Skip to content

Commit 9e8bc49

Browse files
SebasteuoXu Yilun
authored andcommitted
fpga: dfl: add bounds check in dfh_get_param_size()
dfh_get_param_size() can return a parameter size larger than the feature region because the loop bounds check is evaluated before incrementing size. If the EOP (End of Parameters) bit is set in the same iteration, the inflated size is returned without re-validation against max. This can cause create_feature_instance() to call memcpy_fromio() with a size exceeding the ioremap'd region when a malicious FPGA device provides crafted DFHv1 parameter headers. Add a bounds check after the size increment to ensure the accumulated size never exceeds the feature boundary. Fixes: 4747ab8 ("fpga: dfl: add basic support for DFHv1") Cc: stable@vger.kernel.org Signed-off-by: Sebastian Alba Vives <sebasjosue84@gmail.com> Reviewed-by: Xu Yilun <yilun.xu@intel.com> Link: https://lore.kernel.org/r/20260518190742.61426-2-sebasjosue84@gmail.com Signed-off-by: Xu Yilun <yilun.xu@linux.intel.com>
1 parent 3c310d9 commit 9e8bc49

1 file changed

Lines changed: 2 additions & 0 deletions

File tree

drivers/fpga/dfl.c

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1132,6 +1132,8 @@ static int dfh_get_param_size(void __iomem *dfh_base, resource_size_t max)
11321132
return -EINVAL;
11331133

11341134
size += next * sizeof(u64);
1135+
if (size > max)
1136+
return -EINVAL;
11351137

11361138
if (FIELD_GET(DFHv1_PARAM_HDR_NEXT_EOP, v))
11371139
return size;

0 commit comments

Comments
 (0)