From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-qv1-f46.google.com (mail-qv1-f46.google.com [209.85.219.46]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 877F73E7140 for ; Mon, 25 May 2026 09:29:04 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.219.46 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1779701348; cv=none; b=gkIjGllou8H7nYJDRb4Q5+2fgnhknKdDuzafWdc06xNChsQwLFDQ1uCs7JAS+sPa/AeuudnVvC6ZkiZnHJUm6aJGvp3zNo4K7uj32kxCQXw3oPG9/l2Vq+/auqmkOtHxaT6st6LvKZHo05IfpJ7pN+DzUTIn7p0GQTJPtuCpr2M= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1779701348; c=relaxed/simple; bh=xYqqCZX1aHrmamBy2SBhedm1rID/oN896iWM3DutL3w=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=dmmDmNeEbX1KLaJQGcbOKiN6iOXO0p1I0fBfIs4leQQ9U0n8UOSaXMkEcD0aIFkuWShK+iLiFvblP1SHcYl9w681u5tmNVYbRvl6+5B2FSpY5jwr3HN6PAIR4A2S0Lnd17PJAjPoGXGUhUUHFKTYR/rqdsUBKKEl3sdNRqGrr1A= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=KdpFxHjG; arc=none smtp.client-ip=209.85.219.46 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="KdpFxHjG" Received: by mail-qv1-f46.google.com with SMTP id 6a1803df08f44-8b4000e51fdso105716156d6.1 for ; Mon, 25 May 2026 02:29:04 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1779701343; x=1780306143; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to; bh=jkGu0TYeQg7c2WJmg7MepcxFtKbFnqZZwBVV8dtAMFY=; b=KdpFxHjGE1e6znL+VTwy9ZiMKEffIAwSEPvmMn0vc25o7dNq6hU43PZTZgR1IL4yUt W0jBd19S1McnyFcrObXqo2IEcC6pUgO8pFgyfZA1FT+RJmcebZhXCKgcI++3p82tM53l 9JnL2etLWN+TL4W8O65ah8JH63dDSiOSI2anIglqKZhpQIEYtECECBthjdQhI7EEFSWC 5+fuM8wBrTAZnMhHqK3GEkS9pBzJsuioekeN7seE4cK5sIv17j0Jakv7i3HjNTc2Erpr Z6HYqA/oiSfHPJfTQACOJvm3Py2zkam9HwCRH6Tout9ZOwV1mKeM+HTmlIBt7dDbjsPr JCyA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1779701343; x=1780306143; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to; bh=jkGu0TYeQg7c2WJmg7MepcxFtKbFnqZZwBVV8dtAMFY=; b=D/MbwvIP0pa019UAMH5Ub+2hrP7CBU4ZZ+itTDDLTaxZwhBN+fHmtc5o+ebCytBzXX bd5ro1d1FAKhmE1IAETHYU147+JedBfW7DIsmUvt09r15JcyV2jZJqK99NkE/ZJmmhKB pSVm0Rw+Sp2gvyxUU+9SGcuz6kD+fgxD4or6NYYjC3UYw6JbK+8hDkwO5EysGnMmPpzL qTI7wcUY9tfphE+K3gXWZ4LKxKHJIFfFf+WdIqWTr5FwP4AmZA9bGckMuGnaY3HVYJMu 0qOmPCk/4iWZkCKh7LL66nwt8f3+3+9MW4byKlPg5JA/KBGhUmZW2uwrLWrltwSoBBYX ziIw== X-Forwarded-Encrypted: i=1; AFNElJ9S4fHvcIvGevIoiX87OCkbo/KOnLnSjGgCMju1tSihY51Qsyo8tYkifYVE6iOKwL5pb5Zr38+tuG4hD7E=@vger.kernel.org X-Gm-Message-State: AOJu0Yzzcod+gDATN1W0KiuEDKRhYi0qxAuSj579xWNh0vMTk/Ujf6V/ VbkrBBlKhkQ+rfkicL3YbG5ZDjvLczprMHt+kzowNiX705rkNgda4pfH X-Gm-Gg: Acq92OHfRpjD60OLkE9RLVnM7Y3fa/oAqRcSu6iZQLlYGIv1CUxqE1rKFZwOCsNlrwQ 0oKnKmHq4fF4J1TwGCILBo54KtPUvORFn7JwCmDarrQeYzpS++6VdX/0QNmCk4AJg4ifvNVE9Wx qqtIQfl64T0FSP4a1E3m8qlKKcP806jFzweUZ7YB+v2X3RHAx9KLgsyEacdIDCnMrzXBF173IT7 BlJ4DO9mLiqB2M9e7wRDMTMtqKLBTNAsmEUS0EnffUy9PU+4fZZijSr/7ZbIunKf1EmtL5NYFlc