* [PATCH 0/2] remoteproc: mtk_scp: Fix bounds checks in da_to_va callbacks
@ 2026-10-05 11:25 Atul Akella
2026-10-05 11:25 ` [PATCH 1/2] remoteproc: mtk_scp: Fix bounds check in mt8183_scp_da_to_va() Atul Akella
2026-10-05 11:25 ` [PATCH 2/2] remoteproc: mtk_scp: Fix bounds check in mt8192_scp_da_to_va() Atul Akella
0 siblings, 2 replies; 3+ messages in thread
From: Atul Akella @ 2026-10-05 11:25 UTC (permalink / raw)
To: linux-remoteproc; +Cc: Atul Akella
mt8183_scp_da_to_va() and mt8192_scp_da_to_va() validate the device
address and length that the ELF loader passes in from the firmware's
program headers. Both checks can be bypassed through integer truncation
or wraparound. These two patches fix them with overflow-safe comparisons.
The fixes have different origin commits, so they are split for stable
backporting.
Compile tested only (arm64 defconfig, W=1). Not tested on hardware.
Atul Akella (2):
remoteproc: mtk_scp: Fix bounds check in mt8183_scp_da_to_va()
remoteproc: mtk_scp: Fix bounds check in mt8192_scp_da_to_va()
drivers/remoteproc/mtk_scp.c | 32 +++++++++++++++++---------------
1 file changed, 17 insertions(+), 15 deletions(-)
--
2.43.0
^ permalink raw reply [flat|nested] 3+ messages in thread
* [PATCH 1/2] remoteproc: mtk_scp: Fix bounds check in mt8183_scp_da_to_va()
2026-10-05 11:25 [PATCH 0/2] remoteproc: mtk_scp: Fix bounds checks in da_to_va callbacks Atul Akella
@ 2026-10-05 11:25 ` Atul Akella
2026-10-05 11:25 ` [PATCH 2/2] remoteproc: mtk_scp: Fix bounds check in mt8192_scp_da_to_va() Atul Akella
1 sibling, 0 replies; 3+ messages in thread
From: Atul Akella @ 2026-10-05 11:25 UTC (permalink / raw)
To: linux-remoteproc
Cc: Atul Akella, stable, Bjorn Andersson, Mathieu Poirier,
Matthias Brugger, AngeloGioacchino Del Regno, Pi-Hsun Shih,
Nicolas Boichat, Erin Lo, linux-kernel, linux-arm-kernel,
linux-mediatek
mt8183_scp_da_to_va() translates a device address to a pointer into
SCP SRAM or DRAM. Its bounds check is wrong in two ways:
- offset is an int but is assigned from a u64. For the DRAM window,
da = dma_addr + 0x100000010 is truncated to offset 0x10 and passes
the check. There is also no da >= dma_addr check, so a da below
dma_addr wraps in the u64 subtraction and can truncate to a small
positive offset.
- (offset + len) is computed in size_t and wraps for a large len.
With offset = 0x100 and len = (size_t)-0x80, the sum is 0x80 and
the check passes.
da and len come from the firmware's ELF program headers
(p_paddr/p_memsz) via rproc_da_to_va(), and the returned pointer is
then written to by the ELF loader, so a malformed firmware image can
make the loader write outside the intended region.
Use a u64 offset, check da >= dma_addr before subtracting, and
compare len against the remaining window size instead of adding it
to offset.
Fixes: 63c13d61eafe ("remoteproc/mediatek: add SCP support for mt8183")
Cc: stable@vger.kernel.org
Signed-off-by: Atul Akella <atul.akella@gmail.com>
---
drivers/remoteproc/mtk_scp.c | 8 +++++---
1 file changed, 5 insertions(+), 3 deletions(-)
diff --git a/drivers/remoteproc/mtk_scp.c b/drivers/remoteproc/mtk_scp.c
index 9751acc2bf83..d18ae676260a 100644
--- a/drivers/remoteproc/mtk_scp.c
+++ b/drivers/remoteproc/mtk_scp.c
@@ -754,17 +754,19 @@ static int scp_start(struct rproc *rproc)
static void *mt8183_scp_da_to_va(struct mtk_scp *scp, u64 da, size_t len)
{
- int offset;
+ u64 offset;
const struct mtk_scp_sizes_data *scp_sizes;
scp_sizes = scp->data->scp_sizes;
if (da < scp->sram_size) {
offset = da;
- if (offset >= 0 && (offset + len) <= scp->sram_size)
+ if (len <= scp->sram_size - offset)
return (void __force *)scp->sram_base + offset;
} else if (scp_sizes->max_dram_size) {
offset = da - scp->dma_addr;
- if (offset >= 0 && (offset + len) <= scp_sizes->max_dram_size)
+ if (da >= scp->dma_addr &&
+ offset <= scp_sizes->max_dram_size &&
+ len <= scp_sizes->max_dram_size - offset)
return scp->cpu_addr + offset;
}
--
2.43.0
^ permalink raw reply related [flat|nested] 3+ messages in thread
* [PATCH 2/2] remoteproc: mtk_scp: Fix bounds check in mt8192_scp_da_to_va()
2026-10-05 11:25 [PATCH 0/2] remoteproc: mtk_scp: Fix bounds checks in da_to_va callbacks Atul Akella
2026-10-05 11:25 ` [PATCH 1/2] remoteproc: mtk_scp: Fix bounds check in mt8183_scp_da_to_va() Atul Akella
@ 2026-10-05 11:25 ` Atul Akella
1 sibling, 0 replies; 3+ messages in thread
From: Atul Akella @ 2026-10-05 11:25 UTC (permalink / raw)
To: linux-remoteproc
Cc: Atul Akella, stable, Bjorn Andersson, Mathieu Poirier,
Matthias Brugger, AngeloGioacchino Del Regno, Tzung-Bi Shih,
linux-kernel, linux-arm-kernel, linux-mediatek
mt8192_scp_da_to_va() translates a device address to a pointer into
SCP SRAM, L1TCM or DRAM. Its bounds checks have two problems:
- (da + len) is computed in u64 and wraps for a large da or len.
