Received: by 2002:a05:6a10:d5a5:0:0:0:0 with SMTP id gn37csp4707155pxb; Tue, 5 Oct 2021 08:41:38 -0700 (PDT) X-Google-Smtp-Source: ABdhPJyWIlxBWPa3IyupO8bf7oOkrwwCwyAsw1BKNTXYWtBlQ6rtPas/N5yRHj42v19Jbh+MDeQO X-Received: by 2002:a17:90a:a78e:: with SMTP id f14mr4493061pjq.235.1633448498468; Tue, 05 Oct 2021 08:41:38 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1633448498; cv=none; d=google.com; s=arc-20160816; b=cUn7wZX4fNXeesWYq291P+AtRow/vu97bIFe9WM7lsCGEGhRnWBstFHSgTFvE8mhL4 MujyqcocvQnd77g9RnKKg5lCs7Lc6yobPm5WxnG4WLiqz1/k6Oy0m8YkoR0i12rLh0X4 Blh77M3Kh40EvlcIa8BXQsVbxnneTN2Q7B6xRxgODpR8jfhS+E6XMu2DHHTymDwisliw k9GV5x+igmTHaKzMJ03fEc/Afj5hEh6IsNYD56rZ1MUhzyxOgGIV0egIJDQK5BxaWsgR GDoHs/I/k+b8yYOxfcCKJx+hxJrJfbCgDrVYupkqG0IYny+bHz+JaamWCAXPt15jdr91 9t3w== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:in-reply-to:content-disposition:mime-version :references:reply-to:message-id:subject:cc:to:from:date:sender :dkim-signature; bh=5QktpwidiajSgJvIim8VKPelrfPrxs7aTCcg3SgMOnQ=; b=hpS5kFIQMVktBuhZol/jtZPqduirrOuaYvDI5L0wbZA1dY9PLQQRZoNOjQjOOTJPzX ah80wrckUVDpNyBYNiPJ8xUiqYILjcEthU97J14m5SdIzdto/ozTzUtGr0F+vNnxGqpM QyQ+W5eLREzIlPu5sWch2hLYU8Y0Y0gXRoD0GH3By6IX6lBaVDmS2OQKiNMK9wYt9i0o jL+UZfwQOsbS9+82P/pzmf7wv9GTNDCSwGWCkthx+KnHwZ4niXECV37Rk5DqEJ/yFSvI 2iY8oPfEf0L2awPZf3VVHZPS49aZw6VN2Ig9ixfRu6+UevVQTfFvY3zeJGRBdmPu0/gQ NKiw== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@gmail.com header.s=20210112 header.b=LrJydlGq; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org Return-Path: Received: from vger.kernel.org (vger.kernel.org. [23.128.96.18]) by mx.google.com with ESMTP id i1si22118936pgt.343.2021.10.05.08.41.23; Tue, 05 Oct 2021 08:41:38 -0700 (PDT) Received-SPF: pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) client-ip=23.128.96.18; Authentication-Results: mx.google.com; dkim=pass header.i=@gmail.com header.s=20210112 header.b=LrJydlGq; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S235588AbhJEPm0 (ORCPT + 99 others); Tue, 5 Oct 2021 11:42:26 -0400 Received: from lindbergh.monkeyblade.net ([23.128.96.19]:34246 "EHLO lindbergh.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S230059AbhJEPmZ (ORCPT ); Tue, 5 Oct 2021 11:42:25 -0400 Received: from mail-oo1-xc29.google.com (mail-oo1-xc29.google.com [IPv6:2607:f8b0:4864:20::c29]) by lindbergh.monkeyblade.net (Postfix) with ESMTPS id 2AEF0C061749; Tue, 5 Oct 2021 08:40:35 -0700 (PDT) Received: by mail-oo1-xc29.google.com with SMTP id e19-20020a4a7353000000b002b5a2c0d2b8so6543595oof.3; Tue, 05 Oct 2021 08:40:35 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20210112; h=sender:date:from:to:cc:subject:message-id:reply-to:references :mime-version:content-disposition:in-reply-to; bh=5QktpwidiajSgJvIim8VKPelrfPrxs7aTCcg3SgMOnQ=; b=LrJydlGqf2IRWbCkEuUKMLD9qxKoltfdqfE4dgB/X732p4nit+b4w157mj+ialGptg cCCdKSMuHXHBWYskXuKDs9Uut4xCe7CFE5Z8FvgY3u6wNIClzHkn3vf6I0bz71EhoOGh PHcHmP1CMQMhSg6xVG2vxqqzjc5scRnD1m1ic4xtkXtecYecJuULGD6qWue4CLgqdXbU JWpupOpwyflNReq2Ac622+QH1Whqi9kncjtlRCRSzCifgymWQujIF4b3EfKFN9k0nwlx JPtmDkMHVKIvzkWcTAnAO7jAgUTZTO1IppGOtkAaGopor6lP+8zVyRYxfrgdqeEL/UK4 dlTQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20210112; h=x-gm-message-state:sender:date:from:to:cc:subject:message-id :reply-to:references:mime-version:content-disposition:in-reply-to; bh=5QktpwidiajSgJvIim8VKPelrfPrxs7aTCcg3SgMOnQ=; b=UCwNxUXJIjmb/0ik6kc7P3+2z2xZ24KwzdvZCrD8fjXXJea79RemrgOQzi6ZQkPa7h R/+em0PBdHdzqKOMOysnjvL0Y1JDrn1ib/QWhcnnHcYSGY/KApO/dS3SdAToTRb4k0HK 77YBtKAjeoslVtJsqs7CzPFxNCU+z1o8cLa0hQqKV12JRy+sgHl64yp31teglb/mn9uC YggYGw4x4ojNDHVINbxFDGCkF9871/SFKeHRyegbI8w538G2eUAWT6mlW4el6WsR5BPE yb9AycGt/9qZyuQPkTtya8pLjgnG5qOGxvVjLps/q6Cj2cCinxV6qyx9+EGc+OHGILaH buBQ== X-Gm-Message-State: AOAM533w47oTKH3RUDgQydBaqnXuYkNKO1ypRCKjRwiDRDfRfbwm/uUW 4gtiwr9+TKy9lm8yWGMRQ2503wlbag== X-Received: by 2002:a4a:e292:: with SMTP id k18mr13915115oot.80.1633448434304; Tue, 05 Oct 2021 08:40:34 -0700 (PDT) Received: from serve.minyard.net (serve.minyard.net. [2001:470:b8f6:1b::1]) by smtp.gmail.com with ESMTPSA id e2sm3428597ooh.40.2021.10.05.08.40.33 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 05 Oct 2021 08:40:33 -0700 (PDT) Sender: Corey Minyard Received: from minyard.net (unknown [IPv6:2001:470:b8f6:1b:1ce5:3fb4:8fe9:30d1]) by serve.minyard.net (Postfix) with ESMTPSA id F22D2180053; Tue, 5 Oct 2021 15:40:32 +0000 (UTC) Date: Tue, 5 Oct 2021 10:40:31 -0500 From: Corey Minyard To: Colin King Cc: openipmi-developer@lists.sourceforge.net, kernel-janitors@vger.kernel.org, linux-kernel@vger.kernel.org Subject: Re: [Openipmi-developer] [PATCH][next] ipmi: ipmb: Fix off-by-one size check on rcvlen Message-ID: <20211005154031.GD5381@minyard.net> Reply-To: minyard@acm.org References: <20211005151611.305383-1-colin.king@canonical.com> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <20211005151611.305383-1-colin.king@canonical.com> Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org On Tue, Oct 05, 2021 at 04:16:11PM +0100, Colin King wrote: > From: Colin Ian King > > There is an off-by-one bounds check on the rcvlen causing a potential > out of bounds write on iidev->rcvmsg. Fix this by using the >= operator > on the bounds check rather than the > operator. Got it, thanks. -corey > > Addresses-Coverity: ("Out-of-bounds write") > Fixes: 0ba0c3c5d1c1 ("ipmi:ipmb: Add initial support for IPMI over IPMB") > Signed-off-by: Colin Ian King > --- > drivers/char/ipmi/ipmi_ipmb.c | 2 +- > 1 file changed, 1 insertion(+), 1 deletion(-) > > diff --git a/drivers/char/ipmi/ipmi_ipmb.c b/drivers/char/ipmi/ipmi_ipmb.c > index b10a1fd9c563..77ebec4ed28e 100644 > --- a/drivers/char/ipmi/ipmi_ipmb.c > +++ b/drivers/char/ipmi/ipmi_ipmb.c > @@ -192,7 +192,7 @@ static int ipmi_ipmb_slave_cb(struct i2c_client *client, > break; > > case I2C_SLAVE_WRITE_RECEIVED: > - if (iidev->rcvlen > sizeof(iidev->rcvmsg)) > + if (iidev->rcvlen >= sizeof(iidev->rcvmsg)) > iidev->overrun = true; > else > iidev->rcvmsg[iidev->rcvlen++] = *val; > -- > 2.32.0 > > > > _______________________________________________ > Openipmi-developer mailing list > Openipmi-developer@lists.sourceforge.net > https://lists.sourceforge.net/lists/listinfo/openipmi-developer