From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from bombadil.infradead.org (bombadil.infradead.org [198.137.202.133]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.lore.kernel.org (Postfix) with ESMTPS id E1E43C25B4F for ; Mon, 13 May 2024 00:46:29 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=lists.infradead.org; s=bombadil.20210309; h=Sender: Content-Transfer-Encoding:Content-Type:List-Subscribe:List-Help:List-Post: List-Archive:List-Unsubscribe:List-Id:MIME-Version:Message-Id:Date:Subject:Cc :To:From:Reply-To:Content-ID:Content-Description:Resent-Date:Resent-From: Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:In-Reply-To:References: List-Owner; bh=ogzgJqoS5NdMxJXZwYLQo8NoMG4TkATCD9jCwWsNWzQ=; b=IElEPffu7k1uGa QNPoWxcoX+6cAe9qQ8Nh+0wRtMxcqc5+l6yLiB5QVil0duCnoUwBE3UzBuPMGo81oVr5DkhDVSRVk 1nZVxQFxaTCb86IQBnA6SeCW1D+jeyddKUmGhqG+E3OpJaNRA/NldqnhTzRiZdgzuZY6G9Dr+exxP BLLXWS9Ue3U1zHyyE9ZtqClc5vPcV4lJSa1HkSWrpOGyXTLzmvc/l76HoDKpOJiykcdKuPxRRFc2x mMZsNIMKfc3jvnFbZ+MDDrkHFHtvsLwkYjPRS0A0dzWBO3ZuZWySCteoYVs0VwOqERdUpRgVw/KfG AH7h6bgRvAQXkSOAMEWQ==; Received: from localhost ([::1] helo=bombadil.infradead.org) by bombadil.infradead.org with esmtp (Exim 4.97.1 #2 (Red Hat Linux)) id 1s6JpX-0000000BBpc-2Fy5; Mon, 13 May 2024 00:46:15 +0000 Received: from gw2.atmark-techno.com ([35.74.137.57]) by bombadil.infradead.org with esmtps (Exim 4.97.1 #2 (Red Hat Linux)) id 1s6JpU-0000000BBp5-1sRr for linux-arm-kernel@lists.infradead.org; Mon, 13 May 2024 00:46:14 +0000 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=atmark-techno.com; s=gw2_bookworm; t=1715560725; bh=U3HjDiAxMJF9563uzlVT7VbJu7d0dpUtMdwb2XVFRSE=; h=From:To:Cc:Subject:Date:From; b=CQtZhS1K8uqJ13zOLgmNtlN+yK6W+eAVshedhed4p6vgDVQ/ALOiA+UIlDMIZxLGK vBIdZ7MMZ/EnJfcVNB6oCqCamy4HbQTsTKJc2VEBJNwfS9cdjGWXMEilTBrRgpG2e+ 1TY5NABigKfQAFCmZtidQIKDlGl48ySi9cUDDx2A9MJI3M63A03Z5A0YojpELljH4E 3jEuXlJZwtXtIDOvafaert5KMbNXB/YlK2wUBvXQuT89lWR1BWMAlLb6oDHASmxwvE sBSh1rhPC8qyClZPWcQdqkXu+YxksjCNF27iKNHvr7lX4ouwjNpz9T/R8KAMcpC/BH IF9Had3dJCA3w== Received: from gw2.atmark-techno.com (localhost [127.0.0.1]) by gw2.atmark-techno.com (Postfix) with ESMTP id CA55323C for ; Mon, 13 May 2024 09:38:45 +0900 (JST) Authentication-Results: gw2.atmark-techno.com; dkim=pass (2048-bit key; unprotected) header.d=atmark-techno.com header.i=@atmark-techno.com header.a=rsa-sha256 header.s=google header.b=Mnx28FdC; dkim-atps=neutral Received: from mail-oa1-f72.google.com (mail-oa1-f72.google.com [209.85.160.72]) by gw2.atmark-techno.com (Postfix) with ESMTPS id 5F95923C for ; Mon, 13 May 2024 09:38:45 +0900 (JST) Received: by mail-oa1-f72.google.com with SMTP id 586e51a60fabf-23e636fc175so4253551fac.0 for ; Sun, 12 May 2024 17:38:45 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=atmark-techno.com; s=google; t=1715560724; x=1716165524; darn=lists.infradead.