STRTAB_BASE_CFG.LOG2SIZE is programmed by the guest through the
emulated SMMUv3 MMIO register interface. Currently the value is
not checked and used directly in smmu_find_ste() for strtab_base
alignment computation with risk that MAKE_64BIT_MASK() runs out
of bounds. On FMT==1 the strtab_size cannot be greater than 64 after
the SPLIT being at minimum 6 (log2size is max 64).

However on FMT=0 path, strtab_size= log2size + 6 can potentially
exceed 64. Let's abort in that case.

Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3632
Signed-off-by: Eric Auger <[email protected]>
---
 hw/arm/smmuv3.c | 8 ++++++++
 1 file changed, 8 insertions(+)

diff --git a/hw/arm/smmuv3.c b/hw/arm/smmuv3.c
index 285e6164a07..5ec3700d0d5 100644
--- a/hw/arm/smmuv3.c
+++ b/hw/arm/smmuv3.c
@@ -1696,6 +1696,14 @@ static MemTxResult smmu_writel(SMMUv3State *s, hwaddr 
offset,
                 s->sid_split = 6;
             }
             s->features |= SMMU_FEATURE_2LVL_STE;
+        } else {
+            uint32_t log2size = FIELD_EX32(data, STRTAB_BASE_CFG, LOG2SIZE);
+
+            if (log2size + 6 > 64) {
+                qemu_log_mask(LOG_GUEST_ERROR,
+                              "Invalid STRTAB_BASE_CFG.LOG2SIZE: %d", 
log2size);
+                g_assert_not_reached();
+            }
         }
         break;
     case A_CMDQ_BASE: /* 64b */
-- 
2.53.0


Reply via email to