Re: [PATCH v3 09/10] ACPI: APEI: GHES: Bound AER info copy and sanitize software metadata
Alison Schofield <[email protected]>
| Newsgroups | org.kernel.vger.linux-cxl,org.kernel.vger.linux-acpi |
|---|---|
| Message-ID | <[email protected]> |
On Fri, Jul 17, 2026 at 09:16:46AM -0700, Dave Jiang wrote: > sashiko-bot flagged that ghes_handle_aer() has the same unvalidated > AER buffer handling plus a 4-byte over-read. > > ghes_handle_aer() copies sizeof(struct aer_capability_regs) from the > fixed 96-byte pcie_err->aer_info, reading past the section since the > struct is larger. It also fills the software-only header_len and flit > fields of the embedded struct pcie_tlp_log from raw firmware bytes; > pcie_print_tlp_log() uses them to bound a loop over dw[], so a large > value walks past the array. There is also no check that the section can > hold a struct cper_sec_pcie. > > Validate error_data_length, zero the destination, bound the copy to the > 96-byte source, and clear header_len and flit. This mirrors the > extlog_print_pcie() fix. > > Reported-by: [email protected] > Closes: https://sashiko.dev/#/patchset/[email protected]?part=3 > Fixes: 7e077e6707b3 ("PCI/ERR: Handle TLP Log in Flit mode") > Assisted-by: Claude:claude-opus-4-8 > Signed-off-by: Dave Jiang <[email protected]> Reviewed-by: Alison Schofield <[email protected]>