fix ipmi out of bound access

Tested: Builds
Google-Bug-Id: 450349095
Google-Bug-Id: 450351038
Google-Bug-Id: 450349110
Change-Id: I0c1a1caef4feeefd4a51abb0f45df064d5e0e8fc
Signed-off-by: Willy Tu <wltu@google.com>
diff --git a/recipes-phosphor/ipmi/phosphor-ipmi-host/0010-Fix-empty-data-access-in-setMgmntCtrlIdStr.patch b/recipes-phosphor/ipmi/phosphor-ipmi-host/0010-Fix-empty-data-access-in-setMgmntCtrlIdStr.patch
new file mode 100644
index 0000000..db0d5cb
--- /dev/null
+++ b/recipes-phosphor/ipmi/phosphor-ipmi-host/0010-Fix-empty-data-access-in-setMgmntCtrlIdStr.patch
@@ -0,0 +1,43 @@
+From 8051dc1d0aa16dd42f3df6b9686a7948963876d0 Mon Sep 17 00:00:00 2001
+From: Willy Tu <wltu@google.com>
+Date: Fri, 12 Jun 2026 04:55:45 +0000
+Subject: [PATCH 1/3] Fix empty data access in setMgmntCtrlIdStr
+
+Make sure we don't access the back of empty data vector.
+The terminalWrite variable is undefined when the empty vector.back()
+is accessed.
+
+Change-Id: Iefb9c8b6ed2a8f23d9cae2281a438c3ea8285184
+Signed-off-by: Willy Tu <wltu@google.com>
+---
+ dcmihandler.cpp | 13 +++++++++----
+ 1 file changed, 9 insertions(+), 4 deletions(-)
+
+diff --git a/dcmihandler.cpp b/dcmihandler.cpp
+index e45ea3f..620fb74 100644
+--- a/dcmihandler.cpp
++++ b/dcmihandler.cpp
+@@ -594,11 +594,16 @@ ipmi::RspType<uint8_t> setMgmntCtrlIdStr(ipmi::Context::ptr& ctx,
+     {
+         return ipmi::responseReqDataLenInvalid();
+     }
+-    bool terminalWrite{data.back() == '\0'};
+-    if (terminalWrite)
++    bool terminalWrite = false;
++    if (!data.empty())
+     {
+-        // remove the null termination from the data (no need with std::string)
+-        data.resize(count - 1);
++        terminalWrite = (data.back() == '\0');
++        if (terminalWrite)
++        {
++            // remove the null termination from the data (no need with
++            // std::string)
++            data.resize(count - 1);
++        }
+     }
+ 
+     static std::string hostname{};
+-- 
+2.54.0.1136.gdb2ca164c4-goog
+
diff --git a/recipes-phosphor/ipmi/phosphor-ipmi-host/0011-Fix-out-of-bounds-read-in-ChannelConfig-methods.patch b/recipes-phosphor/ipmi/phosphor-ipmi-host/0011-Fix-out-of-bounds-read-in-ChannelConfig-methods.patch
new file mode 100644
index 0000000..004881d
--- /dev/null
+++ b/recipes-phosphor/ipmi/phosphor-ipmi-host/0011-Fix-out-of-bounds-read-in-ChannelConfig-methods.patch
@@ -0,0 +1,65 @@
+From 501a7d587641c4f274874e9fa5b30cc678650576 Mon Sep 17 00:00:00 2001
+From: Willy Tu <wltu@google.com>
+Date: Fri, 12 Jun 2026 04:55:46 +0000
+Subject: [PATCH 2/3] Fix out-of-bounds read in ChannelConfig methods
+
+Make sure it doesn't access invalid
+channelData[chNum].chInfo.sessionSupported.