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to; bh=HsIEASF3QaB3IZhi8DmVvGv/jkEBuLOkXdFEV40N6Z4=; b=Mnx28FdCAZOoKVpt9CV51+34ASvthubNL67R4I5peklr/ff2sfwsLcguiHtb9R1UWD cn6UIIR9HDHhNYfsnREWGTQKmPxV5qXER8kcSoFAB16YcdHHmxYsRXFykL4mNHxfpo9y GxkcZCs4o9WCRuqo6eecPQs29qyYWGA9yCGpFDJsS6CoyVVXQiEkv+c3hkQdn7epuFuE ejWc2HZPKdeQi22J3zX0+cZDOnY2s47kr72XQEsRyG66aj0ACApAou+CaFPO5X8z7iEi RFrN0oeFFLJuuoMzRJQ61TF/8I7Tygr8JL3s+eCfAQcvnqdpbeZ02w+44QzdLgE7GiRL S6hA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1715560724; x=1716165524; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to; bh=HsIEASF3QaB3IZhi8DmVvGv/jkEBuLOkXdFEV40N6Z4=; b=EMHD+OkDkL/PLB9sVkLnFF593R4oxO8a44YD3/CZh4G0RGk98j4tw+bCj9xv+wD3Ko kSDKH8LgPUBCiOVVyFPZulI1404wTjpawmieCOqEiCc9oxgG8lT+ScnPNuSIBBY0fQiV ZhD7837u4KalLXNUMlT32ieMEzNh3Yg6juMnYigD9dXSIVMPoGH5kp5TFh6sgZthRSeV /7QZ8Qhq+zMaiFEGAJdnadjlqJ+Xob2Q3jNwLAHTVes3N6jEp2SO9YV6r27D5PRqss00 6nHyEenaYoByPppd9wacBguBCrf8Pb0agJE9cyrlTgQSWC5qwNxA4qxCBz+dsQNpkYX/ lEgg== X-Forwarded-Encrypted: i=1; AJvYcCUo/J08dQuTgffYQLO7g9FYQ1f6ntAwa70pZPD4/dVIaTxpM9fOtdESqsLQ8CQqAe/W+dVl9cIKtBMCHM8lDFe8a7nDXKmCGN9tWZiW+VY3oW21G94= X-Gm-Message-State: AOJu0YyNtLaEhZCEkIl3TZzXrNtcBtYt4Fv6NWow5iW3j5XtKycj2oAP R9KwOlBHwr3ZsJMddN4KVL+yKRFKqs81Ts5+jRajvy5sdT1/QQEGn4IN2u6KSIIBDLL5mmGD7pA TkGig1cw9MpYt8nLhJ3cgd5cNTpC/FG190Ug7vioE1nahgLvDceVk23PfD3QFsxACMmOAMRguAg == X-Received: by 2002:a05:6870:d285:b0:229:f988:4305 with SMTP id 586e51a60fabf-241728f4b15mr11061015fac.10.1715560723633; Sun, 12 May 2024 17:38:43 -0700 (PDT) X-Google-Smtp-Source: AGHT+IEuRMyXUQmsEKNt7ZKzSLAVq04d2IqNYnUdmXANU1/K7UrBHCWFXccsCvmTKAaos8llpWIz5w== X-Received: by 2002:a05:6870:d285:b0:229:f988:4305 with SMTP id 586e51a60fabf-241728f4b15mr11060984fac.10.1715560722466; Sun, 12 May 2024 17:38:42 -0700 (PDT) Received: from pc-0182.atmarktech (178.101.200.35.bc.googleusercontent.com. [35.200.101.178]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-6f4d2af2969sm6179487b3a.152.2024.05.12.17.38.42 (version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128); Sun, 12 May 2024 17:38:42 -0700 (PDT) Received: from [::1] (helo=pc-0182.atmark.tech) by pc-0182.atmarktech with esmtp (Exim 4.96) (envelope-from ) id 1s6JiC-003OuB-17; Mon, 13 May 2024 09:38:40 +0900 From: Dominique Martinet To: Greg Kroah-Hartman , stable@vger.kernel.org Cc: linux-kernel@vger.kernel.org, linux-arm-kernel@lists.infradead.org, Cristian Marussi , sudeep.holla@arm.com, Dominique