta <shubhrajyoti.datta@amd.com>
> ---
>
> drivers/edac/versalnet_edac.c | 3 +++
> 1 file changed, 3 insertions(+)
>
> diff --git a/drivers/edac/versalnet_edac.c b/drivers/edac/versalnet_edac.c
> index e9561242f292..baca90f44c58 100644
> --- a/drivers/edac/versalnet_edac.c
> +++ b/drivers/edac/versalnet_edac.c
> @@ -602,6 +602,9 @@ static int rpmsg_cb(struct rpmsg_device *rpdev, void *data,
> length = result[MSG_ERR_LENGTH];
> offset = result[MSG_ERR_OFFSET];
>
> + if (offset + length > REG_MAX)
> + return -EINVAL;
> +
Nit - Integer overflow on offset + length
> /*
> * The data can come in two stretches. Construct the regs from two
> * messages. The offset indicates the offset from which the data is to
next prev parent reply other threads:[~2026-07-31 13:56 UTC|newest]
Thread overview: 25+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-07-24 17:19 [PATCH 0/9] EDAC/versalnet: Fix error handling, teardown, and robustness Shubhrajyoti Datta
2026-07-24 17:19 ` [PATCH 1/9] EDAC/versalnet: Add NULL check for mci in handle_error() Shubhrajyoti Datta
2026-07-26 23:52 ` Borislav Petkov
2026-07-27 6:48 ` Pandey, Radhey Shyam
2026-07-28 1:37 ` Borislav Petkov
2026-07-28 18:27 ` Pandey, Radhey Shyam
2026-07-28 21:33 ` Borislav Petkov
2026-07-29 16:40 ` Pandey, Radhey Shyam
2026-07-30 15:03 ` Shubhrajyoti Datta
2026-07-24 17:19 ` [PATCH 2/9] EDAC/versalnet: Add NULL check for mci in remove_one_mc() Shubhrajyoti Datta
2026-07-27 8:11 ` Pandey, Radhey Shyam
2026-07-24 17:19 ` [PATCH 3/9] EDAC/versalnet: Move platform_set_drvdata() to mc_probe() Shubhrajyoti Datta
2026-07-27 8:35 ` Pandey, Radhey Shyam
2026-07-24 17:19 ` [PATCH 4/9] EDAC/versalnet: Fix device_register() error handling in init_one_mc() Shubhrajyoti Datta
2026-07-31 11:01 ` Pandey, Radhey Shyam
2026-07-24 17:19 ` [PATCH 5/9] EDAC/versalnet: Use dev_set_name() instead of sprintf with init_name Shubhrajyoti Datta
2026-07-31 11:22 ` Pandey, Radhey Shyam
2026-07-24 17:19 ` [PATCH 6/9] EDAC/versalnet: Initialize MCDI before RPMsg registration Shubhrajyoti Datta
2026-07-31 11:41 ` Pandey, Radhey Shyam
2026-07-24 17:19 ` [PATCH 7/9] EDAC/versalnet: Add bounds validation in rpmsg_cb() Shubhrajyoti Datta
2026-07-31 13:56 ` Pandey, Radhey Shyam [this message]
2026-07-24 17:19 ` [PATCH 8/9] EDAC/versalnet: Fix use-after-free in remove_one_mc() Shubhrajyoti Datta
2026-07-31 14:06 ` Pandey, Radhey Shyam
2026-07-24 17:19 ` [PATCH 9/9] EDAC/versalnet: Use designated initializer for rpmsg_channel_info Shubhrajyoti Datta
2026-07-31 14:26 ` Pandey, Radhey Shyam
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=4b17c6da-3eba-4591-910f-9fe26b4d422c@amd.com \
--to=radheys@amd.com \
--cc=bp@alien8.de \
--cc=git@amd.com \
--cc=linux-edac@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=michal.simek@amd.com \
--cc=shubhrajyoti.datta@amd.com \
--cc=shubhrajyoti.datta@gmail.com \
--cc=tony.luck@intel.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.