From nobody Sat Jul 25 02:43:54 2026 Received: from cstnet.cn (smtp25.cstnet.cn [159.226.251.25]) (using TLSv1.2 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id DD09939DBE9; Mon, 20 Jul 2026 11:57:43 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=159.226.251.25 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784548668; cv=none; b=p/WXMADvGZz7eLTlQlry25dBabYN4P9ojkTV7eUCruDGUufSRrLwjHyEw0PTUaHfVy5s8N78SFpzVLfvnSuPvH7u3fjj2ropEK18fJwVrKoaxRdMByUG2Mc1ylmNeLq3mdyOcnOeBH9bFQybYtt86xE8lJEcmphG7WDu5FfMK1U= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784548668; c=relaxed/simple; bh=JXP+g5Yop+DVNzHM9hBac//FxjxZfze3PQ57RxDyT80=; h=From:To:Cc:Subject:Date:Message-ID:Content-Type:MIME-Version; b=jJowjD6Qvw1A2ijlGM9LsEMsbzNzmbBMIhg/bQIba6IYC8T/9KbMQ2QSt6GJH/Oej9SOSR9bI9QMC5/SkSfP9a+SOunO5mC1azv9YyjL9w1X4UwLVbMGJuxjqXup2wH3rC4kFeqWA9ZF7BAOP1Brtk+ZwUEfSbYuKVRb+w006HQ= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=iscas.ac.cn; spf=pass smtp.mailfrom=iscas.ac.cn; arc=none smtp.client-ip=159.226.251.25 Authentication-Results: smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=iscas.ac.cn Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=iscas.ac.cn Received: from localhost.localdomain (unknown [111.196.245.140]) by APP-05 (Coremail) with SMTP id zQCowADHNUAlDV5qCNuIAA--.52364S2; Mon, 20 Jul 2026 19:57:25 +0800 (CST) From: Pengpeng Hou To: Miquel Raynal Cc: Richard Weinberger , Vignesh Raghavendra , Huang Shijie , linux-mtd@lists.infradead.org, linux-kernel@vger.kernel.org, stable@vger.kernel.org, Pengpeng Hou Subject: [PATCH v2] mtd: rawnand: validate ONFI extended parameter page sections Date: Mon, 20 Jul 2026 19:57:25 +0800 Message-ID: <20260720115725.10096-1-pengpeng@iscas.ac.cn> X-Mailer: git-send-email 2.50.1 Content-Type: text/plain; charset="utf-8" Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-CM-TRANSID: zQCowADHNUAlDV5qCNuIAA--.52364S2 X-Coremail-Antispam: 1UD129KBjvJXoWxWr15ur4xKr1rJry5KF4DJwb_yoW5WryDpF 4F934akws8J3W7Z3sFka1DCFyFy395GFW8GFyfu34Yk3ZFvr1vkas8Kr1jvFnrKay8Cry8 Xrsrt3Z5C3W5Ca7anT9S1TB71UUUUU7qnTZGkaVYY2UrUUUUjbIjqfuFe4nvWSU5nxnvy2 9KBjDU0xBIdaVrnRJUUUkC14x267AKxVW8JVW5JwAFc2x0x2IEx4CE42xK8VAvwI8IcIk0 rVWrJVCq3wAFIxvE14AKwVWUJVWUGwA2ocxC64kIII0Yj41l84x0c7CEw4AK67xGY2AK02 1l84ACjcxK6xIIjxv20xvE14v26r4j6ryUM28EF7xvwVC0I7IYx2IY6xkF7I0E14v26F4j 6r4UJwA2z4x0Y4vEx4A2jsIE14v26rxl6s0DM28EF7xvwVC2z280aVCY1x0267AKxVW0oV Cq3wAS0I0E0xvYzxvE52x082IY62kv0487Mc02F40EFcxC0VAKzVAqx4xG6I80ewAv7VC0 I7IYx2IY67AKxVWUtVWrXwAv7VC2z280aVAFwI0_Gr0_Cr1lOx8S6xCaFVCjc4AY6r1j6r 4UM4x0Y48IcxkI7VAKI48JM4x0x7Aq67IIx4CEVc8vx2IErcIFxwCY1x0262kKe7AKxVWU AVWUtwCF04k20xvY0x0EwIxGrwCFx2IqxVCFs4IE7xkEbVWUJVW8JwC20s026c02F40E14 v26r1j6r18MI8I3I0E7480Y4vE14v26r106r1rMI8E67AF67kF1VAFwI0_Jw0_GFylIxkG c2Ij64vIr41lIxAIcVC0I7IYx2IY67AKxVW8JVW5JwCI42IY6xIIjxv20xvEc7CjxVAFwI 0_Cr0_Gr1UMIIF0xvE42xK8VAvwI8IcIk0rVWUJVWUCwCI42IY6I8E87Iv67AKxVW8JVWx