rpmsg: rpc: Validate client request lengths

The RPC client copies caller-provided parameters into a fixed-size
stack buffer without checking whether the complete request fits.
Oversized requests can therefore overwrite the caller's stack frame.

Reject requests that exceed the remaining parameter capacity before
copying them, validate nonempty parameter pointers, and document the
public API limit.

Signed-off-by: Ben Levinsky <ben.levinsky@amd.com>
Assisted-by: Codex:GPT-5
This commit is contained in:
Ben Levinsky
2026-09-21 09:54:50 +02:00
committed by Arnaud Pouliquen
parent 49780d11b4
commit f7c918bf07
2 changed files with 8 additions and 3 deletions
@@ -176,7 +176,8 @@ int rpmsg_rpc_server_init(struct rpmsg_rpc_svr *rpcs, struct rpmsg_device *rdev,
* data
* @param rpc_id Function id
* @param request_param Pointer to request buffer
* @param req_param_size Length of the request data
* @param req_param_size Length of the request data; must not exceed
* MAX_BUF_LEN - MAX_FUNC_ID_LEN
*
* @return Length of the received response, negative value for failure.
*/
+6 -2
View File
@@ -53,12 +53,16 @@ int rpmsg_rpc_client_send(struct rpmsg_rpc_clt *rpc,
{
unsigned char tmpbuf[MAX_BUF_LEN];
if (!rpc)
if (!rpc || (!request_param && req_param_size != 0))
return -EINVAL;
/* Reserve space for the function ID before copying parameters. */
if (req_param_size > MAX_BUF_LEN - MAX_FUNC_ID_LEN)
return -EINVAL;
/* to optimize with the zero copy API */
memcpy(tmpbuf, &rpc_id, MAX_FUNC_ID_LEN);
memcpy(&tmpbuf[MAX_FUNC_ID_LEN], request_param, req_param_size);
if (req_param_size != 0)
memcpy(&tmpbuf[MAX_FUNC_ID_LEN], request_param, req_param_size);
return rpmsg_send(&rpc->ept, tmpbuf, MAX_FUNC_ID_LEN + req_param_size);
}