mirror of
https://github.com/OpenAMP/open-amp.git
synced 2026-10-02 18:23:21 +08:00
rpmsg: rpc: Validate and initialize server requests
The RPC callback does not receive the request length, so it may inspect bytes beyond a short message. Those bytes currently come from an uninitialized stack buffer. A message shorter than the function ID can also make the dispatch path read uninitialized data. Reject messages that do not contain a complete function ID and zero-initialize the request buffer so callbacks never consume stale stack contents from bytes omitted by the remote peer. Signed-off-by: Ben Levinsky <ben.levinsky@amd.com> Assisted-by: Codex:GPT-5
This commit is contained in:
committed by
Arnaud Pouliquen
parent
80284e3ac0
commit
372048d49d
@@ -51,14 +51,14 @@ static int rpmsg_endpoint_server_cb(struct rpmsg_endpoint *ept, void *data,
|
|||||||
size_t len,
|
size_t len,
|
||||||
uint32_t src, void *priv)
|
uint32_t src, void *priv)
|
||||||
{
|
{
|
||||||
unsigned char buf[MAX_BUF_LEN];
|
unsigned char buf[MAX_BUF_LEN] = { 0 };
|
||||||
unsigned int id;
|
unsigned int id;
|
||||||
const struct rpmsg_rpc_services *service;
|
const struct rpmsg_rpc_services *service;
|
||||||
struct rpmsg_rpc_svr *rpcs;
|
struct rpmsg_rpc_svr *rpcs;
|
||||||
(void)priv;
|
(void)priv;
|
||||||
(void)src;
|
(void)src;
|
||||||
|
|
||||||
if (len > MAX_BUF_LEN)
|
if (len < MAX_FUNC_ID_LEN || len > MAX_BUF_LEN)
|
||||||
return -EINVAL;
|
return -EINVAL;
|
||||||
|
|
||||||
rpcs = metal_container_of(ept, struct rpmsg_rpc_svr, ept);
|
rpcs = metal_container_of(ept, struct rpmsg_rpc_svr, ept);
|
||||||
|
|||||||
Reference in New Issue
Block a user