mirror of
https://github.com/torvalds/linux.git
synced 2026-09-24 06:24:02 +02:00
ipmi: ipmb: validate write message length
ipmb_write() read message fields before validating the length byte.
A zero or short write can read uninitialized stack bytes.
A length smaller than the SMBus header underflows the block write length.
Require a non-empty buffer and the minimum IPMB request length.
Also require the length byte plus payload before parsing the message.
Fixes: 51bd6f2915 ("Add support for IPMB driver")
Cc: stable@vger.kernel.org
Signed-off-by: Yousef Alhouseen <alhouseenyousef@gmail.com>
Message-ID: <20260624175353.8592-1-alhouseenyousef@gmail.com>
Signed-off-by: Corey Minyard <corey@minyard.net>
This commit is contained in:
parent
4edcdefd40
commit
5363750688
|
|
@ -141,13 +141,14 @@ static ssize_t ipmb_write(struct file *file, const char __user *buf,
|
|||
u8 msg[MAX_MSG_LEN];
|
||||
ssize_t ret;
|
||||
|
||||
if (count > sizeof(msg))
|
||||
if (!count || count > sizeof(msg))
|
||||
return -EINVAL;
|
||||
|
||||
if (copy_from_user(&msg, buf, count))
|
||||
return -EFAULT;
|
||||
|
||||
if (count < msg[0])
|
||||
if (msg[IPMB_MSG_LEN_IDX] < IPMB_REQUEST_LEN_MIN ||
|
||||
count < (size_t)msg[IPMB_MSG_LEN_IDX] + 1)
|
||||
return -EINVAL;
|
||||
|
||||
rq_sa = GET_7BIT_ADDR(msg[RQ_SA_8BIT_IDX]);
|
||||
|
|
|
|||
Loading…
Reference in New Issue
Block a user