:p
atchew
Login
A malformed provided partial DTB specifying both '#address-cells = <0>' and '#size-cells = <0>' causes '(address_cells * 2 + size_cells)' to evaluate to 0. This sum is subsequently used as a divisor when calculating the number of regions in the 'xen,reg' property: len = fdt32_to_cpu(xen_reg->len) / ((address_cells * 2 + size_cells) * sizeof(uint32_t)); This leads to a division by zero exception in the Xen hypervisor during boot, causing a hypervisor panic/crash. Fix this by validating that '(address_cells * 2 + size_cells)' is greater than zero before performing the division. If it is zero, log an error message and return -EINVAL. Signed-off-by: Dmytro Prokopchuk <dmytro_prokopchuk1@epam.com> --- xen/common/device-tree/dom0less-build.c | 7 +++++++ 1 file changed, 7 insertions(+) diff --git a/xen/common/device-tree/dom0less-build.c b/xen/common/device-tree/dom0less-build.c index XXXXXXX..XXXXXXX 100644 --- a/xen/common/device-tree/dom0less-build.c +++ b/xen/common/device-tree/dom0less-build.c @@ -XXX,XX +XXX,XX @@ static int __init handle_passthrough_prop(struct kernel_info *kinfo, /* xen,reg specifies where to map the MMIO region */ cell = (const __be32 *)xen_reg->data; + + if ( (address_cells * 2 + size_cells) == 0 ) + { + printk(XENLOG_ERR "Invalid address/size cells combination (both 0)\n"); + return -EINVAL; + } + len = fdt32_to_cpu(xen_reg->len) / ((address_cells * 2 + size_cells) * sizeof(uint32_t)); -- 2.43.0
A malformed partial DTB specifying both '#address-cells = <0>' and '#size-cells = <0>' causes '(address_cells * 2 + size_cells)' to evaluate to 0. This sum is subsequently used as a divisor when calculating the number of regions in the 'xen,reg' property inside handle_passthrough_prop(): len = fdt32_to_cpu(xen_reg->len) / ((address_cells * 2 + size_cells) * sizeof(uint32_t)); This leads to a division by zero exception in the Xen hypervisor during boot, causing a hypervisor panic/crash. Fix this by validating that both 'address_cells' and 'size_cells' are within the valid range of [1, 2] at the read side in scan_pfdt_node() immediately after they are parsed. Any invalid cell size combination is safely rejected early with an error message and return -EINVAL. Fixes: 9ce974c47588 ("xen/arm: assign devices to boot domains") Signed-off-by: Dmytro Prokopchuk <dmytro_prokopchuk1@epam.com> --- Changes in v5: - fixed mistakes around dprintk() Test CI pipeline: https://gitlab.com/xen-project/people/dimaprkp4k/xen/-/pipelines/2664600678 --- xen/common/device-tree/dom0less-build.c | 8 ++++++++ 1 file changed, 8 insertions(+) diff --git a/xen/common/device-tree/dom0less-build.c b/xen/common/device-tree/dom0less-build.c index XXXXXXX..XXXXXXX 100644 --- a/xen/common/device-tree/dom0less-build.c +++ b/xen/common/device-tree/dom0less-build.c @@ -XXX,XX +XXX,XX @@ static int __init scan_pfdt_node(struct kernel_info *kinfo, const void *pfdt, size_cells = device_tree_get_u32(pfdt, nodeoff, "#size-cells", DT_ROOT_NODE_SIZE_CELLS_DEFAULT); + if ( (address_cells < 1) || (address_cells > 2) || + (size_cells < 1) || (size_cells > 2) ) + { + dprintk(XENLOG_ERR, "Invalid address_cells %u or size_cells %u\n", + address_cells, size_cells); + return -EINVAL; + } + node_next = fdt_first_subnode(pfdt, nodeoff); while ( node_next > 0 ) { -- 2.43.0