With da = 0xfffffffffffffff0 and len = 0x20, the sum is 0x10 and
passes "<= base + size" while da >= base also holds.
- offset is an int but is assigned from a u64 difference, so it is
truncated before being added to the region's base pointer.
da and len come from the firmware's ELF program headers
(p_paddr/p_memsz) via rproc_da_to_va(), and the returned pointer is
then written to by the ELF loader, so a malformed firmware image can
make the loader write outside the intended region.
Use a u64 offset and compare len against the remaining region size
instead of adding it to da. Apply this to the SRAM, L1TCM and DRAM
regions.
Fixes: ca23ecfdbd44 ("remoteproc/mediatek: support L1TCM")
Cc: stable@vger.kernel.org
Signed-off-by: Atul Akella <atul.akella@gmail.com>
---
drivers/remoteproc/mtk_scp.c | 24 ++++++++++++------------
1 file changed, 12 insertions(+), 12 deletions(-)
diff --git a/drivers/remoteproc/mtk_scp.c b/drivers/remoteproc/mtk_scp.c
index d18ae676260a..b1d83265fc26 100644
--- a/drivers/remoteproc/mtk_scp.c
+++ b/drivers/remoteproc/mtk_scp.c
@@ -775,30 +775,30 @@ static void *mt8183_scp_da_to_va(struct mtk_scp *scp, u64 da, size_t len)
static void *mt8192_scp_da_to_va(struct mtk_scp *scp, u64 da, size_t len)
{
- int offset;
+ u64 offset;
const struct mtk_scp_sizes_data *scp_sizes;
scp_sizes = scp->data->scp_sizes;
- if (da >= scp->sram_phys &&
- (da + len) <= scp->sram_phys + scp->sram_size) {
+ if (da >= scp->sram_phys) {
offset = da - scp->sram_phys;
- return (void __force *)scp->sram_base + offset;
+ if (offset <= scp->sram_size && len <= scp->sram_size - offset)
+ return (void __force *)scp->sram_base + offset;
}
/* optional memory region */
- if (scp->cluster->l1tcm_size &&
- da >= scp->cluster->l1tcm_phys &&
- (da + len) <= scp->cluster->l1tcm_phys + scp->cluster->l1tcm_size) {
+ if (scp->cluster->l1tcm_size && da >= scp->cluster->l1tcm_phys) {
offset = da - scp->cluster->l1tcm_phys;
- return (void __force *)scp->cluster->l1tcm_base + offset;
+ if (offset <= scp->cluster->l1tcm_size &&
+ len <= scp->cluster->l1tcm_size - offset)
+ return (void __force *)scp->cluster->l1tcm_base + offset;
}
/* optional memory region */
- if (scp_sizes->max_dram_size &&
- da >= scp->dma_addr &&
- (da + len) <= scp->dma_addr + scp_sizes->max_dram_size) {
+ if (scp_sizes->max_dram_size && da >= scp->dma_addr) {
offset = da - scp->dma_addr;
- return scp->cpu_addr + offset;
+ if (offset <= scp_sizes->max_dram_size &&
+ len <= scp_sizes->max_dram_size - offset)
+ return scp->cpu_addr + offset;
}
return NULL;
--
2.43.0
^ permalink raw reply related [flat|nested] 3+ messages in thread
end of thread, other threads:[~2026-10-05 11:26 UTC | newest]
Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-10-05 11:25 [PATCH 0/2] remoteproc: mtk_scp: Fix bounds checks in da_to_va callbacks Atul Akella
2026-10-05 11:25 ` [PATCH 1/2] remoteproc: mtk_scp: Fix bounds check in mt8183_scp_da_to_va() Atul Akella
2026-10-05 11:25 ` [PATCH 2/2] remoteproc: mtk_scp: Fix bounds check in mt8192_scp_da_to_va() Atul Akella
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox