Re: [PATCH v19 01/14] cxl/ras: Fix cxl_rch_get_aer_info() out-of-bounds AER register read

Alison Schofield <[email protected]> Mon, 3 Aug 2026 19:10:55 -0700
Newsgroups gmane.linux.kernel,gmane.linux.kernel.pci,gmane.linux.acpi.devel,gmane.linux.documentation
Message-ID <[email protected]>
On Mon, Aug 03, 2026 at 05:17:57PM -0500, Terry Bowman wrote:
> cxl_rch_get_aer_info() copies the RCH Downstream Port AER capability from
> the RCRB MMIO block using a readl() loop bounded by sizeof(struct
> aer_capability_regs). This struct is a software layout and its embedded
> struct pcie_tlp_log is larger than the on-wire AER capability. As a
> result the loop reads past the mapped AER register block.
> 
> The over-read also populates the software-only tail fields including
> header_log.header_len. An out-of-range header_len passed to
> pcie_print_tlp_log() can then loop past the header log buffer and cause
> a second out-of-bounds read.
> 
> The read was correct when introduced, but struct pcie_tlp_log has since
> grown (Header Log and TLP Prefix Log sizes, header_len and flit fields),
> so sizeof(struct aer_capability_regs) no longer matches the physical AER
> capability.
> 
> Bound the read to the physical AER registers, header through the 16 byte
> Header Log. Zero the destination first so the software-only fields are
> deterministic.

Reviewed-by: Alison Schofield <[email protected]>