linux-5.15: mmbi: validate buffer offsets

Validate host read-only (hrop) and host read-write (hrwp) pointer
offsets against circular buffer boundaries (b2h_cb_size and
h2b_cb_size) in npcm-espi-mmbi to prevent stack buffer overflow
and out-of-bounds writes from untrusted host inputs.

Tested:
Built obmc-phosphor-image, signed, flashed, rebooted on a real machine from DevRez.

Google-Bug-Id: 540017042
Change-Id: Id079d2eb64ebde58267ccf090d91d91970846df7
Signed-off-by: Joseph CT Chan <josephctchan@google.com>
diff --git a/recipes-kernel/linux/5.15/1033-soc-nuvoton-npcm-espi-mmbi-validate-buffer-offsets.patch b/recipes-kernel/linux/5.15/1033-soc-nuvoton-npcm-espi-mmbi-validate-buffer-offsets.patch
new file mode 100644
index 0000000..72ad8fa
--- /dev/null
+++ b/recipes-kernel/linux/5.15/1033-soc-nuvoton-npcm-espi-mmbi-validate-buffer-offsets.patch
@@ -0,0 +1,79 @@
+From 2cb8bee0b25501de991e79d1a235a9d0ef4c8534 Mon Sep 17 00:00:00 2001
+From: Joseph CT Chan <josephctchan@google.com>
+Date: Wed, 19 Aug 2026 19:07:46 +0000
+Subject: [PATCH] soc: nuvoton: npcm-espi-mmbi: validate buffer offsets
+
+Validate host read-only (hrop) and host read-write (hrwp) pointer
+offsets against circular buffer boundary sizes (b2h_cb_size and
+h2b_cb_size) in npcm-espi-mmbi.
+
+Untrusted inputs from the host could provide out-of-bounds offsets,
+causing negative size calculations that wrap into huge positive values
+when passed to memcpy/copy_from_user, leading to kernel stack overflow
+and arbitrary out-of-bounds writes.
+
+Upstream-Status: Inappropriate [vendor specific]
+Signed-off-by: Joseph CT Chan <josephctchan@google.com>
+---
+ drivers/soc/nuvoton/npcm-espi-mmbi.c | 24 ++++++++++++++++++++++++
+ 1 file changed, 24 insertions(+)
+
+diff --git a/drivers/soc/nuvoton/npcm-espi-mmbi.c b/drivers/soc/nuvoton/npcm-espi-mmbi.c
+index 56f8e3a41376..71d9cac1ed2d 100644
+--- a/drivers/soc/nuvoton/npcm-espi-mmbi.c
++++ b/drivers/soc/nuvoton/npcm-espi-mmbi.c
+@@ -255,6 +255,13 @@ static int get_b2h_avail_buf_len(struct npcm_mmbi_channel *channel,
+ 	dev_dbg(channel->priv->dev, "HROP - b2h_wp: 0x%0x, h2b_rp: 0x%0x",
+ 		hrop.b2h_wp, hrop.h2b_rp);
+ 
++	if (b2h_rp >= channel->b2h_cb_size ||
++	    hrop.b2h_wp >= channel->b2h_cb_size) {
++		dev_err(channel->priv->dev, "Invalid B2H queue offset: b2h_rp=0x%x, b2h_wp=0x%x (max=0x%x)\n",
++			b2h_rp, hrop.b2h_wp, channel->b2h_cb_size);
++		return -EINVAL;
++	}
++
+ 	if (hrop.b2h_wp >= b2h_rp)
+ 		*avail_buf_len = channel->b2h_cb_size - hrop.b2h_wp + b2h_rp - 1;
+ 	else
+@@ -291,6 +298,13 @@ static int get_mmbi_header(struct npcm_mmbi_channel *channel,
+ 	b2h_rp = GET_B2H_READ_POINTER(h_rwp1);
+ 	dev_dbg(channel->priv->dev, "MMBI HRWP - h2b_wp: 0x%0x, b2h_rp: 0x%0x\n", h2b_wp, b2h_rp);
+ 
++	if (h2b_wp >= channel->h2b_cb_size ||
++	    hrop.h2b_rp >= channel->h2b_cb_size) {
++		dev_err(channel->priv->dev, "Invalid H2B queue offset: h2b_wp=0x%x, h2b_rp=0x%x (max=0x%x)\n",
++			h2b_wp, hrop.h2b_rp, channel->h2b_cb_size);
++		return -EINVAL;
++	}
++
+ 	if (h2b_wp >= hrop.h2b_rp)
+ 		*unread_data_len = h2b_wp - hrop.h2b_rp;
+ 	else
+@@ -602,6 +616,11 @@ static ssize_t mmbi_read(struct file *filp, char *buff, size_t count,
+ 	}
+ 
+ 	memcpy(&hrop, channel->hrop_vmem, sizeof(struct host_rop));
++	if (hrop.h2b_rp >= channel->h2b_cb_size) {
++		dev_err(priv->dev, "Invalid H2B read pointer: 0x%x\n", hrop.h2b_rp);
++		ret = -EINVAL;
++		goto err_out;
++	}
+ 	if ((hrop.h2b_rp + sizeof(struct mmbi_header)) <=
+ 	    channel->h2b_cb_size) {
+ 		rd_offset = hrop.h2b_rp + sizeof(struct mmbi_header);
+@@ -732,6 +751,11 @@ static ssize_t mmbi_write(struct file *filp, const char *buffer, size_t len,
+ 	header.data = ((protocol->type << 24) + len);
+ 
+ 	memcpy(&hrop, channel->hrop_vmem, sizeof(struct host_rop));
++	if (hrop.b2h_wp >= channel->b2h_cb_size) {
++		dev_err(priv->dev, "Invalid B2H write pointer: 0x%x\n", hrop.b2h_wp);
++		mutex_unlock(&priv->lock);
++		return -EINVAL;
++	}
+ 	wt_offset = hrop.b2h_wp;
+ 	end_offset = channel->b2h_cb_size;
+ 
+-- 
+2.55.0.737.g08866a6d13-goog
+
diff --git a/recipes-kernel/linux/linux-gbmc_5.15.bb b/recipes-kernel/linux/linux-gbmc_5.15.bb
index 573499d..4952fe3 100644
--- a/recipes-kernel/linux/linux-gbmc_5.15.bb
+++ b/recipes-kernel/linux/linux-gbmc_5.15.bb
@@ -79,6 +79,7 @@
   file://1029-soc-nuvoton-Add-mmbi-driver-401.patch \
   file://1031-drivers-i3c-Revert-i3c-master-svc-workaround-for-i3c.patch \
   file://1032-soc-nuvoton-mmbi-leveage-several-fixes-from-Intel.patch \
+  file://1033-soc-nuvoton-npcm-espi-mmbi-validate-buffer-offsets.patch \
   file://npcm8xx_defconfig \
   "