Re: [PATCH v2 3/3] fpga: microchip-spi: add bounds checks in mpf_ops_parse_header()

Conor Dooley <[email protected]> Tue, 7 Apr 2026 17:43:13 +0100
Newsgroups org.kernel.vger.linux-fpga,org.kernel.vger.linux-kernel
Message-ID <20260407-gap-contest-94de4e56592d@spud>
On Tue, Apr 07, 2026 at 08:06:01AM -0600, Sebastian Alba Vives wrote:
> From: Sebastian Josue Alba Vives <[email protected]>
> 
> mpf_ops_parse_header() reads several fields from the bitstream file
> and uses them as offsets and sizes without validating them against the
> buffer size, leading to multiple out-of-bounds read vulnerabilities:
> 
> 1. When header_size (u8 from file) is 0, the expression
>    *(buf + header_size - 1) reads one byte before the buffer.
> 
> 2. In the block lookup loop, block_id_offset and block_start_offset
>    advance by MPF_LOOKUP_TABLE_RECORD_SIZE (9) each iteration with
>    blocks_num (u8) controlling the count. With a small buffer, these
>    offsets exceed count, causing OOB reads via get_unaligned_le32().
> 
> 3. components_size_start (from file) and component_size_byte_num
>    (derived from components_num, u16 from file) are used as offsets
>    into buf without validation, allowing arbitrary OOB reads.
> 
> Add bounds checks for all three cases: reject header_size of 0,
> validate offsets in the block lookup loop, and validate the component
> size read offset.
> 
> Signed-off-by: Sebastian Alba Vives <[email protected]>

Acked-by: Conor Dooley <[email protected]>

If there's more revisions, please stop sending new versions in response
to old, this is what I see in my mailbox and it is very confusing:

|   1 N   Apr 02 Greg KH         (  43)   ┌─>Re: [PATCH 2/3] fpga: dfl-afu: fix integer truncation of npages in afu_dma_pin_pages()
|   2 N   Apr 04 Greg KH         (  26)   │ ┌─>
|   3 N   Apr 03 Sebastian Alba  (  55)   ├─>[PATCH v2] fpga: dfl-afu: validate DMA mapping length in afu_dma_map_region()
|   4 N   Apr 07 Sebastian Alba  (  41)   ├─>[PATCH v3 2/3] fpga: dfl-afu: validate DMA mapping length in afu_dma_map_region()
|   5 N   Apr 02 Sebastian Alba  (  40) ┌─>[PATCH 2/3] fpga: dfl-afu: fix integer truncation of npages in afu_dma_pin_pages()
|   6 NsF Apr 02 To Sebastian Al ( 116) │   ┌─>
|   7 NsF Apr 02 To Sebastian Al ( 107) │ ┌─>Re: [PATCH 3/3] fpga: microchip-spi: add bounds checks in mpf_ops_parse_header()
|   8 N   Apr 02 Greg KH         ( 106) │ │ ┌─>
|   9 N   Apr 02 Greg KH         (  45) │ │ ├─>
|  10 NsF Apr 02 To Sebastian Al ( 104) │ │ ├─>
|  11 N   Apr 02 Sebastian Alba  (  76) │ ├─>[PATCH v2] fpga: microchip-spi: add bounds checks in mpf_ops_parse_header()
|  12 N   Apr 07 Xu Yilun        (  60) │ │ ┌─>
|  13 N   Apr 02 Sebastian Alba  ( 105) │ ├─>[PATCH v3] fpga: microchip-spi: add bounds checks in mpf_ops_parse_header()
|  14 N   Apr 02 Sebastian Alba  (  65) ├─>[PATCH 3/3] fpga: microchip-spi: add bounds checks in mpf_ops_parse_header()
|  15 N   Apr 07 Xu Yilun        (  61) ├─>Re: [PATCH 1/3] fpga: dfl: add bounds check in dfh_get_param_size()
|  16 N   Apr 07 Sebastian Alba  (  40) │ ┌─>[PATCH v2 2/3] fpga: dfl-afu: fix integer truncation of npages in afu_dma_pin_pages()
|  17 N   Apr 07 Sebastian Alba  (  65) │ ├─>[PATCH v2 3/3] fpga: microchip-spi: add bounds checks in mpf_ops_parse_header()
|  18 N   Apr 07 Sebastian Alba  (  41) ├─>[PATCH v2 1/3] fpga: dfl: add bounds check in dfh_get_param_size()
|  19 N   Apr 02 Sebastian Alba  (  37) [PATCH 1/3] fpga: dfl: add bounds check in dfh_get_param_size()

If one patch needs changing, you unfortunately need to resubmit the
whole series. If you look here there's multiple v2s of the
microchip-spi patch because of the partial resending.
signature.asc (application/pgp-signature, 228 B)
-----BEGIN PGP SIGNATURE-----

iHUEABYKAB0WIQRh246EGq/8RLhDjO14tDGHoIJi0gUCadU0IQAKCRB4tDGHoIJi
0j5mAQCyuMz7otaxiedH2DOxRxXj4PDHt5off4e6DflGoISuvgD+Ol+r+gLlUxlE
P7tVYaqbsTDrZoVdD/1LgBCkvIm/gAA=
=WkrV
-----END PGP SIGNATURE-----