mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [BUG] tpm_tis_plat_probe -- maps a borrowed MEM resource by its own size, then reads at a FIXED 0xF00 offset
@ 2026-08-28  5:37 Farhad Alemi
  2026-09-01 10:30 ` Jarkko Sakkinen
  0 siblings, 1 reply; 2+ messages in thread
From: Farhad Alemi @ 2026-08-28  5:37 UTC (permalink / raw)
  To: Peter Huewe, Jarkko Sakkinen; +Cc: falemi, linux-integrity, linux-kernel

Hello,

As part of the kernel research at ASU's SEFCOM
lab, we hit the crash below. Crash reports can be found here:

  https://github.com/farhad-alemi/public_bug_reports/tree/main/154-tpm_tis-borrowed-resource-fixed-offset-read/

  BUG: unable to handle page fault for address: ffffc90000a17310
  #PF: supervisor read access in kernel mode
  #PF: error_code(0x0000) - not-present page
  Oops: Oops: 0000 [#1] SMP KASAN NOPTI
  RIP: 0010:ioread32+0x1c/0x80
  Call Trace:
   ioread32+0x1c/0x80
   tpm_tcg_read_bytes+0xec/0x270
   tpm_tis_core_init+0x48c/0x1830
   tpm_tis_init+0x420/0x540
   tpm_tis_plat_probe+0x118/0x1a0
   platform_probe+0xf9/0x190
   really_probe+0x267/0xaf0
   device_driver_attach+0xe0/0x1d0
   bind_store+0x1d0/0x220
   kernfs_fop_write_iter+0x3af/0x540
   ksys_write+0x150/0x270
  Kernel panic - not syncing: Fatal exception

Our reproducer.c is available upon request.

Happy to test a patch if that would help.

Regards,

^ permalink raw reply	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2026-09-01 10:30 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-08-28  5:37 [BUG] tpm_tis_plat_probe -- maps a borrowed MEM resource by its own size, then reads at a FIXED 0xF00 offset Farhad Alemi
2026-09-01 10:30 ` Jarkko Sakkinen

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®