From nobody Mon Sep 28 23:12:47 2026 Received: from cstnet.cn (smtp25.cstnet.cn [159.226.251.25]) (using TLSv1.2 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 103752E414 for ; Sat, 15 Aug 2026 13:46:07 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=159.226.251.25 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786801572; cv=none; b=kj0CHqMI02CdVN8fNl0F9/O26C+JREMI3gJZPOetQO/GG3G6ccENUaGfaCmP14MgINcnPVd6sfdo0PoseAsDtU1mXUg/yy38eJ680y73ZOS1GBJiwx0+seQ49uXOlq4PspVh6i13wcXVl2hucu3Q0aMXaoXpqdeAdzLFtC1PN8k= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786801572; c=relaxed/simple; bh=FE68fW5FtRjyiO48whynmH75jx8M06H4va6MpUrIgHs=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version:Content-Type; b=PbwSRGojSZWdf+yGpc7gnk4W9rx9BaFEFR81zLZGY1DsqU4niOuVOaiNOuCmuYDIW/WvPHngsfvc/fPKVDmWUuSFYi71I8zlth+6Rr3QRrcdlOXoHY5s2VW2ipkdzV1+h5iMx0MUScsnk3oJke0+EXM2GooAtiUKFzm15+Cfm1o= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=iscas.ac.cn; spf=pass smtp.mailfrom=iscas.ac.cn; arc=none smtp.client-ip=159.226.251.25 Authentication-Results: smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=iscas.ac.cn Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=iscas.ac.cn Received: from localhost.localdomain (unknown [111.196.241.250]) by APP-05 (Coremail) with SMTP id zQCowAC36EKYbYBqXVLRBQ--.59368S2; Sat, 15 Aug 2026 21:46:01 +0800 (CST) From: Pengpeng Hou To: mmayer@broadcom.com, Krzysztof Kozlowski Cc: Pengpeng Hou , Broadcom internal kernel review list , Florian Fainelli , linux-arm-kernel@lists.infradead.org, linux-kernel@vger.kernel.org Subject: [PATCH v2] memory: brcmstb_dpfe: validate firmware section sizes Date: Sat, 15 Aug 2026 21:45:59 +0800 Message-ID: <20260815134559.47888-1-pengpeng@iscas.ac.cn> X-Mailer: git-send-email 2.50.1 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-CM-TRANSID: zQCowAC36EKYbYBqXVLRBQ--.59368S2 X-Coremail-Antispam: 1UD129KBjvJXoWxJryfJr1UKF4DuF4rXw4xWFg_yoW8Kw17pF 45CFyaqr4UJrZ5trZFywnxuay5Gws3Jay2gFyUCa9Yvrnxur1kAFy8KrW5urWrKr95Aw13 XF1DJr1xCas3ArJanT9S1TB71UUUUU7qnTZGkaVYY2UrUUUUjbIjqfuFe4nvWSU5nxnvy2 9KBjDU0xBIdaVrnRJUUUkC14x267AKxVW8JVW5JwAFc2x0x2IEx4CE42xK8VAvwI8IcIk0 rVWrJVCq3wAFIxvE14AKwVWUJVWUGwA2ocxC64kIII0Yj41l84x0c7CEw4AK67xGY2AK02 1l84ACjcxK6xIIjxv20xvE14v26r4j6ryUM28EF7xvwVC0I7IYx2IY6xkF7I0E14v26r4j 6F4UM28EF7xvwVC2z280aVAFwI0_Cr1j6rxdM28EF7xvwVC2z280aVCY1x0267AKxVWxJr 0_GcWle2I262IYc4CY6c8Ij28IcVAaY2xG8wAqx4xG64xvF2IEw4CE5I8CrVC2j2WlYx0E 2Ix0cI8IcVAFwI0_Jrv_JF1lYx0Ex4A2jsIE14v26r1j6r4UMcvjeVCFs4IE7xkEbVWUJV W8JwACjcxG0xvY0x0EwIxGrwACjI8F5VA0II8E6IAqYI8I648v4I1lc7CjxVAaw2AFwI0_ JF0_Jw1l42xK82IYc2Ij64vIr41l4I8I3I0E4IkC6x0Yz7v_Jr0_Gr1lx2IqxVAqx4xG67 AKxVWUJVWUGwC20s026x8GjcxK67AKxVWUGVWUWwC2zVAF1VAY17CE14v26r126r1DMIIY rxkI7VAKI48JMIIF0xvE2Ix0cI8IcVAFwI0_Jr0_JF4lIxAIcVC0I7IYx2IY6xkF7I0E14 v26r4j6F4UMIIF0xvE42xK8VAvwI8IcIk0rVWUJVWUCwCI42IY6I8E87Iv67AKxVWUJVW8 JwCI42IY6I8E87Iv6xkF7I0E14v26r4j6r4UJbIYCTnIWIevJa73UjIFyTuYvjfUOgAwDU UUU X-CM-SenderInfo: pshqw1xhqjqxpvfd2hldfou0/ Content-Type: text/plain; charset="utf-8" The firmware header is read before the image has been shown to contain a complete header. In addition, the final size check adds two firmware-provided u32 section lengths before comparing the result with fw->size, so the addition can wrap. Reject images shorter than the fixed header and checksum before reading the header. Then derive the available payload length with subtraction and require the two declared sections to fill it exactly. Fixes: 2f330caff577 ("memory: brcmstb: Add driver for DPFE") Assisted-by: Codex:gpt-5 Signed-off-by: Pengpeng Hou --- Changes since v1: https://lore.kernel.org/all/20260706092223.78541-1-pengpe= ng@iscas.ac.cn/ - explain why the early fixed-header check is not redundant - replace the overflowing addition with an exact payload check - disclose the use of Codex drivers/memory/brcmstb_dpfe.c | 17 +++++++++-------- 1 file changed, 9 insertions(+), 8 deletions(-) diff --git a/drivers/memory/brcmstb_dpfe.c b/drivers/memory/brcmstb_dpfe.c index 08d9e05b1b33..121d1a0580dd 100644 --- a/drivers/memory/brcmstb_dpfe.c +++ b/drivers/memory/brcmstb_dpfe.c @@ -518,9 +518,15 @@ static int __verify_firmware(struct init_data *init, const struct firmware *fw) { const struct dpfe_firmware_header *header =3D (void *)fw->data; - unsigned int dmem_size, imem_size, total_size; + unsigned int dmem_size, imem_size; bool is_big_endian =3D false; const u32 *chksum_ptr; + size_t payload_size; + + if (fw->size < sizeof(*header) + sizeof(*chksum_ptr)) + return ERR_INVALID_SIZE; + + payload_size =3D fw->size - sizeof(*header) - sizeof(*chksum_ptr); =20 if (header->magic =3D=3D DPFE_BE_MAGIC) is_big_endian =3D true; @@ -539,13 +545,8 @@ static int __verify_firmware(struct init_data *init, if ((dmem_size % sizeof(u32)) !=3D 0 || (imem_size % sizeof(u32)) !=3D 0) return ERR_INVALID_SIZE; =20 - /* - * The header + the data section + the instruction section + the - * checksum must be equal to the total firmware size. - */ - total_size =3D dmem_size + imem_size + sizeof(*header) + - sizeof(*chksum_ptr); - if (total_size !=3D fw->size) + /* The data and instruction sections must fill the payload exactly. */ + if (dmem_size > payload_size || imem_size !=3D payload_size - dmem_size) return ERR_INVALID_SIZE; =20 /* The checksum comes at the very end. */ --=20 2.50.1 (Apple Git-155)