public inbox for linux-sgx@vger.kernel.org
 help / color / mirror / Atom feed
* [PATCH] x86/sgx: Fix NULL pointer dereference on non-SGX systems
@ 2021-12-17 22:31 Dave Hansen
  2021-12-17 22:57 ` Nathan Chancellor
                   ` (2 more replies)
  0 siblings, 3 replies; 8+ messages in thread
From: Dave Hansen @ 2021-12-17 22:31 UTC (permalink / raw)
  To: dave; +Cc: Dave Hansen, nathan, gregkh, jarkko, linux-sgx, x86


From: Dave Hansen <dave.hansen@linux.intel.com>

Nathan Chancellor reported an oops when aceessing the
'sgx_total_bytes' sysfs file:

	https://lore.kernel.org/all/YbzhBrimHGGpddDM@archlinux-ax161/

The sysfs output code accesses the sgx_numa_nodes[] array
unconditionally.  However, this array is allocated during SGX
initialization, which only occurs on systems where SGX is
supported.

If the sysfs file is accessed on systems without SGX support,
sgx_numa_nodes[] is NULL and an oops occurs.

Add a check to ensure that SGX has been initialized to the point
where sgx_numa_nodes[] is allocated, before accessing it.

Reported-by: Nathan Chancellor <nathan@kernel.org>
CC: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Cc: Jarkko Sakkinen <jarkko@kernel.org>
Cc: linux-sgx@vger.kernel.org
Cc: x86@kernel.org
Signed-off-by: Dave Hansen <dave.hansen@linux.intel.com>
---

 b/arch/x86/kernel/cpu/sgx/main.c |    8 +++++++-
 1 file changed, 7 insertions(+), 1 deletion(-)

diff -puN arch/x86/kernel/cpu/sgx/main.c~sgx-null-ptr arch/x86/kernel/cpu/sgx/main.c
--- a/arch/x86/kernel/cpu/sgx/main.c~sgx-null-ptr	2021-12-17 13:38:00.217312383 -0800
+++ b/arch/x86/kernel/cpu/sgx/main.c	2021-12-17 14:00:36.293044390 -0800
@@ -906,7 +906,13 @@ EXPORT_SYMBOL_GPL(sgx_set_attribute);
 #ifdef CONFIG_NUMA
 static ssize_t sgx_total_bytes_show(struct device *dev, struct device_attribute *attr, char *buf)
 {
-	return sysfs_emit(buf, "%lu\n", sgx_numa_nodes[dev->id].size);
+	unsigned long node_bytes = 0;
+
+	/* Avoid acccessing sgx_numa_nodes[] when it is not allocated: */
+	if (!nodes_empty(sgx_numa_mask))
+		node_bytes = sgx_numa_nodes[dev->id].size;
+
+	return sysfs_emit(buf, "%lu\n", node_bytes);
 }
 static DEVICE_ATTR_RO(sgx_total_bytes);
 
_

^ permalink raw reply	[flat|nested] 8+ messages in thread

end of thread, other threads:[~2021-12-21  8:42 UTC | newest]

Thread overview: 8+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2021-12-17 22:31 [PATCH] x86/sgx: Fix NULL pointer dereference on non-SGX systems Dave Hansen
2021-12-17 22:57 ` Nathan Chancellor
2021-12-17 23:15 ` Greg KH
2021-12-17 23:30   ` Greg KH
2021-12-17 23:55     ` Dave Hansen
2021-12-18  0:07       ` Greg KH
2021-12-18  0:13         ` Dave Hansen
2021-12-21  8:42 ` Jarkko Sakkinen

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox