[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[xen staging-4.22] dom0less: Prevent division by zero in handle_passthrough_prop()



commit c3ce09cd90a18190042fb5fd83b3772ac3e4bfd8
Author:     Dmytro Prokopchuk1 <dmytro_prokopchuk1@xxxxxxxx>
AuthorDate: Sun Jul 12 11:56:55 2026 +0000
Commit:     Andrew Cooper <andrew.cooper3@xxxxxxxxxx>
CommitDate: Tue Jul 14 13:35:24 2026 +0100

    dom0less: Prevent division by zero in handle_passthrough_prop()
    
    A malformed partial DTB specifying both '#address-cells = <0>' and
    '#size-cells = <0>' causes '(address_cells * 2 + size_cells)' to
    evaluate to 0. This sum is subsequently used as a divisor when
    calculating the number of regions in the 'xen,reg' property inside
    handle_passthrough_prop():
    
        len = fdt32_to_cpu(xen_reg->len) / ((address_cells * 2 + size_cells) *
                                            sizeof(uint32_t));
    
    This leads to a division by zero exception in the Xen hypervisor during
    boot, causing a hypervisor panic/crash.
    
    Fix this by validating that both 'address_cells' and 'size_cells'
    are within the range of [1, 2] at the top of handle_passthrough_prop().
    Any invalid cell size combination is safely rejected early with an error
    message and return -EINVAL.
    
    Furthermore, update handle_passthrough_prop() to use the sizeof(*cell)
    instead of sizeof(uint32_t).
    
    Fixes: 9ce974c47588 ("xen/arm: assign devices to boot domains")
    Signed-off-by: Dmytro Prokopchuk <dmytro_prokopchuk1@xxxxxxxx>
    Reviewed-by: Michal Orzel <michal.orzel@xxxxxxx>
    Release-Acked-by: Oleksii Kurochko <oleksii.kurochko@xxxxxxxxx>
    (cherry picked from commit b83e1d9a1ad34436e64c44a1d9355be7b72722e0)
---
 xen/common/device-tree/dom0less-build.c | 15 ++++++++++++++-
 1 file changed, 14 insertions(+), 1 deletion(-)

diff --git a/xen/common/device-tree/dom0less-build.c 
b/xen/common/device-tree/dom0less-build.c
index eacfd93087..9513c1c837 100644
--- a/xen/common/device-tree/dom0less-build.c
+++ b/xen/common/device-tree/dom0less-build.c
@@ -152,10 +152,23 @@ static int __init handle_passthrough_prop(struct 
kernel_info *kinfo,
             return -ENOMEM;
     }
 
+    /*
+     * xen,reg holds flat host/guest physical addresses and sizes, so the
+     * inherited #address-cells/#size-cells must each be 1 or 2. This also
+     * guards the len division below against a zero or wrapped divisor.
+     */
+    if ( (address_cells < 1) || (address_cells > 2) ||
+         (size_cells < 1) || (size_cells > 2) )
+    {
+        printk(XENLOG_ERR "Invalid address_cells %u or size_cells %u\n",
+               address_cells, size_cells);
+        return -EINVAL;
+    }
+
     /* xen,reg specifies where to map the MMIO region */
     cell = (const __be32 *)xen_reg->data;
     len = fdt32_to_cpu(xen_reg->len) / ((address_cells * 2 + size_cells) *
-                                        sizeof(uint32_t));
+                                        sizeof(*cell));
 
     for ( i = 0; i < len; i++ )
     {
--
generated by git-patchbot for /home/xen/git/xen.git#staging-4.22



 


Rackspace

Lists.xenproject.org is hosted with RackSpace, monitoring our
servers 24x7x365 and backed by RackSpace's Fanatical Support®.