Skip to content

non-standard-hisi_hip08: check the payload length before decoding - #266

Open
agenticode wants to merge 1 commit into
mchehab:masterfrom
agenticode:hisi-hip08-payload-length
Open

agenticode wants to merge 1 commit into
mchehab:masterfrom
agenticode:hisi-hip08-payload-length

Conversation

@agenticode

Copy link
Copy Markdown

Follow-up to #265. The HIP08 decoders have the same bug: all three cast event->error to a fixed-size struct and never look at event->length.

On aarch64 (Fedora 44, ASan), a payload one byte short of the struct, or a 1-byte one, reads past the buffer:

1f8161e1 (oem type1, 40 bytes)   -> heap-buffer-overflow, decode_hip08_oem_type1_error :684
45534ea6 (oem type2, 60 bytes)   -> heap-buffer-overflow, decode_hip08_oem_type2_error :850
b2889fc9 (pcie local, 152 bytes) -> heap-buffer-overflow, decode_hip08_pcie_local_error :995

With the patch, anything shorter than the struct gets "truncated payload" and returns -1. Full-size records decode as before.

It doesn't depend on #265 and applies to current master.

Testing

aarch64, Fedora 44, on top of 39fae78:

  • gcc 16.2.1 and clang 22.1.8: no build warnings
  • meson test: 9/9 with both compilers
  • python3 tests/run.py: 140 tests, rc=0
  • scripts/checkpatch.pl --no-tree --strict: no issues

The three HIP08 decoders cast event->error to a fixed-size struct
without checking event->length, so a short record is read past its
end.

With a 1-byte payload on each of the three GUIDs:

  AddressSanitizer: heap-buffer-overflow
  READ of size 4
    #0 decode_hip08_oem_type1_error non-standard-hisi_hip08.c:684
    #0 decode_hip08_oem_type2_error non-standard-hisi_hip08.c:850
    #0 decode_hip08_pcie_local_error non-standard-hisi_hip08.c:995

Reject records shorter than the struct, like the ampereone, nvidia and
yitian decoders already do.

Signed-off-by: Jongwon Lee <ai@linux.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant