All of lore.kernel.org
 help / color / mirror / Atom feed
From: Breno Leitao <leitao@debian.org>
To: sashiko-reviews@lists.linux.dev
Cc: Ilias Apalodimas <ilias.apalodimas@linaro.org>,
	 Michal Hocko <mhocko@suse.com>,
	Naoya Horiguchi <nao.horiguchi@gmail.com>,
	 Andrew Morton <akpm@linux-foundation.org>,
	kas@kernel.org, Vlastimil Babka <vbabka@kernel.org>,
	 x86@kernel.org, "H. Peter Anvin" <hpa@zytor.com>,
	 David Hildenbrand <david@kernel.org>,
	"Liam R. Howlett" <liam@infradead.org>,
	 Brendan Jackman <brendan.jackman@linux.dev>,
	Johannes Weiner <hannes@cmpxchg.org>,
	 Borislav Petkov <bp@alien8.de>,
	Suren Baghdasaryan <surenb@google.com>,
	 Ard Biesheuvel <ardb@kernel.org>,
	Lorenzo Stoakes <ljs@kernel.org>,
	 Mike Rapoport <rppt@kernel.org>,
	Miaohe Lin <linmiaohe@huawei.com>,
	 Ingo Molnar <mingo@redhat.com>,
	Dave Hansen <dave.hansen@linux.intel.com>,
	 Zi Yan <ziy@nvidia.com>, Thomas Gleixner <tglx@kernel.org>,
	kernel-team@meta.com,  rmikey@meta.com, harry@kernel.org,
	linux-efi@vger.kernel.org, riel@surriel.com,
	 linux-kernel@vger.kernel.org, linux-mm@kvack.org,
	kexec@lists.infradead.org
Subject: Re: [PATCH v4 3/5] mm/memory-failure: efi: record hardware-poisoned frames into the poisoned-memory table
Date: Wed, 9 Sep 2026 07:05:57 -0700	[thread overview]
Message-ID: <aqFm1ep0mIlJpA-d@gmail.com> (raw)
In-Reply-To: <20260909132128.AD4D01F00A3A@smtp.kernel.org>

On Wed, Sep 09, 2026 at 01:21:28PM +0000, sashiko-bot@kernel.org wrote:
> > --- /dev/null
> > +++ b/drivers/firmware/efi/poison.c
> >
> > +	/* Whole words, and a bit count that can be taken without wrapping. */
> > +	if (!pm->size || !IS_ALIGNED(pm->size, sizeof(unsigned long)) ||
> > +	    check_mul_overflow(pm->size, (u64)BITS_PER_BYTE, &nbits))
> > +		return false;
> 
> [Severity: High]
> Does this validation fully protect against an excessively large pm->size?

I was clamping the table before, but we decided to drop it in the last
revision. See the discusion in here:

https://lore.kernel.org/all/apGWUWi5-RbhFHpe@thinkstation/

> > +	start = PAGE_ALIGN_DOWN(efi.poisoned_memory);
> > +	end = PAGE_ALIGN(efi.poisoned_memory + sizeof(*pm) + pm->size);
> 
> [Severity: High]
> Can this computation wrap around if pm->size is maliciously large?

Yes, but that means that someone was able to write to EFI memory to
update size?

I can definitely BUG_ON() on "large"  pm->size, but, I don't think this
is what we want here.


  reply	other threads:[~2026-09-09 14:06 UTC|newest]

Thread overview: 15+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-09 13:05 [PATCH v4 0/5] mm/memory-failure: keep hardware-poisoned pages out of the next kexec Breno Leitao
2026-09-09 13:05 ` [PATCH v4 1/5] mm/memory-failure: efi: add the LINUX_EFI_POISONED_MEMORY configuration table Breno Leitao
2026-09-09 13:13   ` sashiko-bot
2026-09-09 13:05 ` [PATCH v4 2/5] mm/memory-failure: libstub: install the poisoned-memory EFI table Breno Leitao
2026-09-09 13:19   ` sashiko-bot
2026-09-09 14:00     ` Breno Leitao
2026-09-09 14:47   ` Ard Biesheuvel
2026-09-10 13:11     ` Breno Leitao
2026-09-09 13:05 ` [PATCH v4 3/5] mm/memory-failure: efi: record hardware-poisoned frames into the poisoned-memory table Breno Leitao
2026-09-09 13:21   ` sashiko-bot
2026-09-09 14:05     ` Breno Leitao [this message]
2026-09-09 13:05 ` [PATCH v4 4/5] mm/memory-failure: efi: answer whether a range is poisoned Breno Leitao
2026-09-09 13:17   ` sashiko-bot
2026-09-09 13:05 ` [PATCH v4 5/5] mm/memory-failure: keep inherited poisoned frames out of the buddy allocator Breno Leitao
2026-09-09 13:24   ` sashiko-bot

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=aqFm1ep0mIlJpA-d@gmail.com \
    --to=leitao@debian.org \
    --cc=akpm@linux-foundation.org \
    --cc=ardb@kernel.org \
    --cc=bp@alien8.de \
    --cc=brendan.jackman@linux.dev \
    --cc=dave.hansen@linux.intel.com \
    --cc=david@kernel.org \
    --cc=hannes@cmpxchg.org \
    --cc=harry@kernel.org \
    --cc=hpa@zytor.com \
    --cc=ilias.apalodimas@linaro.org \
    --cc=kas@kernel.org \
    --cc=kernel-team@meta.com \
    --cc=kexec@lists.infradead.org \
    --cc=liam@infradead.org \
    --cc=linmiaohe@huawei.com \
    --cc=linux-efi@vger.kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-mm@kvack.org \
    --cc=ljs@kernel.org \
    --cc=mhocko@suse.com \
    --cc=mingo@redhat.com \
    --cc=nao.horiguchi@gmail.com \
    --cc=riel@surriel.com \
    --cc=rmikey@meta.com \
    --cc=rppt@kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    --cc=surenb@google.com \
    --cc=tglx@kernel.org \
    --cc=vbabka@kernel.org \
    --cc=x86@kernel.org \
    --cc=ziy@nvidia.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.