From: Breno Leitao <leitao@debian.org>
To: sashiko-reviews@lists.linux.dev
Cc: Ilias Apalodimas <ilias.apalodimas@linaro.org>,
Michal Hocko <mhocko@suse.com>,
Naoya Horiguchi <nao.horiguchi@gmail.com>,
Andrew Morton <akpm@linux-foundation.org>,
kas@kernel.org, Vlastimil Babka <vbabka@kernel.org>,
x86@kernel.org, "H. Peter Anvin" <hpa@zytor.com>,
David Hildenbrand <david@kernel.org>,
"Liam R. Howlett" <liam@infradead.org>,
Brendan Jackman <brendan.jackman@linux.dev>,
Johannes Weiner <hannes@cmpxchg.org>,
Borislav Petkov <bp@alien8.de>,
Suren Baghdasaryan <surenb@google.com>,
Ard Biesheuvel <ardb@kernel.org>,
Lorenzo Stoakes <ljs@kernel.org>,
Mike Rapoport <rppt@kernel.org>,
Miaohe Lin <linmiaohe@huawei.com>,
Ingo Molnar <mingo@redhat.com>,
Dave Hansen <dave.hansen@linux.intel.com>,
Zi Yan <ziy@nvidia.com>, Thomas Gleixner <tglx@kernel.org>,
kernel-team@meta.com, rmikey@meta.com, harry@kernel.org,
linux-efi@vger.kernel.org, riel@surriel.com,
linux-kernel@vger.kernel.org, linux-mm@kvack.org,
kexec@lists.infradead.org
Subject: Re: [PATCH v4 3/5] mm/memory-failure: efi: record hardware-poisoned frames into the poisoned-memory table
Date: Wed, 9 Sep 2026 07:05:57 -0700 [thread overview]
Message-ID: <aqFm1ep0mIlJpA-d@gmail.com> (raw)
In-Reply-To: <20260909132128.AD4D01F00A3A@smtp.kernel.org>
On Wed, Sep 09, 2026 at 01:21:28PM +0000, sashiko-bot@kernel.org wrote:
> > --- /dev/null
> > +++ b/drivers/firmware/efi/poison.c
> >
> > + /* Whole words, and a bit count that can be taken without wrapping. */
> > + if (!pm->size || !IS_ALIGNED(pm->size, sizeof(unsigned long)) ||
> > + check_mul_overflow(pm->size, (u64)BITS_PER_BYTE, &nbits))
> > + return false;
>
> [Severity: High]
> Does this validation fully protect against an excessively large pm->size?
I was clamping the table before, but we decided to drop it in the last
revision. See the discusion in here:
https://lore.kernel.org/all/apGWUWi5-RbhFHpe@thinkstation/
> > + start = PAGE_ALIGN_DOWN(efi.poisoned_memory);
> > + end = PAGE_ALIGN(efi.poisoned_memory + sizeof(*pm) + pm->size);
>
> [Severity: High]
> Can this computation wrap around if pm->size is maliciously large?
Yes, but that means that someone was able to write to EFI memory to
update size?
I can definitely BUG_ON() on "large" pm->size, but, I don't think this
is what we want here.
next prev parent reply other threads:[~2026-09-09 14:06 UTC|newest]
Thread overview: 15+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-09 13:05 [PATCH v4 0/5] mm/memory-failure: keep hardware-poisoned pages out of the next kexec Breno Leitao
2026-09-09 13:05 ` [PATCH v4 1/5] mm/memory-failure: efi: add the LINUX_EFI_POISONED_MEMORY configuration table Breno Leitao
2026-09-09 13:13 ` sashiko-bot
2026-09-09 13:05 ` [PATCH v4 2/5] mm/memory-failure: libstub: install the poisoned-memory EFI table Breno Leitao
2026-09-09 13:19 ` sashiko-bot
2026-09-09 14:00 ` Breno Leitao
2026-09-09 14:47 ` Ard Biesheuvel
2026-09-10 13:11 ` Breno Leitao
2026-09-09 13:05 ` [PATCH v4 3/5] mm/memory-failure: efi: record hardware-poisoned frames into the poisoned-memory table Breno Leitao
2026-09-09 13:21 ` sashiko-bot
2026-09-09 14:05 ` Breno Leitao [this message]
2026-09-09 13:05 ` [PATCH v4 4/5] mm/memory-failure: efi: answer whether a range is poisoned Breno Leitao
2026-09-09 13:17 ` sashiko-bot
2026-09-09 13:05 ` [PATCH v4 5/5] mm/memory-failure: keep inherited poisoned frames out of the buddy allocator Breno Leitao
2026-09-09 13:24 ` sashiko-bot
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=aqFm1ep0mIlJpA-d@gmail.com \
--to=leitao@debian.org \
--cc=akpm@linux-foundation.org \
--cc=ardb@kernel.org \
--cc=bp@alien8.de \
--cc=brendan.jackman@linux.dev \
--cc=dave.hansen@linux.intel.com \
--cc=david@kernel.org \
--cc=hannes@cmpxchg.org \
--cc=harry@kernel.org \
--cc=hpa@zytor.com \
--cc=ilias.apalodimas@linaro.org \
--cc=kas@kernel.org \
--cc=kernel-team@meta.com \
--cc=kexec@lists.infradead.org \
--cc=liam@infradead.org \
--cc=linmiaohe@huawei.com \
--cc=linux-efi@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-mm@kvack.org \
--cc=ljs@kernel.org \
--cc=mhocko@suse.com \
--cc=mingo@redhat.com \
--cc=nao.horiguchi@gmail.com \
--cc=riel@surriel.com \
--cc=rmikey@meta.com \
--cc=rppt@kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
--cc=surenb@google.com \
--cc=tglx@kernel.org \
--cc=vbabka@kernel.org \
--cc=x86@kernel.org \
--cc=ziy@nvidia.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.