gasVcuF5Z675W5BjD3pw07vKC9pNDokWheYAKfgh6AhMoE9mXyWGKc3qGvQuu0v7kUiApbUpKbi foAuXID06HzBHfJqjV85Sa4NvVL86BD90cqHr4qoW6fOCkHWamCo9kRrDv+Lj5oj1x3xPv/jYc9 omY9UjMv4qyChogj7sxdvEJC2ZaCNv+eIM2kQ4FAOxSbjvof1JyjqMhoh8hIfpncK6uHwae0h/8 OgP9PkIK9dtjom4e65rSv+Y5QgTu7jJ1QokZPmDY84= X-Received: by 2002:a05:6214:242c:b0:8ae:60c4:857 with SMTP id 6a1803df08f44-8cc7b62163cmr227783116d6.18.1779701343370; Mon, 25 May 2026 02:29:03 -0700 (PDT) Received: from server0.tail6e7dd.ts.net (c-68-48-65-54.hsd1.mi.comcast.net. [68.48.65.54]) by smtp.gmail.com with ESMTPSA id 6a1803df08f44-8cc80dcf4a9sm104255826d6.2.2026.05.25.02.29.02 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 25 May 2026 02:29:02 -0700 (PDT) From: Michael Bommarito To: Mika Westerberg , Andreas Noever , Yehezkel Bernat Cc: linux-usb@vger.kernel.org, linux-kernel@vger.kernel.org Subject: [PATCH 5/6] thunderbolt: limit XDomain response copy to actual frame size Date: Mon, 25 May 2026 05:28:29 -0400 Message-ID: <20260525092830.735472-6-michael.bommarito@gmail.com> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260525092830.735472-1-michael.bommarito@gmail.com> References: <20260525092830.735472-1-michael.bommarito@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 7bit tb_xdomain_copy() copies req->response_size bytes from the received packet buffer regardless of the actual frame size. When a short response arrives, this reads past the valid frame data in the DMA pool buffer into stale contents from previous transactions. Use the minimum of frame size and expected response size for the copy length. Fixes: cdae7c07e3e3 ("thunderbolt: Add support for XDomain properties") Cc: stable@vger.kernel.org Assisted-by: Claude:claude-opus-4-7 Signed-off-by: Michael Bommarito --- The DMA pool buffer (ctl.c:340) is always 256 bytes, so a short frame does not cause an out-of-bounds read from the buffer itself. The real impact is that bytes past the valid frame contain stale data from previous DMA transactions, which are copied into the response struct and interpreted as protocol fields. Confirmed on QEMU (7.1.0-rc3). drivers/thunderbolt/xdomain.c | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/drivers/thunderbolt/xdomain.c b/drivers/thunderbolt/xdomain.c index 9d54e3ccc8278..1fd1cf4295a2a 100644 --- a/drivers/thunderbolt/xdomain.c +++ b/drivers/thunderbolt/xdomain.c @@ -123,7 +123,9 @@ static bool tb_xdomain_match(const struct tb_cfg_request *req, static bool tb_xdomain_copy(struct tb_cfg_request *req, const struct ctl_pkg *pkg) { - memcpy(req->response, pkg->buffer, req->response_size); + size_t len = min_t(size_t, pkg->frame.size, req->response_size); + + memcpy(req->response, pkg->buffer, len); req->result.err = 0; return true; } -- 2.53.0