lib: utils/ipi: buffer overrun aclint_mswi_cold_init
authorHeinrich Schuchardt <heinrich.schuchardt@canonical.com>
Mon, 29 May 2023 09:27:20 +0000 (11:27 +0200)
committerAnup Patel <anup@brainfault.org>
Sun, 4 Jun 2023 09:43:50 +0000 (15:13 +0530)
commitdf75e0995689842b3022a4a8d4d69e980430c129
tree71fb382aebbb67e2a1ead6951bde839ce464b8a1
parent122f2260b350e94e4e79439ea289f08a329eb14a
lib: utils/ipi: buffer overrun aclint_mswi_cold_init

The parameter checks in aclint_mswi_cold_init() don't guard against a
buffer overrun.

mswi_hartid2data is defined as an array of SBI_HARTMASK_MAX_BITS entries.
The current check allows

    mswi->hart_count = ACLINT_MSWI_MAX_HARTS
    mswi->first_hartid = SBI_HARTMASK_MAX_BITS - 1.

With these values mswi_hartid2data will be accessed at index

    SBI_HARTMASK_MAX_BITS + SBI_HARTMASK_MAX_BITS - 2.

We have to check the sum of mswi->first_hartid and mswi->hart_count.

Furthermore mswi->hart_count = 0 would not make much sense.

Addresses-Coverity-ID: 1529705 ("Out-of-bounds write")
Fixes: 5a049fe1d6a5 ("lib: utils/ipi: Add ACLINT MSWI library")
Signed-off-by: Heinrich Schuchardt <heinrich.schuchardt@canonical.com>
Reviewed-by: Xiang W <wxjstz@126.com>
Reviewed-by: Anup Patel <anup@brainfault.org>
lib/utils/ipi/aclint_mswi.c