[PATCH v4 06/13] ACPI: extlog: Validate PCIe error section length before payload access
Dave Jiang <[email protected]>
| Newsgroups | org.kernel.vger.linux-cxl,org.kernel.vger.linux-acpi |
|---|---|
| Message-ID | <[email protected]> |
extlog_print_pcie() reads pcie_err->validation_bits and device_id and copies the 96-byte aer_info buffer without checking that gdata->error_data_length is big enough for a struct cper_sec_pcie. The cper_estatus_check() call added earlier keeps the read inside the estatus block, but a short section still gets stale adjacent bytes treated as PCIe error data. Reject a section too small to hold the record before touching any field, and warn: a truncated section means firmware is emitting malformed records. Reported-by: [email protected] Closes: https://lore.kernel.org/linux-cxl/[email protected]/ Fixes: e778ffefa34d ("ACPI: extlog: Trace CPER PCI Express Error Section") Reviewed-by: Alison Schofield <[email protected]> Reviewed-by: Shuai Xue <[email protected]> Assisted-by: Claude:claude-opus-4-8 Signed-off-by: Dave Jiang <[email protected]> --- v4: - Warn instead of returning silently, matching the other length rejections in the series (Shuai Xue). - Added the Closes: link to the sashiko report, which v3 omitted. --- drivers/acpi/acpi_extlog.c | 11 +++++++++-- 1 file changed, 9 insertions(+), 2 deletions(-) diff --git a/drivers/acpi/acpi_extlog.c b/drivers/acpi/acpi_extlog.c index 6d5532ec0920..3aec73187b51 100644 --- a/drivers/acpi/acpi_extlog.c +++ b/drivers/acpi/acpi_extlog.c @@ -134,7 +134,7 @@ static int print_extlog_rcd(const char *pfx, } static void extlog_print_pcie(struct cper_sec_pcie *pcie_err, - int severity) + int severity, u32 len) { #ifdef ACPI_APEI_PCIEAER struct aer_capability_regs aer_regs = {}; @@ -144,6 +144,12 @@ static void extlog_print_pcie(struct cper_sec_pcie *pcie_err, int aer_severity; int domain; + if (len < sizeof(*pcie_err)) { + pr_warn_ratelimited(FW_WARN + "PCIe error section too small (%u)\n", len); + return; + } + if (!(pcie_err->validation_bits & CPER_PCIE_VALID_DEVICE_ID && pcie_err->validation_bits & CPER_PCIE_VALID_AER_INFO)) return; @@ -231,7 +237,8 @@ static int extlog_print(struct notifier_block *nb, unsigned long val, } else if (guid_equal(sec_type, &CPER_SEC_PCIE)) { struct cper_sec_pcie *pcie_err = acpi_hest_get_payload(gdata); - extlog_print_pcie(pcie_err, gdata->error_severity); + extlog_print_pcie(pcie_err, gdata->error_severity, + gdata->error_data_length); } else { void *err = acpi_hest_get_payload(gdata); -- 2.54.0