Re: [PATCH v19 01/14] cxl/ras: Fix cxl_rch_get_aer_info() out-of-bounds AER register read
Alison Schofield <[email protected]> Mon, 3 Aug 2026 19:10:55 -0700
| Newsgroups | org.kernel.vger.linux-pci,org.kernel.vger.linux-acpi,org.kernel.vger.linux-cxl,org.kernel.vger.linux-doc,org.kernel.vger.linux-kernel |
|---|---|
| Message-ID | <[email protected]> |
On Mon, Aug 03, 2026 at 05:17:57PM -0500, Terry Bowman wrote: > cxl_rch_get_aer_info() copies the RCH Downstream Port AER capability from > the RCRB MMIO block using a readl() loop bounded by sizeof(struct > aer_capability_regs). This struct is a software layout and its embedded > struct pcie_tlp_log is larger than the on-wire AER capability. As a > result the loop reads past the mapped AER register block. > > The over-read also populates the software-only tail fields including > header_log.header_len. An out-of-range header_len passed to > pcie_print_tlp_log() can then loop past the header log buffer and cause > a second out-of-bounds read. > > The read was correct when introduced, but struct pcie_tlp_log has since > grown (Header Log and TLP Prefix Log sizes, header_len and flit fields), > so sizeof(struct aer_capability_regs) no longer matches the physical AER > capability. > > Bound the read to the physical AER registers, header through the 16 byte > Header Log. Zero the destination first so the software-only fields are > deterministic. Reviewed-by: Alison Schofield <[email protected]>