From nobody Wed Aug 26 15:52:49 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1779486809; cv=none; d=zohomail.com; s=zohoarc; b=FgtCLPcKQ3xToHHarRTUDq1ITHtFIWaxWqKsbAK1C18shAgEwSRIGUy6PUhb+pbQlOtbWV8F2AL0Lb/Iif8HD70uOMlgqWTXgmjCy2lA4Xy3fb9q0f8rhUt3SD1AatnFOvZLdfPVPtmUgYcCShgeGdqnRvxlf97avOxfhmkyfGg= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1779486809; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=XPMBrFiUpX/hI+Yxh2FQVNHH0I+E6NGmwHbpVjgfk/Y=; b=QvGc8pt30w6HhX1UQrXOH+jjV2Zw2tMTi61yI4RSwFtfWz8H2VdXsOLdHSK8QUXoCzAkuuGDhFuGrQ8rSfq+XH6ySS5jBNmDy12Es3oyRm2HdYpW1i4FLue3Zmozv1nyHxzf0Ci/a1B4gGW+R/lCtJIDXb5PiARuxnbMIFQ0Jwk= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1779486809095578.937518980349; Fri, 22 May 2026 14:53:29 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wQXmw-0003ph-KV; Fri, 22 May 2026 17:52:14 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wQXmd-0002r7-Td; Fri, 22 May 2026 17:52:00 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wQXmY-0004Bu-8h; Fri, 22 May 2026 17:51:53 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id EAD7A1AFB76; Sat, 23 May 2026 00:49:20 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 1EF543B71C5; Sat, 23 May 2026 00:49:25 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1779486560; bh=JAZIl9UU37pIptr7cp3TbXuzV+fdEh9Xox+SYIH5P7g=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=aRD8u+/O54P5TlLhaf3BQP4rUYboVIX4qO9MGMQiY2BWMHM8o78CTxpDx5uRG1d21 sF0F3XXzphjjj63V8kE3k9Cvm3ERpKaTFRPeCTvbDFiLKXQP31T8VqAOD5KxavVGGT 43Fvo4slLaBgbZl8PNi7XM/K0TJtffbM79ZhDvABKwu/hVElqlzvEMruxaX7t745c4 zo1uu9SlS8J6xTpUtdkuKNc3DzY/7b6HLIPZL++lLHL+FTu7x4UAZ7AQ0vF5E371o8 J+90180kAy2Bmr6K71XLQA5wxNbaiwhuRyyMQjLR7E5c8nAsVlG+pOGqzNjsfKZE6V 8ClYsdYUQe18A== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, =?UTF-8?q?C=C3=A9dric=20Le=20Goater?= , Katherine Leaver , Michael Tokarev Subject: [Stable-10.2.3 128/149] aspeed/hace: Prevent total_req_len overflow Date: Sat, 23 May 2026 00:49:00 +0300 Message-ID: <20260522214923.807017-29-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1779486810796154100 From: C=C3=A9dric Le Goater In accumulate mode, total_req_len is incremented with plen (hwaddr) for each hash request. Repeated additions can overflow total_req_len (uint32_t) and potentially bypass validation checks in has_padding(). Add a helper function to detect overflow before incrementing total_req_len and reject the request if overflow would occur. Reported-by: Katherine Leaver Cc: qemu-stable@nongnu.org Fixes: 5cd7d8564a8b ("aspeed/hace: Support AST2600 HACE") Link: https://lore.kernel.org/qemu-devel/20260504213421.710035-3-clg@redhat= .com Signed-off-by: C=C3=A9dric Le Goater (cherry picked from commit c6aa2d0ac161f2a58a8fbab9a15e846278661158) Signed-off-by: Michael Tokarev diff --git a/hw/misc/aspeed_hace.c b/hw/misc/aspeed_hace.c index c7a2731e38..f08b7ae376 100644 --- a/hw/misc/aspeed_hace.c +++ b/hw/misc/aspeed_hace.c @@ -205,6 +205,19 @@ static uint64_t hash_get_source_addr(AspeedHACEState *= s) return src_addr; } =20 +static bool hash_accumulate_len(AspeedHACEState *s, hwaddr plen) +{ + if (plen > UINT32_MAX - s->total_req_len) { + qemu_log_mask(LOG_GUEST_ERROR, + "%s: total_req_len overflow, current=3D0x%x, adding= =3D0x%" + HWADDR_PRIx "\n", __func__, s->total_req_len, plen); + return false; + } + + s->total_req_len +=3D plen; + return true; +} + static int hash_prepare_direct_iov(AspeedHACEState *s, struct iovec *iov, bool acc_mode, bool *acc_final_request) { @@ -232,7 +245,9 @@ static int hash_prepare_direct_iov(AspeedHACEState *s, = struct iovec *iov, iov_idx =3D 1; =20 if (acc_mode) { - s->total_req_len +=3D plen; + if (!hash_accumulate_len(s, plen)) { + return -1; + } =20 if (has_padding(s, &iov[0], plen, &total_msg_len, &pad_offset)) { @@ -299,7 +314,9 @@ static int hash_prepare_sg_iov(AspeedHACEState *s, stru= ct iovec *iov, =20 iov[iov_idx].iov_base =3D haddr; if (acc_mode) { - s->total_req_len +=3D plen; + if (!hash_accumulate_len(s, plen)) { + return -1; + } =20 if (has_padding(s, &iov[iov_idx], plen, &total_msg_len, &pad_offset)) { --=20 2.47.3