+
+Change-Id: I583b6a4b361136f5c55464f58d8f512b01d91d24
+Signed-off-by: Willy Tu <wltu@google.com>
+---
+ user_channel/channel_mgmt.cpp | 16 ++++++++++++++++
+ 1 file changed, 16 insertions(+)
+
+diff --git a/user_channel/channel_mgmt.cpp b/user_channel/channel_mgmt.cpp
+index 50505aa..5c1065a 100644
+--- a/user_channel/channel_mgmt.cpp
++++ b/user_channel/channel_mgmt.cpp
+@@ -395,6 +395,10 @@ bool ChannelConfig::isValidChannel(const uint8_t chNum)
+ EChannelSessSupported
+     ChannelConfig::getChannelSessionSupport(const uint8_t chNum)
+ {
++    if (chNum >= maxIpmiChannels)
++    {
++        return EChannelSessSupported::none;
++    }
+     EChannelSessSupported chSessSupport =
+         (EChannelSessSupported)channelData[chNum].chInfo.sessionSupported;
+     return chSessSupport;
+@@ -403,6 +407,10 @@ EChannelSessSupported
+ bool ChannelConfig::isValidAuthType(const uint8_t chNum,
+                                     const EAuthType& authType)
+ {
++    if (chNum >= maxIpmiChannels)
++    {
++        return false;
++    }
+     if ((authType < EAuthType::md2) || (authType > EAuthType::oem))
+     {
+         log<level::DEBUG>("Invalid authentication type");
+@@ -421,6 +429,10 @@ bool ChannelConfig::isValidAuthType(const uint8_t chNum,
+ 
+ int ChannelConfig::getChannelActiveSessions(const uint8_t chNum)
+ {
++    if (chNum >= maxIpmiChannels)
++    {
++        return 0;
++    }
+     // TODO: TEMPORARY FIX
+     // Channels active session count is managed separately
+     // by monitoring channel session which includes LAN and
+@@ -431,6 +443,10 @@ int ChannelConfig::getChannelActiveSessions(const uint8_t chNum)
+ 
+ size_t ChannelConfig::getChannelMaxTransferSize(uint8_t chNum)
+ {
++    if (chNum >= maxIpmiChannels)
++    {
++        return 0;
++    }
+     return channelData[chNum].maxTransferSize;
+ }
+ 
+-- 
+2.54.0.1136.gdb2ca164c4-goog
+
diff --git a/recipes-phosphor/ipmi/phosphor-ipmi-host/0012-Fix-heap-buffer-overflow-in-ipmi_sen_get_sdr.patch b/recipes-phosphor/ipmi/phosphor-ipmi-host/0012-Fix-heap-buffer-overflow-in-ipmi_sen_get_sdr.patch
new file mode 100644
index 0000000..3220f32
--- /dev/null
+++ b/recipes-phosphor/ipmi/phosphor-ipmi-host/0012-Fix-heap-buffer-overflow-in-ipmi_sen_get_sdr.patch
@@ -0,0 +1,40 @@
+From 305ddcefb5afa1cc098c3936bf50bfb6cb26cc9c Mon Sep 17 00:00:00 2001
+From: Willy Tu <wltu@google.com>
+Date: Fri, 12 Jun 2026 04:55:48 +0000
+Subject: [PATCH 3/3] Fix heap-buffer-overflow in ipmi_sen_get_sdr
+
+Change-Id: I980323b0c605476e65cf2eb5badb5f324e58a600
+Signed-off-by: Willy Tu <wltu@google.com>
+---
+ sensorhandler.cpp | 8 ++++++++
+ 1 file changed, 8 insertions(+)
+
+diff --git a/sensorhandler.cpp b/sensorhandler.cpp
+index 5c5af4e..1954774 100644
+--- a/sensorhandler.cpp
++++ b/sensorhandler.cpp
+@@ -1285,6 +1285,10 @@ ipmi_ret_t ipmi_sen_get_sdr(ipmi_netfn_t, ipmi_cmd_t, ipmi_request_t request,
+                             ipmi_response_t response, ipmi_data_len_t data_len,
+                             ipmi_context_t)
+ {
++    if (*data_len < sizeof(get_sdr::GetSdrReq))
++    {
++        return IPMI_CC_REQ_DATA_LEN_INVALID;
++    }
+     ipmi_ret_t ret = IPMI_CC_OK;
+     get_sdr::GetSdrReq* req = (get_sdr::GetSdrReq*)request;
+     get_sdr::GetSdrResp* resp = (get_sdr::GetSdrResp*)response;
+@@ -1429,6 +1433,10 @@ ipmi_ret_t ipmicmdPlatformEvent(ipmi_netfn_t, ipmi_cmd_t,
+     }
+     else
+     {
++        if (*dataLen < sizeof(PlatformEventRequest))
++        {
++            return IPMI_CC_REQ_DATA_LEN_INVALID;
++        }
+         req = reinterpret_cast<PlatformEventRequest*>(request);
+         // TODO GenratorID for IPMB is combination of RqSA and RqLUN
+         generatorID = 0xff;
+-- 
+2.54.0.1136.gdb2ca164c4-goog
+
diff --git a/recipes-phosphor/ipmi/phosphor-ipmi-host_%.bbappend b/recipes-phosphor/ipmi/phosphor-ipmi-host_%.bbappend
index 499de8a..ccb70da 100644
--- a/recipes-phosphor/ipmi/phosphor-ipmi-host_%.bbappend
+++ b/recipes-phosphor/ipmi/phosphor-ipmi-host_%.bbappend
@@ -12,6 +12,9 @@
   file://0007-dbus-sdr-Add-limited-log-on-sensorTree-Resets.patch \
   file://0008-user_mgmt-Recover-corrupted-nv-files.patch \
   file://0009-Remove-GetManagedObject-call-for-fru-sdr.patch \
+  file://0010-Fix-empty-data-access-in-setMgmntCtrlIdStr.patch \
+  file://0011-Fix-out-of-bounds-read-in-ChannelConfig-methods.patch \
+  file://0012-Fix-heap-buffer-overflow-in-ipmi_sen_get_sdr.patch \
 "
 
 EXTRA_OEMESON:append:gbmc = " -Dfru-device-property-override-fru-name=disabled"