From: Nicolas VINCENT <redacted>
the i2c_ram structure is missing the sdmatmp field mentionned in
datasheet for MPC8272 at paragraph 36.5. With this field missing, the
hardware would write past the allocated memory done through
cpm_muram_alloc for the i2c_ram structure and land in memory allocated
for the buffers descriptors corrupting the cbd_bufaddr field. Since this
field is only set during setup(), the first i2c transaction would work
and the following would send data read from an arbitrary memory
location.
Signed-off-by: Nicolas VINCENT <redacted>
---
drivers/i2c/busses/i2c-cpm.c | 3 +++
1 file changed, 3 insertions(+)
@@ -65,6 +65,9 @@ struct i2c_ram {charres1[4];/* Reserved */ushortrpbase;/* Relocation pointer */charres2[2];/* Reserved */+/* The following elements are only for CPM2 */+charres3[4];/* Reserved */+uintsdmatmp;/* Internal */};#define I2COM_START 0x80
From: Jochen Friedrich <jochen@scram.de> Date: 2020-09-23 14:21:47
Acked-by: Jochen Friedrich <jochen@scram.de>
Am 23.09.2020 um 16:08 schrieb nico.vince@gmail.com:
quoted hunk
From: Nicolas VINCENT <redacted>
the i2c_ram structure is missing the sdmatmp field mentionned in
datasheet for MPC8272 at paragraph 36.5. With this field missing, the
hardware would write past the allocated memory done through
cpm_muram_alloc for the i2c_ram structure and land in memory allocated
for the buffers descriptors corrupting the cbd_bufaddr field. Since this
field is only set during setup(), the first i2c transaction would work
and the following would send data read from an arbitrary memory
location.
Signed-off-by: Nicolas VINCENT <redacted>
---
drivers/i2c/busses/i2c-cpm.c | 3 +++
1 file changed, 3 insertions(+)
@@ -65,6 +65,9 @@ struct i2c_ram {charres1[4];/* Reserved */ushortrpbase;/* Relocation pointer */charres2[2];/* Reserved */+/* The following elements are only for CPM2 */+charres3[4];/* Reserved */+uintsdmatmp;/* Internal */};#define I2COM_START 0x80
From: Wolfram Sang <wsa@kernel.org> Date: 2020-09-23 16:11:10
On Wed, Sep 23, 2020 at 04:08:40PM +0200, nico.vince@gmail.com wrote:
From: Nicolas VINCENT <redacted>
the i2c_ram structure is missing the sdmatmp field mentionned in
datasheet for MPC8272 at paragraph 36.5. With this field missing, the
hardware would write past the allocated memory done through
cpm_muram_alloc for the i2c_ram structure and land in memory allocated
for the buffers descriptors corrupting the cbd_bufaddr field. Since this
field is only set during setup(), the first i2c transaction would work
and the following would send data read from an arbitrary memory
location.
Signed-off-by: Nicolas VINCENT <redacted>
Thanks!
Is someone able to identify a Fixes: tag I could add?
@@ -65,6 +65,9 @@ struct i2c_ram {charres1[4];/* Reserved */ushortrpbase;/* Relocation pointer */charres2[2];/* Reserved */+/* The following elements are only for CPM2 */+charres3[4];/* Reserved */+uintsdmatmp;/* Internal */};#define I2COM_START 0x80
On Wed, Sep 23, 2020 at 04:08:40PM +0200, nico.vince@gmail.com wrote:
quoted
From: Nicolas VINCENT <redacted>
the i2c_ram structure is missing the sdmatmp field mentionned in
datasheet for MPC8272 at paragraph 36.5. With this field missing, the
hardware would write past the allocated memory done through
cpm_muram_alloc for the i2c_ram structure and land in memory allocated
for the buffers descriptors corrupting the cbd_bufaddr field. Since this
field is only set during setup(), the first i2c transaction would work
and the following would send data read from an arbitrary memory
location.
Signed-off-by: Nicolas VINCENT <redacted>
Thanks!
Is someone able to identify a Fixes: tag I could add?
I'd suggest
Fixes: 61045dbe9d8d ("i2c: Add support for I2C bus on Freescale
CPM1/CPM2 controllers")
Christophe
@@ -65,6 +65,9 @@ struct i2c_ram {charres1[4];/* Reserved */ushortrpbase;/* Relocation pointer */charres2[2];/* Reserved */+/* The following elements are only for CPM2 */+charres3[4];/* Reserved */+uintsdmatmp;/* Internal */};#define I2COM_START 0x80
From: Wolfram Sang <wsa@kernel.org> Date: 2020-09-27 13:18:15
On Wed, Sep 23, 2020 at 04:08:40PM +0200, nico.vince@gmail.com wrote:
From: Nicolas VINCENT <redacted>
the i2c_ram structure is missing the sdmatmp field mentionned in
datasheet for MPC8272 at paragraph 36.5. With this field missing, the
hardware would write past the allocated memory done through
cpm_muram_alloc for the i2c_ram structure and land in memory allocated
for the buffers descriptors corrupting the cbd_bufaddr field. Since this
field is only set during setup(), the first i2c transaction would work
and the following would send data read from an arbitrary memory
location.
Signed-off-by: Nicolas VINCENT <redacted>
Fixes tag aded and applied to for-current, thanks everyone!