From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.133.124]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 10846381AE3 for ; Mon, 18 May 2026 17:51:15 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=170.10.133.124 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1779126677; cv=none; b=JVV1MnlwQsuu4fZfwuxP14+uQyUeUaVt6gLmod+GpzeVa8CKfdAR2d9DLTD4VyF6rmFbBGgtp/KmVfZhID9GgzG751E+k91oKDRJ2lw/VYT6QSqRJqsiKtfpnP0iM60E7kqPhNeHPi92qaUdNAyFWNKrhrB0W8YCqAxQ2hUsfDE= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1779126677; c=relaxed/simple; bh=91smVd3QAkXEQnAcUjgtO9+U3ppX/svzKoezLQCwKvo=; h=Message-ID:Subject:From:To:Cc:Date:In-Reply-To:References: Content-Type:MIME-Version; b=YEOgkGbOqHH9MVtFbQxLm2Wuo6cTgVZHAmTYOAVXvbIN7mHdIGnNW6o3W2/eNsTKKp11u6Ufv4QBS2vzJq0rjVDKoN8m1Hb5EQRlJ6hpjLM6CPMfpHdriEQeFg7UnePqNutZcNAMdBVOKSI8o1bnDXrX/X8h94dPt+qESPbzfMM= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com; spf=pass smtp.mailfrom=redhat.com; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b=RmlMYL67; dkim=pass (2048-bit key) header.d=redhat.com header.i=@redhat.com header.b=Dsas56wn; arc=none smtp.client-ip=170.10.133.124 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=redhat.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b="RmlMYL67"; dkim=pass (2048-bit key) header.d=redhat.com header.i=@redhat.com header.b="Dsas56wn" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1779126675; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=e0D/2lnvFHwbgVt4+FwCYJ0wron62f0hNfGCEfp5oz8=; b=RmlMYL67isOs9QezpHt3dIuLZf/SUC7/zW5wMOkTNDeiQtmYaj06H2TMwKBNh80IgGsnrc 6wgV3Gh4JC+5de9voNhPDVjJokDO99qw3hvyuGN2vwAhOy08C3dwI1hVB9YX+zn0OoCynz xsphMAQ/ZHjb7Nucvso87piyRzvy1OY= Received: from mail-qv1-f71.google.com (mail-qv1-f71.google.com [209.85.219.71]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-646-rJomir4IMyWGAjWu3HlD8g-1; Mon, 18 May 2026 13:51:14 -0400 X-MC-Unique: rJomir4IMyWGAjWu3HlD8g-1 X-Mimecast-MFC-AGG-ID: rJomir4IMyWGAjWu3HlD8g_1779126673 Received: by mail-qv1-f71.google.com with SMTP id 6a1803df08f44-8b7a1ea06bfso89990106d6.3 for ; Mon, 18 May 2026 10:51:14 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=google; t=1779126673; x=1779731473; darn=vger.kernel.org; h=mime-version:user-agent:content-transfer-encoding:references :in-reply-to:date:cc:to:from:subject:message-id:from:to:cc:subject :date:message-id:reply-to; bh=e0D/2lnvFHwbgVt4+FwCYJ0wron62f0hNfGCEfp5oz8=; b=Dsas56wnQL0yhJ486qacPCIGx/FrA6FPfPEM2H3MXY1LPTCuDpNvLiPfO6xylDvcqP ejAL89z1IO8oZVnlD9eS4zV72BwKLt1++ADs0qH805Eqx5sQBZOF9PuHQW+p+e8jpx/P iVUvgm3qlkrRVxg9zsTSjnPME6vjiVYNsYdDYmjvIEZcgnQr9F9q0qhy+1NBUbIgMCQB