fix ipmi out of bound access Tested: Builds Google-Bug-Id: 450349095 Google-Bug-Id: 450351038 Google-Bug-Id: 450349110 Change-Id: I0c1a1caef4feeefd4a51abb0f45df064d5e0e8fc Signed-off-by: Willy Tu <wltu@google.com>
diff --git a/recipes-phosphor/ipmi/phosphor-ipmi-host/0010-Fix-empty-data-access-in-setMgmntCtrlIdStr.patch b/recipes-phosphor/ipmi/phosphor-ipmi-host/0010-Fix-empty-data-access-in-setMgmntCtrlIdStr.patch new file mode 100644 index 0000000..db0d5cb --- /dev/null +++ b/recipes-phosphor/ipmi/phosphor-ipmi-host/0010-Fix-empty-data-access-in-setMgmntCtrlIdStr.patch
@@ -0,0 +1,43 @@ +From 8051dc1d0aa16dd42f3df6b9686a7948963876d0 Mon Sep 17 00:00:00 2001 +From: Willy Tu <wltu@google.com> +Date: Fri, 12 Jun 2026 04:55:45 +0000 +Subject: [PATCH 1/3] Fix empty data access in setMgmntCtrlIdStr + +Make sure we don't access the back of empty data vector. +The terminalWrite variable is undefined when the empty vector.back() +is accessed. + +Change-Id: Iefb9c8b6ed2a8f23d9cae2281a438c3ea8285184 +Signed-off-by: Willy Tu <wltu@google.com> +--- + dcmihandler.cpp | 13 +++++++++---- + 1 file changed, 9 insertions(+), 4 deletions(-) + +diff --git a/dcmihandler.cpp b/dcmihandler.cpp +index e45ea3f..620fb74 100644 +--- a/dcmihandler.cpp ++++ b/dcmihandler.cpp +@@ -594,11 +594,16 @@ ipmi::RspType<uint8_t> setMgmntCtrlIdStr(ipmi::Context::ptr& ctx, + { + return ipmi::responseReqDataLenInvalid(); + } +- bool terminalWrite{data.back() == '\0'}; +- if (terminalWrite) ++ bool terminalWrite = false; ++ if (!data.empty()) + { +- // remove the null termination from the data (no need with std::string) +- data.resize(count - 1); ++ terminalWrite = (data.back() == '\0'); ++ if (terminalWrite) ++ { ++ // remove the null termination from the data (no need with ++ // std::string) ++ data.resize(count - 1); ++ } + } + + static std::string hostname{}; +-- +2.54.0.1136.gdb2ca164c4-goog +
diff --git a/recipes-phosphor/ipmi/phosphor-ipmi-host/0011-Fix-out-of-bounds-read-in-ChannelConfig-methods.patch b/recipes-phosphor/ipmi/phosphor-ipmi-host/0011-Fix-out-of-bounds-read-in-ChannelConfig-methods.patch new file mode 100644 index 0000000..004881d --- /dev/null +++ b/recipes-phosphor/ipmi/phosphor-ipmi-host/0011-Fix-out-of-bounds-read-in-ChannelConfig-methods.patch
@@ -0,0 +1,65 @@ +From 501a7d587641c4f274874e9fa5b30cc678650576 Mon Sep 17 00:00:00 2001 +From: Willy Tu <wltu@google.com> +Date: Fri, 12 Jun 2026 04:55:46 +0000 +Subject: [PATCH 2/3] Fix out-of-bounds read in ChannelConfig methods + +Make sure it doesn't access invalid +channelData[chNum].chInfo.sessionSupported. + +Change-Id: I583b6a4b361136f5c55464f58d8f512b01d91d24 +Signed-off-by: Willy Tu <wltu@google.com> +--- + user_channel/channel_mgmt.cpp | 16 ++++++++++++++++ + 1 file changed, 16 insertions(+) + +diff --git a/user_channel/channel_mgmt.cpp b/user_channel/channel_mgmt.cpp +index 50505aa..5c1065a 100644 +--- a/user_channel/channel_mgmt.cpp ++++ b/user_channel/channel_mgmt.cpp +@@ -395,6 +395,10 @@ bool ChannelConfig::isValidChannel(const uint8_t chNum) + EChannelSessSupported + ChannelConfig::getChannelSessionSupport(const uint8_t chNum) + { ++ if (chNum >= maxIpmiChannels) ++ { ++ return EChannelSessSupported::none; ++ } + EChannelSessSupported chSessSupport = + (EChannelSessSupported)channelData[chNum].chInfo.sessionSupported; + return chSessSupport; +@@ -403,6 +407,10 @@ EChannelSessSupported + bool ChannelConfig::isValidAuthType(const uint8_t chNum, + const EAuthType& authType) + { ++ if (chNum >= maxIpmiChannels) ++ { ++ return false; ++ } + if ((authType < EAuthType::md2) || (authType > EAuthType::oem)) + { + log<level::DEBUG>("Invalid authentication type"); +@@ -421,6 +429,10 @@ bool ChannelConfig::isValidAuthType(const uint8_t chNum, + + int ChannelConfig::getChannelActiveSessions(const uint8_t chNum) + { ++ if (chNum >= maxIpmiChannels) ++ { ++ return 0; ++ } + // TODO: TEMPORARY FIX + // Channels active session count is managed separately + // by monitoring channel session which includes LAN and +@@ -431,6 +443,10 @@ int ChannelConfig::getChannelActiveSessions(const uint8_t chNum) + + size_t ChannelConfig::getChannelMaxTransferSize(uint8_t chNum) + { ++ if (chNum >= maxIpmiChannels) ++ { ++ return 0; ++ } + return channelData[chNum].maxTransferSize; + } + +-- +2.54.0.1136.gdb2ca164c4-goog +
diff --git a/recipes-phosphor/ipmi/phosphor-ipmi-host/0012-Fix-heap-buffer-overflow-in-ipmi_sen_get_sdr.patch b/recipes-phosphor/ipmi/phosphor-ipmi-host/0012-Fix-heap-buffer-overflow-in-ipmi_sen_get_sdr.patch new file mode 100644 index 0000000..3220f32 --- /dev/null +++ b/recipes-phosphor/ipmi/phosphor-ipmi-host/0012-Fix-heap-buffer-overflow-in-ipmi_sen_get_sdr.patch
@@ -0,0 +1,40 @@ +From 305ddcefb5afa1cc098c3936bf50bfb6cb26cc9c Mon Sep 17 00:00:00 2001 +From: Willy Tu <wltu@google.com> +Date: Fri, 12 Jun 2026 04:55:48 +0000 +Subject: [PATCH 3/3] Fix heap-buffer-overflow in ipmi_sen_get_sdr + +Change-Id: I980323b0c605476e65cf2eb5badb5f324e58a600 +Signed-off-by: Willy Tu <wltu@google.com> +--- + sensorhandler.cpp | 8 ++++++++ + 1 file changed, 8 insertions(+) + +diff --git a/sensorhandler.cpp b/sensorhandler.cpp +index 5c5af4e..1954774 100644 +--- a/sensorhandler.cpp ++++ b/sensorhandler.cpp +@@ -1285,6 +1285,10 @@ ipmi_ret_t ipmi_sen_get_sdr(ipmi_netfn_t, ipmi_cmd_t, ipmi_request_t request, + ipmi_response_t response, ipmi_data_len_t data_len, + ipmi_context_t) + { ++ if (*data_len < sizeof(get_sdr::GetSdrReq)) ++ { ++ return IPMI_CC_REQ_DATA_LEN_INVALID; ++ } + ipmi_ret_t ret = IPMI_CC_OK; + get_sdr::GetSdrReq* req = (get_sdr::GetSdrReq*)request; + get_sdr::GetSdrResp* resp = (get_sdr::GetSdrResp*)response; +@@ -1429,6 +1433,10 @@ ipmi_ret_t ipmicmdPlatformEvent(ipmi_netfn_t, ipmi_cmd_t, + } + else + { ++ if (*dataLen < sizeof(PlatformEventRequest)) ++ { ++ return IPMI_CC_REQ_DATA_LEN_INVALID; ++ } + req = reinterpret_cast<PlatformEventRequest*>(request); + // TODO GenratorID for IPMB is combination of RqSA and RqLUN + generatorID = 0xff; +-- +2.54.0.1136.gdb2ca164c4-goog +
diff --git a/recipes-phosphor/ipmi/phosphor-ipmi-host_%.bbappend b/recipes-phosphor/ipmi/phosphor-ipmi-host_%.bbappend index 499de8a..ccb70da 100644 --- a/recipes-phosphor/ipmi/phosphor-ipmi-host_%.bbappend +++ b/recipes-phosphor/ipmi/phosphor-ipmi-host_%.bbappend
@@ -12,6 +12,9 @@ file://0007-dbus-sdr-Add-limited-log-on-sensorTree-Resets.patch \ file://0008-user_mgmt-Recover-corrupted-nv-files.patch \ file://0009-Remove-GetManagedObject-call-for-fru-sdr.patch \ + file://0010-Fix-empty-data-access-in-setMgmntCtrlIdStr.patch \ + file://0011-Fix-out-of-bounds-read-in-ChannelConfig-methods.patch \ + file://0012-Fix-heap-buffer-overflow-in-ipmi_sen_get_sdr.patch \ " EXTRA_OEMESON:append:gbmc = " -Dfru-device-property-override-fru-name=disabled"