linux-5.15: mmbi: validate buffer offsets

Validate host read-only (hrop) and host read-write (hrwp) pointer
offsets against circular buffer boundaries (b2h_cb_size and
h2b_cb_size) in npcm-espi-mmbi to prevent stack buffer overflow
and out-of-bounds writes from untrusted host inputs.

Tested:
Built obmc-phosphor-image, signed, flashed, rebooted on a real machine from DevRez.

Google-Bug-Id: 540017042
Change-Id: Id079d2eb64ebde58267ccf090d91d91970846df7
Signed-off-by: Joseph CT Chan <josephctchan@google.com>
2 files changed
tree: 6b99b74a6ae587a8e7bbddfe55c69604a73c6012
  1. classes/
  2. conf/
  3. dynamic-layers/
  4. recipes-bsp/
  5. recipes-connectivity/
  6. recipes-core/
  7. recipes-devtools/
  8. recipes-extended/
  9. recipes-google/
  10. recipes-kernel/
  11. recipes-phosphor/
  12. recipes-support/
  13. recipes-tpm1/
  14. recipes-tpm2/
  15. LICENSE
  16. README.md
README.md

meta-gbmc-staging

This repository contains additions to the openbmc/meta-google layer that are not yet ready for OpenBMC inclusion.

How to use this layer

  1. Clone openbmc/openbmc from GitHub.
  2. Clone this layer from GitHub into a subdirectory of openbmc.