powerpc/pseries: Avoid using the size greater than RTAS_ERROR_LOG_MAX.
authorMahesh Salgaonkar <mahesh@linux.vnet.ibm.com>
Wed, 4 Jul 2018 17:57:02 +0000 (23:27 +0530)
committerMichael Ellerman <mpe@ellerman.id.au>
Tue, 7 Aug 2018 11:49:28 +0000 (21:49 +1000)
The global mce data buffer that used to copy rtas error log is of 2048
(RTAS_ERROR_LOG_MAX) bytes in size. Before the copy we read
extended_log_length from rtas error log header, then use max of
extended_log_length and RTAS_ERROR_LOG_MAX as a size of data to be copied.
Ideally the platform (phyp) will never send extended error log with
size > 2048. But if that happens, then we have a risk of buffer overrun
and corruption. Fix this by using min_t instead.

Fixes: d368514c3097 ("powerpc: Fix corruption when grabbing FWNMI data")
Reported-by: Michal Suchanek <msuchanek@suse.com>
Signed-off-by: Mahesh Salgaonkar <mahesh@linux.vnet.ibm.com>
Signed-off-by: Michael Ellerman <mpe@ellerman.id.au>
arch/powerpc/platforms/pseries/ras.c

index 5e1ef915018208c3511ef0e91c0064c8c9474389..ef104144d4bcde27c3dd513e59e621215d86556d 100644 (file)
@@ -371,7 +371,7 @@ static struct rtas_error_log *fwnmi_get_errinfo(struct pt_regs *regs)
                int len, error_log_length;
 
                error_log_length = 8 + rtas_error_extended_log_length(h);
-               len = max_t(int, error_log_length, RTAS_ERROR_LOG_MAX);
+               len = min_t(int, error_log_length, RTAS_ERROR_LOG_MAX);
                memset(global_mce_data_buf, 0, RTAS_ERROR_LOG_MAX);
                memcpy(global_mce_data_buf, h, len);
                errhdr = (struct rtas_error_log *)global_mce_data_buf;