Commit 007a9c7fce for qemu.org
commit 007a9c7fce1701f7631cc8717cb37434f653825f
Author: Stefan Berger <stefanb@linux.vnet.ibm.com>
Date: Fri Oct 2 10:25:15 2026 -0400
hw/tpm: crb: Consider response_buffer->len of received response
When the CRB receives a TPM reponse from the backend, then reject responses
that are shorter than the TPM_HEADER_SIZE. When determining the size of the
reponse, also consider the length of the response_buffer as being possibly
shorter than the negotiated backend buffer size or the size indicated in
the response itself.
Fixes: 2a660ad67d15 ("hw/tpm: Implement TPM CRB chunking logic")
Reviewed-by: Marc-André Lureau <marcandre.lureau@redhat.com>
Link: https://lore.kernel.org/qemu-devel/20261002142516.2063735-10-stefanb@linux.ibm.com
Signed-off-by: Stefan Berger <stefanb@linux.ibm.com>
diff --git a/hw/tpm/tpm_crb.c b/hw/tpm/tpm_crb.c
index 5c50a79936..78db220520 100644
--- a/hw/tpm/tpm_crb.c
+++ b/hw/tpm/tpm_crb.c
@@ -323,13 +323,15 @@ static void tpm_crb_request_completed(TPMIf *ti, int ret)
CRBState *s = CRB(ti);
ARRAY_FIELD_DP32(s->regs, CRB_CTRL_START, Start, 0);
- if (ret != 0) {
+ if (ret != 0 || s->response_buffer->len < TPM_HEADER_SIZE) {
ARRAY_FIELD_DP32(s->regs, CRB_CTRL_STS,
tpmSts, 1); /* fatal error */
tpm_crb_clear_internal_buffers(s);
} else {
uint32_t actual_resp_size = tpm_cmd_get_size(s->response_buffer->data);
uint32_t total_resp_size = MIN(actual_resp_size, s->be_buffer_size);
+
+ total_resp_size = MIN(total_resp_size, s->response_buffer->len);
g_byte_array_set_size(s->response_buffer, total_resp_size);
s->response_offset = 0;
}