F7QfhM4CHWGa0tyFhIoXKuCku+TcWMDYhRP1C6uRa8GMboptj6ZDVnIvcMBaU7I4adyX uujcJC8a5AYhBqzXODLbiDCvQfuxq0oLoX6ofKszTCNffPYwmLfTaTvWUuncTlgvPXna q4uQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1779126673; x=1779731473; h=mime-version:user-agent:content-transfer-encoding:references :in-reply-to:date:cc:to:from:subject:message-id:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to; bh=e0D/2lnvFHwbgVt4+FwCYJ0wron62f0hNfGCEfp5oz8=; b=Ot3qP5DzwMXYZ/CEnEaI8LEfpOZDeyqHG+dHH6fG1FIUV2phPMBpwb/yHdgUNd8FBG LDoGlCV++UJ+hKfcBD3xwHTUeXmfDrC5qfFg95VLQvYuwNou9lTosTFZbmo460qWrOcJ gZj/VRwVIo2stG7sHg3g4YC62uoT0L9TtfzgFWHwRMvNN10hdXf+M5Z9voI/W/4MHxVu uwwPo52DWIBAbC5EoKIRpUcXCOysI+cvOvkx5kArPIw4DTJVqYgajbmeR7efl+orkBvS 0/KmWS8+wKs50htNfPWKF6f/w4m60tK3GL0bTzIJfAfCBsz+q0ioZa/rSeM1ZV+Oab25 sH3A== X-Forwarded-Encrypted: i=1; AFNElJ/YH8PM/HCgcF5XTvRHKadOM5i9tFwzZmp18t7MTygZgAn1dT2EZGjM5L5LoTaB2EErZJpcDMpzNRv+g8g=@vger.kernel.org X-Gm-Message-State: AOJu0YzMyzhDCruC1jJqPA/RVxG5MpNOx/5Hqs1qVhijfVP9jCOhnAMw GUICKJ0CknlBpAQkGgaK/UNkbpZEfY3rc4+Gn6KV6IkYzBTe0SI+xR+YLC2Zwng7ytJBqGHZeFQ ciFxgsOemk5G83nl/GgnijXuoctv7V3lVQ7KbJFo8+2Ch5y5V7NlLCFSjP/c6AByHXg== X-Gm-Gg: Acq92OEnLiiqxsiGsfGoUVyD9xECkCYrrCgTQKJK59gc3tArwQe7LZNqUnZbG43z3Jw LrOKz7+2hWSXhtcdyebBFSl0nku2n5BYY/mhDWEGVb/a76ZVJ+1Puuf3tvncWSwJU4i1vqIpF2A lV32VuNohMglRHsy1M8GdmeIAW13kJHp5R2F+8qwmsII9qu37QTGV3SKoLIVnucddCDaoF9GE5H X1LsHgyKy4aSi4ktVzmEge/vOGhTUtRzHSLGCOw8mAQNNiiwxazrFHSatBe0EfZX4sT+NFB62PW EeWY/xaCDbl77Pdcyn0cmlqATTs2OXKImB6KfVnGEndmK9tuvvomKzhjHjUs+UgbCf0DBUxvpGp tAiPLVHuTN0hsNANwuQ== X-Received: by 2002:a05:620a:170f:b0:911:5568:364e with SMTP id af79cd13be357-911cea09f95mr2541777385a.37.1779126673344; Mon, 18 May 2026 10:51:13 -0700 (PDT) X-Received: by 2002:a05:620a:170f:b0:911:5568:364e with SMTP id af79cd13be357-911cea09f95mr2541772085a.37.1779126672725; Mon, 18 May 2026 10:51:12 -0700 (PDT) Received: from [192.168.8.4] ([100.0.180.93]) by smtp.gmail.com with ESMTPSA id af79cd13be357-91435ca2855sm449582485a.40.2026.05.18.10.51.11 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 18 May 2026 10:51:11 -0700 (PDT) Message-ID: Subject: Re: [PATCH v2] drm/dp/mst: fix OOB reads in remote DPCD/I2C sideband reply parsers From: lyude@redhat.com To: Ashutosh Desai , dri-devel@lists.freedesktop.org Cc: stable@vger.kernel.org, airlied@gmail.com, daniel@ffwll.ch, maarten.lankhorst@linux.intel.com, mripard@kernel.org, tzimmermann@suse.de, simona@ffwll.ch, linux-kernel@vger.kernel.org Date: Mon, 18 May 2026 13:51:11 -0400 In-Reply-To: <20260510201733.2882224-1-ashutoshdesai993@gmail.com> References: <20260510201733.2882224-1-ashutoshdesai993@gmail.com> Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable