[PATCH 0/4] RAS/amd/fmpm: Fix OOB, uninitialized data, and error-handling bugs
"Rui Qi" <[email protected]>
| Newsgroups | org.kernel.vger.linux-edac,org.kernel.vger.linux-kernel |
|---|---|
| Message-ID | <[email protected]> |
Hi Yazen, Borislav, Tony, This series fixes several bugs in the AMD FRU Memory Poison Manager driver. Patch 1 fixes an out-of-bounds read in the for_each_fru macro caused by the comma operator evaluating the array access before the bounds check. This is technically undefined behavior and would be flagged by UBSan. Patch 2 fixes an uninitialized stack bitmap in save_new_records() that could cause the rollback path to clear ERST records that were not created in the current initialization pass. Patch 3 makes the max_nr_entries module parameter read-only (0444), preventing runtime writes that could exceed the allocated flexible array size. Patch 4 fixes a spurious BUG when erst_get_record_id_begin() fails, because the error path unconditionally calls erst_get_record_id_end() which triggers BUG_ON. All four bugs have been present since the original introduction of the AMD FMPM driver. Rui Qi (4): RAS/amd/fmpm: Fix out-of-bounds read in for_each_fru macro RAS/amd/fmpm: Clear new records bitmap before rollback RAS/amd/fmpm: Make max_nr_entries read-only RAS/amd/fmpm: Fix spurious BUG when ERST record enumeration fails drivers/ras/amd/fmpm.c | 9 ++++++--- 1 file changed, 6 insertions(+), 3 deletions(-) -- 2.20.1