From 79a7bbffecc2a79b1bb20a6eea188a8fb790556d Mon Sep 17 00:00:00 2001 From: Jongwon Lee Date: Wed, 23 Sep 2026 06:31:28 +0000 Subject: [PATCH] non-standard-hisi_hip08: check the payload length before decoding The three HIP08 decoders cast event->error to a fixed-size struct without checking event->length, so a short record is read past its end. With a 1-byte payload on each of the three GUIDs: AddressSanitizer: heap-buffer-overflow READ of size 4 #0 decode_hip08_oem_type1_error non-standard-hisi_hip08.c:684 #0 decode_hip08_oem_type2_error non-standard-hisi_hip08.c:850 #0 decode_hip08_pcie_local_error non-standard-hisi_hip08.c:995 Reject records shorter than the struct, like the ampereone, nvidia and yitian decoders already do. Signed-off-by: Jongwon Lee --- events-arch-arm/non-standard-hisi_hip08.c | 15 +++++++++++++++ 1 file changed, 15 insertions(+) diff --git a/events-arch-arm/non-standard-hisi_hip08.c b/events-arch-arm/non-standard-hisi_hip08.c index 736bb94d..d1d650da 100644 --- a/events-arch-arm/non-standard-hisi_hip08.c +++ b/events-arch-arm/non-standard-hisi_hip08.c @@ -676,6 +676,11 @@ static int decode_hip08_oem_type1_error(struct ras_events *ras, (struct hisi_oem_type1_err_sec *)event->error; struct ras_stmt *stmt = hip08_oem_type1_event_db.stmt; + if (!event->error || event->length < sizeof(*err)) { + trace_seq_printf(s, "%s: truncated payload\n", __func__); + return -1; + } + if (ras->record_events) WARN_ONCE(!stmt, ALL, LOG_WARNING, "Can't insert into table %s: no statement\n", @@ -842,6 +847,11 @@ static int decode_hip08_oem_type2_error(struct ras_events *ras, (struct hisi_oem_type2_err_sec *)event->error; struct ras_stmt *stmt = hip08_oem_type2_event_db.stmt; + if (!event->error || event->length < sizeof(*err)) { + trace_seq_printf(s, "%s: truncated payload\n", __func__); + return -1; + } + if (ras->record_events) WARN_ONCE(!stmt, ALL, LOG_WARNING, "Can't insert into table %s: no statement\n", @@ -987,6 +997,11 @@ static int decode_hip08_pcie_local_error(struct ras_events *ras, (struct hisi_pcie_local_err_sec *)event->error; struct ras_stmt *stmt = hip08_pcie_local_event_db.stmt; + if (!event->error || event->length < sizeof(*err)) { + trace_seq_printf(s, "%s: truncated payload\n", __func__); + return -1; + } + if (ras->record_events) WARN_ONCE(!stmt, ALL, LOG_WARNING, "Can't insert into table %s: no statement\n",