From: Jarkko Sakkinen <jarkko@kernel.org>
To: Yuqi Xu <xuyuqiabc@gmail.com>
Cc: linux-integrity@vger.kernel.org, Peter Huewe <peterhuewe@gmx.de>,
Jason Gunthorpe <jgg@ziepe.ca>,
stable@vger.kernel.org, Vega <vega@nebusec.ai>,
Ren Wei <weir@nebusec.ai>,
xuyq21@lenovo.com
Subject: Re: [PATCH 1/1] tpm: ignore duplicate PCR banks in tpm2_get_pcr_allocation
Date: Fri, 25 Sep 2026 14:53:55 +0300 [thread overview]
Message-ID: <arZg081NHaBL4O5G@kernel.org> (raw)
In-Reply-To: <85b8cbb1985c743325d57e05d51d8814d3c56549.1789800840.git.xuyuqiabc@gmail.com>
On Sat, Sep 19, 2026 at 04:47:00PM +0800, Yuqi Xu wrote:
> The TPM2_CAP_PCRS response is external input and may contain duplicate
> hash algorithms. tpm2_get_pcr_allocation() adds every active selection
> to allocated_banks, while tpm_sysfs_add_device() has one group slot per
> distinct hash algorithm. Eight duplicate selections can therefore make
> it write past chip->groups[].
>
> Keep allocated_banks unique by ignoring duplicate hash algorithms while
> parsing the response.
>
> Fixes: aab73d952402 ("tpm: add sysfs exports for all banks of PCR registers")
> Cc: stable@vger.kernel.org
> Reported-by: Vega <vega@nebusec.ai>
> Assisted-by: LLM
> Signed-off-by: Yuqi Xu <xuyuqiabc@gmail.com>
> Reviewed-by: Ren Wei <weir@nebusec.ai>
> ---
It may not contain duplicates as per protocol spec i.e., instead of
silently ignoring the error -EIO should be returned. TPM should not
be enabled if it is compromised.
> drivers/char/tpm/tpm2-cmd.c | 18 +++++++++++++-----
> 1 file changed, 13 insertions(+), 5 deletions(-)
>
> diff --git a/drivers/char/tpm/tpm2-cmd.c b/drivers/char/tpm/tpm2-cmd.c
> index ae22295df798..99e9d89b18e1 100644
> --- a/drivers/char/tpm/tpm2-cmd.c
> +++ b/drivers/char/tpm/tpm2-cmd.c
> @@ -527,6 +527,7 @@ ssize_t tpm2_get_pcr_allocation(struct tpm_chip *chip)
> u32 rsp_len;
> int rc;
> int i = 0;
> + int j;
>
> struct tpm_buf *buf __free(kfree) = kzalloc(TPM_BUFSIZE, GFP_KERNEL);
> if (!buf)
> @@ -569,13 +570,20 @@ ssize_t tpm2_get_pcr_allocation(struct tpm_chip *chip)
> pcr_select_offset = memchr_inv(pcr_selection.pcr_select, 0,
> pcr_selection.size_of_select);
> if (pcr_select_offset) {
> - chip->allocated_banks[nr_alloc_banks].alg_id = hash_alg;
> + for (j = 0; j < nr_alloc_banks; j++) {
> + if (chip->allocated_banks[j].alg_id == hash_alg)
> + break;
> + }
>
> - rc = tpm2_init_bank_info(chip, nr_alloc_banks);
> - if (rc < 0)
> - break;
> + if (j == nr_alloc_banks) {
> + chip->allocated_banks[nr_alloc_banks].alg_id = hash_alg;
>
> - nr_alloc_banks++;
> + rc = tpm2_init_bank_info(chip, nr_alloc_banks);
> + if (rc < 0)
> + break;
> +
> + nr_alloc_banks++;
> + }
> }
>
> sizeof_pcr_selection = sizeof(pcr_selection.hash_alg) +
> --
> 2.55.0
>
Br, Jarkko
prev parent reply other threads:[~2026-09-25 11:53 UTC|newest]
Thread overview: 4+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-19 8:46 [PATCH 0/1] tpm: ignore duplicate PCR banks in tpm2_get_pcr_allocation Yuqi Xu
2026-09-19 8:47 ` [PATCH 1/1] " Yuqi Xu
2026-09-20 7:34 ` Yuqi Xu
2026-09-25 11:53 ` Jarkko Sakkinen [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=arZg081NHaBL4O5G@kernel.org \
--to=jarkko@kernel.org \
--cc=jgg@ziepe.ca \
--cc=linux-integrity@vger.kernel.org \
--cc=peterhuewe@gmx.de \
--cc=stable@vger.kernel.org \
--cc=vega@nebusec.ai \
--cc=weir@nebusec.ai \
--cc=xuyq21@lenovo.com \
--cc=xuyuqiabc@gmail.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.