User-Agent: Evolution 3.58.3 (3.58.3-1.fc43) Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Reviewed-by: Lyude Paul Will push to drm-misc in just a moment On Sun, 2026-05-10 at 20:17 +0000, Ashutosh Desai wrote: > drm_dp_sideband_parse_remote_dpcd_read() reads num_bytes from the raw > message and then unconditionally does: >=20 > =C2=A0 memcpy(bytes, &raw->msg[idx], num_bytes); >=20 > without checking that idx + num_bytes <=3D raw->curlen. raw->msg[] is > 256 bytes; if a malicious or misbehaving MST hub sets num_bytes > larger > than the remaining payload, the memcpy reads past the received data > into whatever follows in raw->msg[]. >=20 > drm_dp_sideband_parse_remote_i2c_read_ack() has the same flaw (noted > with a /* TODO check */ comment since the code was introduced). >=20 > Fix both functions by using a single combined check > (idx + num_bytes > curlen) before each memcpy. Since num_bytes is u8, > it is always >=3D 0, so this strictly subsumes the simpler idx > curlen > form and no separate step is needed. >=20 > Cc: stable@vger.kernel.org > Signed-off-by: Ashutosh Desai > --- > Changes in v2: > - Drop separate idx > curlen check; idx + num_bytes > curlen with u8 > =C2=A0 num_bytes (always >=3D 0) strictly subsumes it (Lyude Paul) >=20 > =C2=A0drivers/gpu/drm/display/drm_dp_mst_topology.c | 6 ++++-- > =C2=A01 file changed, 4 insertions(+), 2 deletions(-) >=20 > diff --git a/drivers/gpu/drm/display/drm_dp_mst_topology.c > b/drivers/gpu/drm/display/drm_dp_mst_topology.c > index 170113520a43..9416a48804c8 100644 > --- a/drivers/gpu/drm/display/drm_dp_mst_topology.c > +++ b/drivers/gpu/drm/display/drm_dp_mst_topology.c > @@ -871,7 +871,7 @@ static bool > drm_dp_sideband_parse_remote_dpcd_read(struct drm_dp_sideband_msg_rx > =C2=A0 goto fail_len; > =C2=A0 repmsg->u.remote_dpcd_read_ack.num_bytes =3D raw->msg[idx]; > =C2=A0 idx++; > - if (idx > raw->curlen) > + if (idx + repmsg->u.remote_dpcd_read_ack.num_bytes > raw- > >curlen) > =C2=A0 goto fail_len; > =C2=A0 > =C2=A0 memcpy(repmsg->u.remote_dpcd_read_ack.bytes, &raw->msg[idx], > repmsg->u.remote_dpcd_read_ack.num_bytes); > @@ -907,7 +907,9 @@ static bool > drm_dp_sideband_parse_remote_i2c_read_ack(struct drm_dp_sideband_msg > =C2=A0 goto fail_len; > =C2=A0 repmsg->u.remote_i2c_read_ack.num_bytes =3D raw->msg[idx]; > =C2=A0 idx++; > - /* TODO check */ > + if (idx + repmsg->u.remote_i2c_read_ack.num_bytes > raw- > >curlen) > + goto fail_len; > + > =C2=A0 memcpy(repmsg->u.remote_i2c_read_ack.bytes, &raw->msg[idx], > repmsg->u.remote_i2c_read_ack.num_bytes); > =C2=A0 return true; > =C2=A0fail_len: