[PATCH 0/2] platform/x86: ISST: Two ioctl input validation fixes

HyeongJun An posted 2 patches 1 month, 3 weeks ago
.../x86/intel/speed_select_if/isst_tpmi_core.c      | 13 ++++++++++++-
1 file changed, 12 insertions(+), 1 deletion(-)
[PATCH 0/2] platform/x86: ISST: Two ioctl input validation fixes
Posted by HyeongJun An 1 month, 3 weeks ago
Two out-of-bounds accesses reachable from the ISST character device
ioctls, both from user-supplied index values that are not bounded before
use.

The first is an off-by-one on socket_id in the CLOS association ioctl,
plus a missing NULL check on the resulting instance pointer. The same
file already gets both of these right in get_instance(), which rejects
pkg_id with in_range(pkg_id, 0, topology_max_packages()) and then checks
the instance for NULL before returning it.

The second is a missing level bound in the two perf-mask ioctls. The
four adjacent helpers that read the same per-level register block all
reject a level above max_level first.

Neither path is behind CAP_SYS_ADMIN. Commit 69cd1ca440a9 ("platform/x86:
ISST: Check for admin capability for write commands") describes
deployments that relax the permissions on /dev/isst_interface so that
non-root users can read SST capabilities, and deliberately gates only the
write commands.

Found by inspection, not reproduced on hardware.

HyeongJun An (2):
  platform/x86: ISST: Validate socket ID in clos_assoc ioctl
  platform/x86: ISST: Validate level in perf mask ioctls

 .../x86/intel/speed_select_if/isst_tpmi_core.c      | 13 ++++++++++++-
 1 file changed, 12 insertions(+), 1 deletion(-)

-- 
2.43.0
Re: [PATCH 0/2] platform/x86: ISST: Two ioctl input validation fixes
Posted by Ilpo Järvinen 1 month, 1 week ago
On Fri, 07 Aug 2026 23:40:01 +0900, HyeongJun An wrote:

> Two out-of-bounds accesses reachable from the ISST character device
> ioctls, both from user-supplied index values that are not bounded before
> use.
> 
> The first is an off-by-one on socket_id in the CLOS association ioctl,
> plus a missing NULL check on the resulting instance pointer. The same
> file already gets both of these right in get_instance(), which rejects
> pkg_id with in_range(pkg_id, 0, topology_max_packages()) and then checks
> the instance for NULL before returning it.
> 
> [...]

Thank you for your contribution, it has been applied to my local
review-ilpo-next branch. Note it will show up in the public
platform-drivers-x86/review-ilpo-next branch only once I've pushed my
local branch there, which might take a while.

FYI [if applicable to your patch], as per Linus' policy change, also
fixes are mostly routed through for-next unless the fix is for a
commit introduced in the most recent cycle or is clearly a regression
fix.

The list of commits applied:
[1/2] platform/x86: ISST: Validate socket ID in clos_assoc ioctl
      commit: 9100b71ea369c2d9cefd3ed607f683087ff4b03c
[2/2] platform/x86: ISST: Validate level in perf mask ioctls
      commit: 74bb8134e55402cdd809d1613cac40765c6711c8

--
 i.
Re: [PATCH 0/2] platform/x86: ISST: Two ioctl input validation fixes
Posted by srinivas pandruvada 1 month, 3 weeks ago
On Fri, 2026-08-07 at 23:40 +0900, HyeongJun An wrote:
> Two out-of-bounds accesses reachable from the ISST character device
> ioctls, both from user-supplied index values that are not bounded
> before
> use.
> 
> The first is an off-by-one on socket_id in the CLOS association
> ioctl,
> plus a missing NULL check on the resulting instance pointer. The same
> file already gets both of these right in get_instance(), which
> rejects
> pkg_id with in_range(pkg_id, 0, topology_max_packages()) and then
> checks
> the instance for NULL before returning it.
> 
> The second is a missing level bound in the two perf-mask ioctls. The
> four adjacent helpers that read the same per-level register block all
> reject a level above max_level first.
> 
> Neither path is behind CAP_SYS_ADMIN. Commit 69cd1ca440a9
> ("platform/x86:
> ISST: Check for admin capability for write commands") describes
> deployments that relax the permissions on /dev/isst_interface so that
> non-root users can read SST capabilities, and deliberately gates only
> the
> write commands.
> 
> Found by inspection, not reproduced on hardware.

Thanks for the fixes.

-Srinivas

> 
> HyeongJun An (2):
>   platform/x86: ISST: Validate socket ID in clos_assoc ioctl
>   platform/x86: ISST: Validate level in perf mask ioctls
> 
>  .../x86/intel/speed_select_if/isst_tpmi_core.c      | 13
> ++++++++++++-
>  1 file changed, 12 insertions(+), 1 deletion(-)