Re: [PATCH 1/2] drm/i915/huc: Validate the CPD entry offset before manifest read

Daniele Ceraolo Spurio <[email protected]>
Newsgroups org.kernel.vger.stable,org.freedesktop.lists.intel-gfx
Message-ID <[email protected]>

On 8/7/2026 12:23 PM, Jesus Narvaez wrote:
> The CPD manifest offset was dereferenced without checking whether the
> offset was out of bounds or not. Validate the offset is within the FW
> blob before continuing with the read.
>
> Discovered using AI-assisted static analysis confirmed by Intel Product
> Security.
>
> Reported-by: Martin Hodo <[email protected]>
> Fixes: 93a575ab1533 ("drm/i915/huc: Parse the GSC-enabled HuC binary")
> Cc: Daniele Ceraolo Spurio <[email protected]>
> Cc: Alan Previn <[email protected]>
> Cc: <[email protected]> # v6.5+
> Signed-off-by: Jesus Narvaez <[email protected]>
> ---
>   drivers/gpu/drm/i915/gt/uc/intel_huc_fw.c | 14 ++++++++++++--
>   1 file changed, 12 insertions(+), 2 deletions(-)
>
> diff --git a/drivers/gpu/drm/i915/gt/uc/intel_huc_fw.c b/drivers/gpu/drm/i915/gt/uc/intel_huc_fw.c
> index b648238cc675..b9cbcf973236 100644
> --- a/drivers/gpu/drm/i915/gt/uc/intel_huc_fw.c
> +++ b/drivers/gpu/drm/i915/gt/uc/intel_huc_fw.c
> @@ -216,9 +216,19 @@ int intel_huc_fw_get_binary_info(struct intel_uc_fw *huc_fw, const void *data, s
>   	entry = data + header->header_length;
>   
>   	for (i = 0; i < header->num_of_entries; i++, entry++) {
> -		if (strcmp(entry->name, "HUCP.man") == 0)
> +		if (strcmp(entry->name, "HUCP.man") == 0) {
> +			u32 offset = entry_offset(entry);
> +
> +			if (offset >= size ||
> +			    size - offset < sizeof(struct intel_gsc_manifest_header)) {

IMO this could use some parenthesis to clear up the ordering of operations.
with that:

Reviewed-by: Daniele Ceraolo Spurio <[email protected]>

> +				huc_err(huc, "CPD manifest offset 0x%x out of bounds (size %zu)\n",
> +					offset, size);
> +				return -ENODATA;
> +			}
> +
>   			intel_uc_fw_version_from_gsc_manifest(&huc_fw->file_selected.ver,
> -							      data + entry_offset(entry));
> +							      data + offset);
> +		}
>   
>   		if (strcmp(entry->name, "huc_fw") == 0) {
>   			u32 offset = entry_offset(entry);
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.