Armin Wolf
e9f6972ab4
hwmon: (gpio-fan) Fix array out of bounds access
...
[ Upstream commit f233d2be38dbbb22299192292983037f01ab363c ]
The driver does not check if the cooling state passed to
gpio_fan_set_cur_state() exceeds the maximum cooling state as
stored in fan_data->num_speeds. Since the cooling state is later
used as an array index in set_fan_speed(), an array out of bounds
access can occur.
This can be exploited by setting the state of the thermal cooling device
to arbitrary values, causing for example a kernel oops when unavailable
memory is accessed this way.
Example kernel oops:
[ 807.987276] Unable to handle kernel paging request at virtual address ffffff80d0588064
[ 807.987369] Mem abort info:
[ 807.987398] ESR = 0x96000005
[ 807.987428] EC = 0x25: DABT (current EL), IL = 32 bits
[ 807.987477] SET = 0, FnV = 0
[ 807.987507] EA = 0, S1PTW = 0
[ 807.987536] FSC = 0x05: level 1 translation fault
[ 807.987570] Data abort info:
[ 807.987763] ISV = 0, ISS = 0x00000005
[ 807.987801] CM = 0, WnR = 0
[ 807.987832] swapper pgtable: 4k pages, 39-bit VAs, pgdp=0000000001165000
[ 807.987872] [ffffff80d0588064] pgd=0000000000000000, p4d=0000000000000000, pud=0000000000000000
[ 807.987961] Internal error: Oops: 96000005 [#1 ] PREEMPT SMP
[ 807.987992] Modules linked in: cmac algif_hash aes_arm64 algif_skcipher af_alg bnep hci_uart btbcm bluetooth ecdh_generic ecc 8021q garp stp llc snd_soc_hdmi_codec brcmfmac vc4 brcmutil cec drm_kms_helper snd_soc_core cfg80211 snd_compress bcm2835_codec(C) snd_pcm_dmaengine syscopyarea bcm2835_isp(C) bcm2835_v4l2(C) sysfillrect v4l2_mem2mem bcm2835_mmal_vchiq(C) raspberrypi_hwmon sysimgblt videobuf2_dma_contig videobuf2_vmalloc fb_sys_fops videobuf2_memops rfkill videobuf2_v4l2 videobuf2_common i2c_bcm2835 snd_bcm2835(C) videodev snd_pcm snd_timer snd mc vc_sm_cma(C) gpio_fan uio_pdrv_genirq uio drm fuse drm_panel_orientation_quirks backlight ip_tables x_tables ipv6
[ 807.988508] CPU: 0 PID: 1321 Comm: bash Tainted: G C 5.15.56-v8+ #1575
[ 807.988548] Hardware name: Raspberry Pi 3 Model B Rev 1.2 (DT)
[ 807.988574] pstate: 20000005 (nzCv daif -PAN -UAO -TCO -DIT -SSBS BTYPE=--)
[ 807.988608] pc : set_fan_speed.part.5+0x34/0x80 [gpio_fan]
[ 807.988654] lr : gpio_fan_set_cur_state+0x34/0x50 [gpio_fan]
[ 807.988691] sp : ffffffc008cf3bd0
[ 807.988710] x29: ffffffc008cf3bd0 x28: ffffff80019edac0 x27: 0000000000000000
[ 807.988762] x26: 0000000000000000 x25: 0000000000000000 x24: ffffff800747c920
[ 807.988787] x23: 000000000000000a x22: ffffff800369f000 x21: 000000001999997c
[ 807.988854] x20: ffffff800369f2e8 x19: ffffff8002ae8080 x18: 0000000000000000
[ 807.988877] x17: 0000000000000000 x16: 0000000000000000 x15: 000000559e271b70
[ 807.988938] x14: 0000000000000000 x13: 0000000000000000 x12: 0000000000000000
[ 807.988960] x11: 0000000000000000 x10: ffffffc008cf3c20 x9 : ffffffcfb60c741c
[ 807.989018] x8 : 000000000000000a x7 : 00000000ffffffc9 x6 : 0000000000000009
[ 807.989040] x5 : 000000000000002a x4 : 0000000000000000 x3 : ffffff800369f2e8
[ 807.989062] x2 : 000000000000e780 x1 : 0000000000000001 x0 : ffffff80d0588060
[ 807.989084] Call trace:
[ 807.989091] set_fan_speed.part.5+0x34/0x80 [gpio_fan]
[ 807.989113] gpio_fan_set_cur_state+0x34/0x50 [gpio_fan]
[ 807.989199] cur_state_store+0x84/0xd0
[ 807.989221] dev_attr_store+0x20/0x38
[ 807.989262] sysfs_kf_write+0x4c/0x60
[ 807.989282] kernfs_fop_write_iter+0x130/0x1c0
[ 807.989298] new_sync_write+0x10c/0x190
[ 807.989315] vfs_write+0x254/0x378
[ 807.989362] ksys_write+0x70/0xf8
[ 807.989379] __arm64_sys_write+0x24/0x30
[ 807.989424] invoke_syscall+0x4c/0x110
[ 807.989442] el0_svc_common.constprop.3+0xfc/0x120
[ 807.989458] do_el0_svc+0x2c/0x90
[ 807.989473] el0_svc+0x24/0x60
[ 807.989544] el0t_64_sync_handler+0x90/0xb8
[ 807.989558] el0t_64_sync+0x1a0/0x1a4
[ 807.989579] Code: b9403801 f9402800 7100003f 8b35cc00 (b9400416)
[ 807.989627] ---[ end trace 8ded4c918658445b ]---
Fix this by checking the cooling state and return an error if it
exceeds the maximum cooling state.
