All of lore.kernel.org
 help / color / mirror / Atom feed
From: Jarkko Sakkinen <jarkko@kernel.org>
To: Yuqi Xu <xuyuqiabc@gmail.com>
Cc: linux-integrity@vger.kernel.org, Peter Huewe <peterhuewe@gmx.de>,
	Jason Gunthorpe <jgg@ziepe.ca>,
	stable@vger.kernel.org, Vega <vega@nebusec.ai>,
	Ren Wei <weir@nebusec.ai>,
	xuyq21@lenovo.com
Subject: Re: [PATCH 1/1] tpm: ignore duplicate PCR banks in tpm2_get_pcr_allocation
Date: Fri, 25 Sep 2026 14:53:55 +0300	[thread overview]
Message-ID: <arZg081NHaBL4O5G@kernel.org> (raw)
In-Reply-To: <85b8cbb1985c743325d57e05d51d8814d3c56549.1789800840.git.xuyuqiabc@gmail.com>

On Sat, Sep 19, 2026 at 04:47:00PM +0800, Yuqi Xu wrote:
> The TPM2_CAP_PCRS response is external input and may contain duplicate
> hash algorithms.  tpm2_get_pcr_allocation() adds every active selection
> to allocated_banks, while tpm_sysfs_add_device() has one group slot per
> distinct hash algorithm.  Eight duplicate selections can therefore make
> it write past chip->groups[].
> 
> Keep allocated_banks unique by ignoring duplicate hash algorithms while
> parsing the response.
> 
> Fixes: aab73d952402 ("tpm: add sysfs exports for all banks of PCR registers")
> Cc: stable@vger.kernel.org
> Reported-by: Vega <vega@nebusec.ai>
> Assisted-by: LLM
> Signed-off-by: Yuqi Xu <xuyuqiabc@gmail.com>
> Reviewed-by: Ren Wei <weir@nebusec.ai>
> ---

It may not contain duplicates as per protocol spec i.e., instead of
silently ignoring the error -EIO should be returned. TPM should not
be enabled if it is compromised.

>  drivers/char/tpm/tpm2-cmd.c | 18 +++++++++++++-----
>  1 file changed, 13 insertions(+), 5 deletions(-)
> 
> diff --git a/drivers/char/tpm/tpm2-cmd.c b/drivers/char/tpm/tpm2-cmd.c
> index ae22295df798..99e9d89b18e1 100644
> --- a/drivers/char/tpm/tpm2-cmd.c
> +++ b/drivers/char/tpm/tpm2-cmd.c
> @@ -527,6 +527,7 @@ ssize_t tpm2_get_pcr_allocation(struct tpm_chip *chip)
>  	u32 rsp_len;
>  	int rc;
>  	int i = 0;
> +	int j;
>  
>  	struct tpm_buf *buf __free(kfree) = kzalloc(TPM_BUFSIZE, GFP_KERNEL);
>  	if (!buf)
> @@ -569,13 +570,20 @@ ssize_t tpm2_get_pcr_allocation(struct tpm_chip *chip)
>  		pcr_select_offset = memchr_inv(pcr_selection.pcr_select, 0,
>  					       pcr_selection.size_of_select);
>  		if (pcr_select_offset) {
> -			chip->allocated_banks[nr_alloc_banks].alg_id = hash_alg;
> +			for (j = 0; j < nr_alloc_banks; j++) {
> +				if (chip->allocated_banks[j].alg_id == hash_alg)
> +					break;
> +			}
>  
> -			rc = tpm2_init_bank_info(chip, nr_alloc_banks);
> -			if (rc < 0)
> -				break;
> +			if (j == nr_alloc_banks) {
> +				chip->allocated_banks[nr_alloc_banks].alg_id = hash_alg;
>  
> -			nr_alloc_banks++;
> +				rc = tpm2_init_bank_info(chip, nr_alloc_banks);
> +				if (rc < 0)
> +					break;
> +
> +				nr_alloc_banks++;
> +			}
>  		}
>  
>  		sizeof_pcr_selection = sizeof(pcr_selection.hash_alg) +
> -- 
> 2.55.0
> 

Br, Jarkko

      parent reply	other threads:[~2026-09-25 11:53 UTC|newest]

Thread overview: 4+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-19  8:46 [PATCH 0/1] tpm: ignore duplicate PCR banks in tpm2_get_pcr_allocation Yuqi Xu
2026-09-19  8:47 ` [PATCH 1/1] " Yuqi Xu
2026-09-20  7:34   ` Yuqi Xu
2026-09-25 11:53   ` Jarkko Sakkinen [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=arZg081NHaBL4O5G@kernel.org \
    --to=jarkko@kernel.org \
    --cc=jgg@ziepe.ca \
    --cc=linux-integrity@vger.kernel.org \
    --cc=peterhuewe@gmx.de \
    --cc=stable@vger.kernel.org \
    --cc=vega@nebusec.ai \
    --cc=weir@nebusec.ai \
    --cc=xuyq21@lenovo.com \
    --cc=xuyuqiabc@gmail.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.