Martinet Subject: [PATCH 5.4 / 5.10] firmware: arm_scmi: Harden accesses to the reset domains Date: Mon, 13 May 2024 09:38:37 +0900 Message-Id: <20240513003837.810709-1-dominique.martinet@atmark-techno.com> X-Mailer: git-send-email 2.39.2 MIME-Version: 1.0 X-CRM114-Version: 20100106-BlameMichelson ( TRE 0.8.0 (BSD) ) MR-646709E3 X-CRM114-CacheID: sfid-20240512_174612_676256_FD52C637 X-CRM114-Status: GOOD ( 16.44 ) X-BeenThere: linux-arm-kernel@lists.infradead.org X-Mailman-Version: 2.1.34 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit Sender: "linux-arm-kernel" Errors-To: linux-arm-kernel-bounces+linux-arm-kernel=archiver.kernel.org@lists.infradead.org From: Cristian Marussi [ Upstream commit e9076ffbcaed5da6c182b144ef9f6e24554af268 ] Accessing reset domains descriptors by the index upon the SCMI drivers requests through the SCMI reset operations interface can potentially lead to out-of-bound violations if the SCMI driver misbehave. Add an internal consistency check before any such domains descriptors accesses. Link: https://lore.kernel.org/r/20220817172731.1185305-5-cristian.marussi@arm.com Signed-off-by: Cristian Marussi Signed-off-by: Sudeep Holla Signed-off-by: Dominique Martinet --- This is the backport I promised for CVE-2022-48655[1] [1] https://lkml.kernel.org/r/Zj4t4q_w6gqzdvhz@codewreck.org The 'pi' variable declaration context just changed a bit (handle->reset_priv -> ph->get_priv(ph)) but the patch is otherwise fine as is. (I've also checked that num_domains is properly initialized at module init time and this part of the code hasn't changed until 5.15, so it should be safe to use this previously unused field) This same patch applies cleanly to both 5.4.275 and 5.10.216. Thanks! drivers/firmware/arm_scmi/reset.c | 6 +++++- 1 file changed, 5 insertions(+), 1 deletion(-) diff --git a/drivers/firmware/arm_scmi/reset.c b/drivers/firmware/arm_scmi/reset.c index a981a22cfe89..b8388a3b9c06 100644 --- a/drivers/firmware/arm_scmi/reset.c +++ b/drivers/firmware/arm_scmi/reset.c @@ -149,8 +149,12 @@ static int scmi_domain_reset(const struct scmi_handle *handle, u32 domain, struct scmi_xfer *t; struct scmi_msg_reset_domain_reset *dom; struct scmi_reset_info *pi = handle->reset_priv; - struct reset_dom_info *rdom = pi->dom_info + domain; + struct reset_dom_info *rdom; + if (domain >= pi->num_domains) + return -EINVAL; + + rdom = pi->dom_info + domain; if (rdom->async_reset) flags |= ASYNCHRONOUS_RESET; -- 2.39.2 _______________________________________________ linux-arm-kernel mailing list linux-arm-kernel@lists.infradead.org http://lists.infradead.org/mailman/listinfo/linux-arm-kernel