|
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index] [xen staging-4.22] dom0less: Prevent division by zero in handle_passthrough_prop()
commit c3ce09cd90a18190042fb5fd83b3772ac3e4bfd8
Author: Dmytro Prokopchuk1 <dmytro_prokopchuk1@xxxxxxxx>
AuthorDate: Sun Jul 12 11:56:55 2026 +0000
Commit: Andrew Cooper <andrew.cooper3@xxxxxxxxxx>
CommitDate: Tue Jul 14 13:35:24 2026 +0100
dom0less: Prevent division by zero in handle_passthrough_prop()
A malformed partial DTB specifying both '#address-cells = <0>' and
'#size-cells = <0>' causes '(address_cells * 2 + size_cells)' to
evaluate to 0. This sum is subsequently used as a divisor when
calculating the number of regions in the 'xen,reg' property inside
handle_passthrough_prop():
len = fdt32_to_cpu(xen_reg->len) / ((address_cells * 2 + size_cells) *
sizeof(uint32_t));
This leads to a division by zero exception in the Xen hypervisor during
boot, causing a hypervisor panic/crash.
Fix this by validating that both 'address_cells' and 'size_cells'
are within the range of [1, 2] at the top of handle_passthrough_prop().
Any invalid cell size combination is safely rejected early with an error
message and return -EINVAL.
Furthermore, update handle_passthrough_prop() to use the sizeof(*cell)
instead of sizeof(uint32_t).
Fixes: 9ce974c47588 ("xen/arm: assign devices to boot domains")
Signed-off-by: Dmytro Prokopchuk <dmytro_prokopchuk1@xxxxxxxx>
Reviewed-by: Michal Orzel <michal.orzel@xxxxxxx>
Release-Acked-by: Oleksii Kurochko <oleksii.kurochko@xxxxxxxxx>
(cherry picked from commit b83e1d9a1ad34436e64c44a1d9355be7b72722e0)
---
xen/common/device-tree/dom0less-build.c | 15 ++++++++++++++-
1 file changed, 14 insertions(+), 1 deletion(-)
diff --git a/xen/common/device-tree/dom0less-build.c
b/xen/common/device-tree/dom0less-build.c
index eacfd93087..9513c1c837 100644
--- a/xen/common/device-tree/dom0less-build.c
+++ b/xen/common/device-tree/dom0less-build.c
@@ -152,10 +152,23 @@ static int __init handle_passthrough_prop(struct
kernel_info *kinfo,
return -ENOMEM;
}
+ /*
+ * xen,reg holds flat host/guest physical addresses and sizes, so the
+ * inherited #address-cells/#size-cells must each be 1 or 2. This also
+ * guards the len division below against a zero or wrapped divisor.
+ */
+ if ( (address_cells < 1) || (address_cells > 2) ||
+ (size_cells < 1) || (size_cells > 2) )
+ {
+ printk(XENLOG_ERR "Invalid address_cells %u or size_cells %u\n",
+ address_cells, size_cells);
+ return -EINVAL;
+ }
+
/* xen,reg specifies where to map the MMIO region */
cell = (const __be32 *)xen_reg->data;
len = fdt32_to_cpu(xen_reg->len) / ((address_cells * 2 + size_cells) *
- sizeof(uint32_t));
+ sizeof(*cell));
for ( i = 0; i < len; i++ )
{
--
generated by git-patchbot for /home/xen/git/xen.git#staging-4.22
|
![]() |
Lists.xenproject.org is hosted with RackSpace, monitoring our |