Tested on a Raspberry Pi 3.
Fixes: b5cf88e46bad ("(gpio-fan): Add thermal control hooks")
Signed-off-by: Armin Wolf <W_Armin@gmx.de>
Link: https://lore.kernel.org/r/20220830011101.178843-1-W_Armin@gmx.de
Signed-off-by: Guenter Roeck <linux@roeck-us.net>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2022-09-15 12:39:44 +02:00
..
2022-04-20 09:06:31 +02:00
2014-10-03 08:19:02 -07:00
2014-10-20 16:20:36 +02:00
2014-10-20 16:20:36 +02:00
2015-10-14 07:57:14 -07:00
2013-04-16 18:27:52 -07:00
2020-07-09 09:35:56 +02:00
2016-06-27 18:58:03 -07:00
2014-08-04 07:01:35 -07:00
2014-08-04 07:01:35 -07:00
2015-01-25 21:24:00 -08:00
2015-10-28 10:30:17 +09:00
2014-08-04 07:01:36 -07:00
2014-08-05 19:44:36 -07:00
2014-08-05 19:44:36 -07:00
2014-08-04 07:01:35 -07:00
2014-08-04 07:01:37 -07:00
2016-10-17 10:16:20 -07:00
2016-02-18 19:14:04 -08:00
2016-04-19 06:30:28 -07:00
2016-06-27 18:58:03 -07:00
2015-10-28 10:30:17 +09:00
2016-09-08 21:34:14 -07:00
2020-03-11 07:53:13 +01:00
2022-05-12 12:14:57 +02:00
2020-01-29 10:24:37 +01:00
2017-01-12 11:39:25 +01:00
2020-09-12 11:47:32 +02:00
2014-08-05 19:44:36 -07:00
2014-08-04 07:01:38 -07:00
2017-12-25 14:23:40 +01:00
2015-05-31 22:58:36 -07:00
2018-02-22 15:43:55 +01:00
2014-10-20 16:20:36 +02:00
2014-10-20 16:20:36 +02:00
2022-02-16 12:43:55 +01:00
2014-10-20 16:20:36 +02:00
2017-01-12 11:39:25 +01:00
2014-08-28 11:18:47 -07:00
2016-06-27 18:58:03 -07:00
2014-08-04 07:01:35 -07:00
2020-07-22 09:10:53 +02:00
2019-05-31 06:48:24 -07:00
2022-05-18 09:15:43 +02:00
2013-10-13 16:16:27 -07:00
2016-06-07 20:11:10 -07:00
2016-09-08 21:34:16 -07:00
2014-08-04 07:01:37 -07:00
2017-01-12 11:39:26 +01:00
2014-08-04 07:01:36 -07:00
2017-10-08 10:26:04 +02:00
2022-09-15 12:39:44 +02:00
2014-08-05 19:40:27 -07:00
2018-02-22 15:43:55 +01:00
2021-11-26 11:48:34 +01:00
2014-10-20 16:20:36 +02:00
2015-01-24 14:16:22 +01:00
2022-07-07 17:30:11 +02:00
2015-03-09 09:59:35 -07:00
2018-11-27 16:09:39 +01:00
2016-09-08 21:34:17 -07:00
2018-12-17 09:38:32 +01:00
2013-10-18 09:11:57 -07:00
2019-11-25 09:53:51 +01:00
2017-05-14 14:00:13 +02:00
2020-05-02 17:23:18 +02:00
2016-06-27 18:58:03 -07:00
2018-02-22 15:43:55 +01:00
2018-02-22 15:43:55 +01:00
2016-09-13 07:27:34 -07:00
2014-08-04 07:01:37 -07:00
2014-08-04 07:01:36 -07:00
2015-10-28 10:30:17 +09:00
2013-10-13 16:16:28 -07:00
