* [PATCH 6.12.y] tpm: fix off-by-four bounds check in tpm2_get_random() [not found] <2026100308-drew-squeamish-a28c@gregkh> @ 2026-10-05 7:59 ` Jarkko Sakkinen 2026-10-05 13:50 ` Sasha Levin 0 siblings, 1 reply; 3+ messages in thread From: Jarkko Sakkinen @ 2026-10-05 7:59 UTC (permalink / raw) To: stable Cc: Jiangshan Yi, Sashiko, Jarkko Sakkinen, Peter Huewe, Jason Gunthorpe, Greg Kroah-Hartman, Jonathan McDowell, Justinien Bouron, Gunnar Kudrjavets, James Bottomley, linux-integrity, linux-kernel From: Jiangshan Yi <yijiangshan@kylinos.cn> [ Upstream commit 9b522400bf5c082feb9a0037a053ea822a2c7e4d ] When the response carries the TPM2_ST_SESSIONS tag, tpm2_get_random() skips the 4-byte parameter size field before locating the random data, but the bounds check still validates the response length against TPM_HEADER_SIZE. A truncated response can pass the check and make memcpy() read up to 4 bytes past the response end, so stale buffer contents end up in the caller's random bytes. Fix this by checking the response length against 'offset', which already includes the skipped parameter size field. Cc: stable@vger.kernel.org # v6.12+ Fixes: 1b6d7f9eb150 ("tpm: add session encryption protection to tpm2_get_random()") Reported-by: Sashiko <sashiko-bot@kernel.org> Closes: https://sashiko.dev/#/patchset/20260902074839.417419-1-yijiangshan%40kylinos.cn Signed-off-by: Jiangshan Yi <yijiangshan@kylinos.cn> Reviewed-by: Jarkko Sakkinen <jarkko@kernel.org> Link: https://lore.kernel.org/r/20260903035837.219284-1-yijiangshan@kylinos.cn Signed-off-by: Jarkko Sakkinen <jarkko@kernel.org> --- drivers/char/tpm/tpm2-cmd.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/drivers/char/tpm/tpm2-cmd.c b/drivers/char/tpm/tpm2-cmd.c index c710128f49b1..63d26aebf55d 100644 --- a/drivers/char/tpm/tpm2-cmd.c +++ b/drivers/char/tpm/tpm2-cmd.c @@ -361,7 +361,7 @@ int tpm2_get_random(struct tpm_chip *chip, u8 *dest, size_t max) out = (struct tpm2_get_random_out *)&buf.data[offset]; recd = min_t(u32, be16_to_cpu(out->size), num_bytes); if (tpm_buf_length(&buf) < - TPM_HEADER_SIZE + + offset + offsetof(struct tpm2_get_random_out, buffer) + recd) { err = -EFAULT; -- 2.47.3 ^ permalink raw reply [flat|nested] 3+ messages in thread
* Re: [PATCH 6.12.y] tpm: fix off-by-four bounds check in tpm2_get_random() 2026-10-05 7:59 ` [PATCH 6.12.y] tpm: fix off-by-four bounds check in tpm2_get_random() Jarkko Sakkinen @ 2026-10-05 13:50 ` Sasha Levin 2026-10-05 19:19 ` Jarkko Sakkinen 0 siblings, 1 reply; 3+ messages in thread From: Sasha Levin @ 2026-10-05 13:50 UTC (permalink / raw) To: stable Cc: Sasha Levin, Jiangshan Yi, Sashiko, Jarkko Sakkinen, Peter Huewe, Jason Gunthorpe, Greg Kroah-Hartman, Jonathan McDowell, Justinien Bouron, Gunnar Kudrjavets, James Bottomley, linux-integrity, linux-kernel > Fix this by checking the response length against 'offset', which > already includes the skipped parameter size field. Queued for 6.12, thanks. -- Thanks, Sasha ^ permalink raw reply [flat|nested] 3+ messages in thread
* Re: [PATCH 6.12.y] tpm: fix off-by-four bounds check in tpm2_get_random() 2026-10-05 13:50 ` Sasha Levin @ 2026-10-05 19:19 ` Jarkko Sakkinen 0 siblings, 0 replies; 3+ messages in thread From: Jarkko Sakkinen @ 2026-10-05 19:19 UTC (permalink / raw) To: Sasha Levin Cc: stable, Jiangshan Yi, Sashiko, Peter Huewe, Jason Gunthorpe, Greg Kroah-Hartman, Jonathan McDowell, Justinien Bouron, Gunnar Kudrjavets, James Bottomley, linux-integrity, linux-kernel On Mon, Oct 05, 2026 at 09:50:27AM -0400, Sasha Levin wrote: > > Fix this by checking the response length against 'offset', which > > already includes the skipped parameter size field. > > Queued for 6.12, thanks. > > -- > Thanks, > Sasha Phew, good to hear, thank you! There might be for some time more than usual merge conflicts in TPM driver given making tpm_buf memory layout flat for the sake of being able to use __free for of its allocations, and thus completely prevent any possible memory leaks from transient buffers. Right, and also merge conflicts could happen also in trusted keys. They are cheap to fix and I'll monitor this situation proactively, and try to react fast. Br, Jarkko ^ permalink raw reply [flat|nested] 3+ messages in thread
end of thread, other threads:[~2026-10-05 19:20 UTC | newest]
Thread overview: 3+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
[not found] <2026100308-drew-squeamish-a28c@gregkh>
2026-10-05 7:59 ` [PATCH 6.12.y] tpm: fix off-by-four bounds check in tpm2_get_random() Jarkko Sakkinen
2026-10-05 13:50 ` Sasha Levin
2026-10-05 19:19 ` Jarkko Sakkinen
This is a public inbox, see mirroring instructions for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®