.../x86/intel/speed_select_if/isst_tpmi_core.c | 13 ++++++++++++- 1 file changed, 12 insertions(+), 1 deletion(-)
Two out-of-bounds accesses reachable from the ISST character device
ioctls, both from user-supplied index values that are not bounded before
use.
The first is an off-by-one on socket_id in the CLOS association ioctl,
plus a missing NULL check on the resulting instance pointer. The same
file already gets both of these right in get_instance(), which rejects
pkg_id with in_range(pkg_id, 0, topology_max_packages()) and then checks
the instance for NULL before returning it.
The second is a missing level bound in the two perf-mask ioctls. The
four adjacent helpers that read the same per-level register block all
reject a level above max_level first.
Neither path is behind CAP_SYS_ADMIN. Commit 69cd1ca440a9 ("platform/x86:
ISST: Check for admin capability for write commands") describes
deployments that relax the permissions on /dev/isst_interface so that
non-root users can read SST capabilities, and deliberately gates only the
write commands.
Found by inspection, not reproduced on hardware.
HyeongJun An (2):
platform/x86: ISST: Validate socket ID in clos_assoc ioctl
platform/x86: ISST: Validate level in perf mask ioctls
.../x86/intel/speed_select_if/isst_tpmi_core.c | 13 ++++++++++++-
1 file changed, 12 insertions(+), 1 deletion(-)
--
2.43.0
On Fri, 07 Aug 2026 23:40:01 +0900, HyeongJun An wrote:
> Two out-of-bounds accesses reachable from the ISST character device
> ioctls, both from user-supplied index values that are not bounded before
> use.
>
> The first is an off-by-one on socket_id in the CLOS association ioctl,
> plus a missing NULL check on the resulting instance pointer. The same
> file already gets both of these right in get_instance(), which rejects
> pkg_id with in_range(pkg_id, 0, topology_max_packages()) and then checks
> the instance for NULL before returning it.
>
> [...]
Thank you for your contribution, it has been applied to my local
review-ilpo-next branch. Note it will show up in the public
platform-drivers-x86/review-ilpo-next branch only once I've pushed my
local branch there, which might take a while.
FYI [if applicable to your patch], as per Linus' policy change, also
fixes are mostly routed through for-next unless the fix is for a
commit introduced in the most recent cycle or is clearly a regression
fix.
The list of commits applied:
[1/2] platform/x86: ISST: Validate socket ID in clos_assoc ioctl
commit: 9100b71ea369c2d9cefd3ed607f683087ff4b03c
[2/2] platform/x86: ISST: Validate level in perf mask ioctls
commit: 74bb8134e55402cdd809d1613cac40765c6711c8
--
i.
On Fri, 2026-08-07 at 23:40 +0900, HyeongJun An wrote:
> Two out-of-bounds accesses reachable from the ISST character device
> ioctls, both from user-supplied index values that are not bounded
> before
> use.
>
> The first is an off-by-one on socket_id in the CLOS association
> ioctl,
> plus a missing NULL check on the resulting instance pointer. The same
> file already gets both of these right in get_instance(), which
> rejects
> pkg_id with in_range(pkg_id, 0, topology_max_packages()) and then
> checks
> the instance for NULL before returning it.
>
> The second is a missing level bound in the two perf-mask ioctls. The
> four adjacent helpers that read the same per-level register block all
> reject a level above max_level first.
>
> Neither path is behind CAP_SYS_ADMIN. Commit 69cd1ca440a9
> ("platform/x86:
> ISST: Check for admin capability for write commands") describes
> deployments that relax the permissions on /dev/isst_interface so that
> non-root users can read SST capabilities, and deliberately gates only
> the
> write commands.
>
> Found by inspection, not reproduced on hardware.
Thanks for the fixes.
-Srinivas
>
> HyeongJun An (2):
> platform/x86: ISST: Validate socket ID in clos_assoc ioctl
> platform/x86: ISST: Validate level in perf mask ioctls
>
> .../x86/intel/speed_select_if/isst_tpmi_core.c | 13
> ++++++++++++-
> 1 file changed, 12 insertions(+), 1 deletion(-)
© 2016 - 2026 Red Hat, Inc.