non-standard-hisi_hip08: check the payload length before decoding - #266
Open
agenticode wants to merge 1 commit into
Open
agenticode wants to merge 1 commit into
agenticode wants to merge 1 commit into
Conversation
The three HIP08 decoders cast event->error to a fixed-size struct
without checking event->length, so a short record is read past its
end.
With a 1-byte payload on each of the three GUIDs:
AddressSanitizer: heap-buffer-overflow
READ of size 4
#0 decode_hip08_oem_type1_error non-standard-hisi_hip08.c:684
#0 decode_hip08_oem_type2_error non-standard-hisi_hip08.c:850
#0 decode_hip08_pcie_local_error non-standard-hisi_hip08.c:995
Reject records shorter than the struct, like the ampereone, nvidia and
yitian decoders already do.
Signed-off-by: Jongwon Lee <ai@linux.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Follow-up to #265. The HIP08 decoders have the same bug: all three cast
event->errorto a fixed-size struct and never look atevent->length.On aarch64 (Fedora 44, ASan), a payload one byte short of the struct, or a 1-byte one, reads past the buffer:
With the patch, anything shorter than the struct gets "truncated payload" and returns -1. Full-size records decode as before.
It doesn't depend on #265 and applies to current master.
Testing
aarch64, Fedora 44, on top of 39fae78:
meson test: 9/9 with both compilerspython3 tests/run.py: 140 tests, rc=0scripts/checkpatch.pl --no-tree --strict: no issues