JwCI42IY6I8E87Iv6xkF7I0E14v26r4j6r4UJbIYCTnIWIevJa73UjIFyTuYvjfUnGQDUU UUU X-CM-SenderInfo: pshqw1xhqjqxpvfd2hldfou0/ nand_flash_detect_ext_param_page() allocates the length declared by the ONFI parameter page, then treats the data as a fixed header followed by variable-length sections. It reads that header and advances over sections without first proving that the fixed page and each current section fit in the allocation. Reject pages shorter than the fixed header, track the remaining variable area while walking sections, and require the ECC section to contain every field read from struct onfi_ext_ecc_info. Use device-scoped diagnostics that identify the malformed ONFI section. Fixes: 6dcbe0cdd83f ("mtd: get the ECC info from the Extended Parameter Pag= e") Cc: stable@vger.kernel.org Signed-off-by: Pengpeng Hou --- Changes since v1: https://lore.kernel.org/all/20260715084226.38336-1-pengpe= ng@iscas.ac.cn/ - replace generic pr_debug() messages with ONFI-specific dev_dbg() diagnost= ics - keep the low-cost bounds hardening conservative because the page is CRC-protected - rebase onto v7.2-rc4 drivers/mtd/nand/raw/nand_onfi.c | 27 +++++++++++++++++++++++++-- 1 file changed, 25 insertions(+), 2 deletions(-) diff --git a/drivers/mtd/nand/raw/nand_onfi.c b/drivers/mtd/nand/raw/nand_o= nfi.c index cd3ad373883e..b5e304c35738 100644 --- a/drivers/mtd/nand/raw/nand_onfi.c +++ b/drivers/mtd/nand/raw/nand_onfi.c @@ -35,16 +35,21 @@ static int nand_flash_detect_ext_param_page(struct nand= _chip *chip, struct nand_onfi_params *p) { struct nand_device *base =3D &chip->base; + struct mtd_info *mtd =3D nand_to_mtd(chip); struct nand_ecc_props requirements; struct onfi_ext_param_page *ep; struct onfi_ext_section *s; struct onfi_ext_ecc_info *ecc; + size_t remaining, section_len; uint8_t *cursor; int ret; int len; int i; =20 len =3D le16_to_cpu(p->ext_param_page_length) * 16; + if (len < sizeof(*ep)) + return -EINVAL; + ep =3D kmalloc(len, GFP_KERNEL); if (!ep) return -ENOMEM; @@ -77,11 +82,29 @@ static int nand_flash_detect_ext_param_page(struct nand= _chip *chip, =20 /* find the ECC section. */ cursor =3D (uint8_t *)(ep + 1); + remaining =3D len - sizeof(*ep); for (i =3D 0; i < ONFI_EXT_SECTION_MAX; i++) { s =3D ep->sections + i; - if (s->type =3D=3D ONFI_SECTION_TYPE_2) + section_len =3D s->length * 16; + if (section_len > remaining) { + dev_dbg(&mtd->dev, + "ONFI extended parameter section %d exceeds page\n", + i); + goto ext_out; + } + + if (s->type =3D=3D ONFI_SECTION_TYPE_2) { + if (section_len < sizeof(*ecc)) { + dev_dbg(&mtd->dev, + "ONFI extended parameter ECC section %d is too short\n", + i); + goto ext_out; + } break; - cursor +=3D s->length * 16; + } + + cursor +=3D section_len; + remaining -=3D section_len; } if (i =3D=3D ONFI_EXT_SECTION_MAX) { pr_debug("We can not find the ECC section.\n");