All of lore.kernel.org
 help / color / mirror / Atom feed
From: "Pandey, Radhey Shyam" <radheys@amd.com>
To: Shubhrajyoti Datta <shubhrajyoti.datta@amd.com>,
	linux-edac@vger.kernel.org
Cc: git@amd.com, shubhrajyoti.datta@gmail.com,
	Michal Simek <michal.simek@amd.com>,
	Borislav Petkov <bp@alien8.de>, Tony Luck <tony.luck@intel.com>,
	linux-kernel@vger.kernel.org
Subject: Re: [PATCH 7/9] EDAC/versalnet: Add bounds validation in rpmsg_cb()
Date: Fri, 31 Jul 2026 19:26:19 +0530	[thread overview]
Message-ID: <4b17c6da-3eba-4591-910f-9fe26b4d422c@amd.com> (raw)
In-Reply-To: <20260724171945.2812749-8-shubhrajyoti.datta@amd.com>

On 7/24/2026 10:49 PM, Shubhrajyoti Datta wrote:
> The firmware-supplied offset and length values from the RPMsg payload
> are used without validation to index into mc_priv->regs[] (REG_MAX=152
> entries). A malformed or buggy firmware message could write past the end
> of the array, corrupting adjacent structure members and the kernel heap.
> Add check for the same.
> 
> Signed-off-by: Shubhrajyoti Datta <shubhrajyoti.datta@amd.com>
> ---
> 
>   drivers/edac/versalnet_edac.c | 3 +++
>   1 file changed, 3 insertions(+)
> 
> diff --git a/drivers/edac/versalnet_edac.c b/drivers/edac/versalnet_edac.c
> index e9561242f292..baca90f44c58 100644
> --- a/drivers/edac/versalnet_edac.c
> +++ b/drivers/edac/versalnet_edac.c
> @@ -602,6 +602,9 @@ static int rpmsg_cb(struct rpmsg_device *rpdev, void *data,
>   	length = result[MSG_ERR_LENGTH];
>   	offset = result[MSG_ERR_OFFSET];
>   
> +	if (offset + length > REG_MAX)
> +		return -EINVAL;
> +

Nit - Integer overflow on offset + length

>   	/*
>   	 * The data can come in two stretches. Construct the regs from two
>   	 * messages. The offset indicates the offset from which the data is to


  reply	other threads:[~2026-07-31 13:56 UTC|newest]

Thread overview: 25+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-07-24 17:19 [PATCH 0/9] EDAC/versalnet: Fix error handling, teardown, and robustness Shubhrajyoti Datta
2026-07-24 17:19 ` [PATCH 1/9] EDAC/versalnet: Add NULL check for mci in handle_error() Shubhrajyoti Datta
2026-07-26 23:52   ` Borislav Petkov
2026-07-27  6:48     ` Pandey, Radhey Shyam
2026-07-28  1:37       ` Borislav Petkov
2026-07-28 18:27         ` Pandey, Radhey Shyam
2026-07-28 21:33           ` Borislav Petkov
2026-07-29 16:40             ` Pandey, Radhey Shyam
2026-07-30 15:03               ` Shubhrajyoti Datta
2026-07-24 17:19 ` [PATCH 2/9] EDAC/versalnet: Add NULL check for mci in remove_one_mc() Shubhrajyoti Datta
2026-07-27  8:11   ` Pandey, Radhey Shyam
2026-07-24 17:19 ` [PATCH 3/9] EDAC/versalnet: Move platform_set_drvdata() to mc_probe() Shubhrajyoti Datta
2026-07-27  8:35   ` Pandey, Radhey Shyam
2026-07-24 17:19 ` [PATCH 4/9] EDAC/versalnet: Fix device_register() error handling in init_one_mc() Shubhrajyoti Datta
2026-07-31 11:01   ` Pandey, Radhey Shyam
2026-07-24 17:19 ` [PATCH 5/9] EDAC/versalnet: Use dev_set_name() instead of sprintf with init_name Shubhrajyoti Datta
2026-07-31 11:22   ` Pandey, Radhey Shyam
2026-07-24 17:19 ` [PATCH 6/9] EDAC/versalnet: Initialize MCDI before RPMsg registration Shubhrajyoti Datta
2026-07-31 11:41   ` Pandey, Radhey Shyam
2026-07-24 17:19 ` [PATCH 7/9] EDAC/versalnet: Add bounds validation in rpmsg_cb() Shubhrajyoti Datta
2026-07-31 13:56   ` Pandey, Radhey Shyam [this message]
2026-07-24 17:19 ` [PATCH 8/9] EDAC/versalnet: Fix use-after-free in remove_one_mc() Shubhrajyoti Datta
2026-07-31 14:06   ` Pandey, Radhey Shyam
2026-07-24 17:19 ` [PATCH 9/9] EDAC/versalnet: Use designated initializer for rpmsg_channel_info Shubhrajyoti Datta
2026-07-31 14:26   ` Pandey, Radhey Shyam

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=4b17c6da-3eba-4591-910f-9fe26b4d422c@amd.com \
    --to=radheys@amd.com \
    --cc=bp@alien8.de \
    --cc=git@amd.com \
    --cc=linux-edac@vger.kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=michal.simek@amd.com \
    --cc=shubhrajyoti.datta@amd.com \
    --cc=shubhrajyoti.datta@gmail.com \
    --cc=tony.luck@intel.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.