mirror of
https://github.com/OpenAMP/open-amp.git
synced 2026-10-02 18:23:21 +08:00
rpmsg: rpc: Validate and initialize server requests
The RPC callback does not receive the request length, so it may inspect bytes beyond a short message. Those bytes currently come from an uninitialized stack buffer. A message shorter than the function ID can also make the dispatch path read uninitialized data. Reject messages that do not contain a complete function ID and zero-initialize the request buffer so callbacks never consume stale stack contents from bytes omitted by the remote peer. Signed-off-by: Ben Levinsky <ben.levinsky@amd.com> Assisted-by: Codex:GPT-5
This commit is contained in:
committed by
Arnaud Pouliquen
parent
80284e3ac0
commit
372048d49d
@@ -51,14 +51,14 @@ static int rpmsg_endpoint_server_cb(struct rpmsg_endpoint *ept, void *data,
|
||||
size_t len,
|
||||
uint32_t src, void *priv)
|
||||
{
|
||||
unsigned char buf[MAX_BUF_LEN];
|
||||
unsigned char buf[MAX_BUF_LEN] = { 0 };
|
||||
unsigned int id;
|
||||
const struct rpmsg_rpc_services *service;
|
||||
struct rpmsg_rpc_svr *rpcs;
|
||||
(void)priv;
|
||||
(void)src;
|
||||
|
||||
if (len > MAX_BUF_LEN)
|
||||
if (len < MAX_FUNC_ID_LEN || len > MAX_BUF_LEN)
|
||||
return -EINVAL;
|
||||
|
||||
rpcs = metal_container_of(ept, struct rpmsg_rpc_svr, ept);
|
||||
|
||||
Reference in New Issue
Block a user