2020-01-29 10:24:30 +01:00
2014-07-31 09:41:46 -07:00
2014-10-20 16:20:36 +02:00
2021-05-26 11:29:07 +02:00
2014-05-21 16:02:26 -07:00
2015-04-17 09:03:55 -04:00
2014-08-05 19:44:42 -07:00
2022-02-08 18:15:28 +01:00
2014-08-05 17:48:52 -07:00
2014-08-04 07:01:36 -07:00
2014-12-02 06:11:53 -08:00
2016-09-13 07:28:01 -07:00
2016-09-08 21:34:18 -07:00
2014-08-04 07:01:35 -07:00
2016-03-05 06:25:34 -08:00
2016-09-08 21:34:16 -07:00
2014-03-03 08:01:05 -08:00
2014-08-04 07:01:35 -07:00
2016-09-08 21:34:18 -07:00
2014-08-04 07:01:35 -07:00
2013-10-18 09:12:00 -07:00
2016-09-08 21:34:16 -07:00
2015-05-31 22:58:36 -07:00
2016-03-27 10:37:48 -07:00
2014-05-21 16:02:25 -07:00
2014-08-04 07:01:39 -07:00
2014-08-04 07:01:39 -07:00
2014-01-29 20:40:08 +01:00
2016-09-08 21:34:17 -07:00
2020-07-09 09:35:56 +02:00
2014-08-04 07:01:38 -07:00
2021-07-20 16:21:01 +02:00
2021-07-20 16:21:01 +02:00
2014-10-20 16:20:36 +02:00
2015-07-01 13:56:27 -07:00
2014-11-03 19:53:56 -08:00
2016-01-09 07:31:58 -08:00
2019-08-25 10:51:24 +02:00
2020-01-29 10:24:39 +01:00
2016-09-08 21:34:18 -07:00
2016-03-08 18:40:49 -08:00
2016-09-08 21:34:15 -07:00
2014-10-20 16:20:36 +02:00
2019-05-31 06:48:24 -07:00
2014-01-29 20:40:08 +01:00
2014-08-04 07:01:33 -07:00
2019-11-25 09:53:51 +01:00
2014-10-20 16:20:36 +02:00
2022-04-20 09:06:31 +02:00
2014-10-20 16:20:36 +02:00
2016-04-25 07:26:29 -07:00
2017-01-12 11:39:25 +01:00
2016-07-31 14:56:36 -07:00
2015-08-10 23:00:10 -07:00
2014-08-04 07:01:38 -07:00
2020-01-29 10:24:31 +01:00
2014-10-20 16:20:36 +02:00
2014-08-04 07:01:37 -07:00
2019-05-31 06:48:24 -07:00
2019-05-31 06:48:24 -07:00
2014-08-04 07:01:39 -07:00
2015-06-21 22:54:53 -07:00
2014-08-04 07:01:39 -07:00
2016-09-08 21:34:17 -07:00
2014-09-22 11:11:48 -07:00
2016-06-27 18:58:03 -07:00
2021-10-06 10:23:41 +02:00
2014-10-20 16:20:36 +02:00
2014-10-20 16:20:36 +02:00
2016-03-05 06:25:33 -08:00
2014-10-20 16:20:36 +02:00
2014-10-20 16:20:36 +02:00
2019-05-31 06:48:23 -07:00
2014-10-20 16:20:36 +02:00
2014-04-04 18:01:34 +02:00
2014-08-04 07:01:34 -07:00
2015-07-03 14:39:06 +02:00
2020-01-29 10:24:21 +01:00
2014-10-20 16:20:36 +02:00
2014-08-05 19:44:42 -07:00
2015-07-03 14:39:05 +02:00
2014-08-05 19:44:42 -07:00
2018-12-17 09:38:32 +01:00
2014-10-20 16:20:36 +02:00
2014-10-20 16:20:36 +02:00
2016-09-09 14:54:53 -07:00