Linux cryptographic layer development
 help / color / mirror / Atom feed
From: Herbert Xu <herbert@gondor.apana.org.au>
To: Aldo Ariel Panzardo <qwe.aldo@gmail.com>
Cc: haren@us.ibm.com, linux-crypto@vger.kernel.org,
	linux-kernel@vger.kernel.org, stable@vger.kernel.org,
	Vishal Chourasia <vishalc@linux.ibm.com>,
	Michael Ellerman <mpe@ellerman.id.au>
Subject: Re: [PATCH] crypto: nx - validate 'ignore' before subtracting in decompress
Date: Fri, 2 Oct 2026 18:07:12 +1000	[thread overview]
Message-ID: <ar9mMJaWd7kbZDiL@gondor.apana.org.au> (raw)
In-Reply-To: <20260925175839.3704942-1-qwe.aldo@gmail.com>

On Fri, Sep 25, 2026 at 02:58:39PM -0300, Aldo Ariel Panzardo wrote:
> The decompress() function subtracts the header-supplied `ignore` value
> (a u16 from the compressed stream) from `dlen` (the number of bytes
> produced by the decompressor) without checking that ignore <= dlen.
> 
> If a caller decompresses a crafted buffer where `hdr->ignore` exceeds
> the actual decompressed length, the subtraction wraps around to a
> near-UINT_MAX value.  The subsequent memcpy() then copies gigabytes of
> data past the destination buffer, causing an out-of-bounds kernel write.
> 
> Add a bounds check before the subtraction and return -EINVAL if the
> value is inconsistent.
> 
> Cc: stable@vger.kernel.org
> Signed-off-by: Aldo Ariel Panzardo <qwe.aldo@gmail.com>
> ---
>  drivers/crypto/nx/nx-842.c | 3 +++
>  1 file changed, 3 insertions(+)

Thanks for the fix!

I think a bigger problem is that this hardware is accepting input
that cannot be processed by the software fallback since it has no
handling of NX842_CRYPTO_MAGIC.

The whole point of having the software implementation is to be able
to decompress the output of the hardware.

I'm not sure who is maintaining this currently.  Vishal, do we
still need the 842 algorithm? Could we fix the software fallback
so that it can handle the same input as the hardware driver?

Cheers,
-- 
Email: Herbert Xu <herbert@gondor.apana.org.au>
Home Page: http://gondor.apana.org.au/~herbert/
PGP Key: http://gondor.apana.org.au/~herbert/pubkey.txt

  reply	other threads:[~2026-10-02  8:07 UTC|newest]

Thread overview: 3+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-25 17:58 [PATCH] crypto: nx - validate 'ignore' before subtracting in decompress Aldo Ariel Panzardo
2026-10-02  8:07 ` Herbert Xu [this message]
2026-10-02 10:15 ` Herbert Xu

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=ar9mMJaWd7kbZDiL@gondor.apana.org.au \
    --to=herbert@gondor.apana.org.au \
    --cc=haren@us.ibm.com \
    --cc=linux-crypto@vger.kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=mpe@ellerman.id.au \
    --cc=qwe.aldo@gmail.com \
    --cc=stable@vger.kernel.org \
    --cc=vishalc@linux.ibm.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox