[PATCH] PCI: sysfs: Reject unaligned resource I/O port accesses

Deepanshu Kartikey <[email protected]>
Newsgroups org.kernel.vger.linux-pci,org.kernel.vger.linux-kernel
Message-ID <[email protected]>
pci_resource_io() validates that off+count stays within the BAR's
range but never checks that the resulting port is aligned to the
access size. A pwrite64()/pread64() on a resourceN file with an odd
offset and count=2 or count=4 reaches outw()/outl() with a misaligned
address. On arm64 this becomes a store/load to a Device-memory
mapping (PCI_IOBASE + port), which architecturally requires natural
alignment, causing an alignment fault and kernel oops.

Reject misaligned accesses before they reach the low-level accessor.

Reported-by: [email protected]
Closes: https://syzkaller.appspot.com/bug?extid=7134530b25073b4ef373
Signed-off-by: Deepanshu Kartikey <[email protected]>
---
 drivers/pci/pci-sysfs.c | 3 +++
 1 file changed, 3 insertions(+)

diff --git a/drivers/pci/pci-sysfs.c b/drivers/pci/pci-sysfs.c
index 5ec0b245a69b..72f0404a34e9 100644
--- a/drivers/pci/pci-sysfs.c
+++ b/drivers/pci/pci-sysfs.c
@@ -1175,6 +1175,9 @@ static ssize_t pci_resource_io(struct file *filp, struct kobject *kobj,
 	if (port + count - 1 > pci_resource_end(pdev, bar))
 		return -EINVAL;
 
+	if (!IS_ALIGNED(port, count))
+		return -EINVAL;
+
 	switch (count) {
 	case 1:
 		if (write)
-- 
2.43.0
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.