Re: [PATCH v2] iommu/amd: bound the early ACPI HID map

Ankit Soni <[email protected]>
Newsgroups dev.linux.lists.iommu,org.kernel.vger.linux-kernel
Message-ID <6i2odgsshu4sqxz34d33r63v3ilsb6gxraazw2kzxot44kzf5w@bagwpkpodifv>
On Mon, Jul 20, 2026 at 07:46:13PM +0800, Pengpeng Hou wrote:
> The ivrs_acpihid command-line parser appends entries to a fixed
> four-element early_acpihid_map array. Unlike the sibling IOAPIC and HPET
> parsers, it does not reject a fifth entry before incrementing the map size.
> 
> Check the capacity at the common found label before parsing the HID and
> UID or writing the entry.
> 
> Fixes: ca3bf5d47cec ("iommu/amd: Introduces ivrs_acpihid kernel parameter")
> Signed-off-by: Pengpeng Hou <[email protected]>

Reviewed-by: Ankit Soni <[email protected]>

> ---
> Changes since v1: https://lore.kernel.org/all/[email protected]/
> - move the capacity check to the start of the found path
> - describe the condition as a full map rather than an invalid option
> - rebase onto v7.2-rc4
> 
>  drivers/iommu/amd/init.c | 6 ++++++
>  1 file changed, 6 insertions(+)
> 
> diff --git a/drivers/iommu/amd/init.c b/drivers/iommu/amd/init.c
> index e93bcb5eef70..e7d7b4cb9337 100644
> --- a/drivers/iommu/amd/init.c
> +++ b/drivers/iommu/amd/init.c
> @@ -3864,6 +3864,12 @@ static int __init parse_ivrs_acpihid(char *str)
>  	return 1;
>  
>  found:
> +	if (early_acpihid_map_size == EARLY_MAP_SIZE) {
> +		pr_err("Early ACPI HID map overflow - ignoring ivrs_acpihid%s\n",
> +		       str);
> +		return 1;
> +	}
> +
>  	p = acpiid;
>  	hid = strsep(&p, ":");
>  	uid = p;
>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.