Commit 1c4908f613 for qemu.org
commit 1c4908f61367f5989143d7746f29ea07f8e02189
Author: Stefan Berger <stefanb@linux.vnet.ibm.com>
Date: Fri Oct 2 10:25:13 2026 -0400
hw/tpm: crb: Avoid potential integer underflow
Avoid a potential integer underflow in tpm_crb_fill_command_response
that could occur if s->response_offset > s->response_buffer->len and
the function's call sites were to change.
tpm_crb_fill_command_response currently has 3 callers that either test
that 's->response_offset < s->response_buffer->len' is true or ensure that
s->response_offset = 0 and s->response_buffer->len >= 0. Therefore, the
integer underflow cannot currently occur. In the worst case the subtraction
would lead to a '0'.
Reviewed-by: Marc-André Lureau <marcandre.lureau@redhat.com>
Link: https://lore.kernel.org/qemu-devel/20261002142516.2063735-8-stefanb@linux.ibm.com
Signed-off-by: Stefan Berger <stefanb@linux.ibm.com>
diff --git a/hw/tpm/tpm_crb.c b/hw/tpm/tpm_crb.c
index daf451aa56..cd46b2e888 100644
--- a/hw/tpm/tpm_crb.c
+++ b/hw/tpm/tpm_crb.c
@@ -180,10 +180,17 @@ static void tpm_crb_fill_command_response(CRBState *s)
* to the linux guest in chunks by writing it back to MMIO region.
*/
void *mem = memory_region_get_ram_ptr(&s->cmdmem);
- uint32_t remaining = s->response_buffer->len - s->response_offset;
- uint32_t to_copy = MIN(CRB_CTRL_CMD_SIZE, remaining);
+ uint32_t remaining = 0;
+ uint32_t to_copy;
- memcpy(mem, s->response_buffer->data + s->response_offset, to_copy);
+ if (s->response_offset < s->response_buffer->len) {
+ remaining = s->response_buffer->len - s->response_offset;
+ }
+ to_copy = MIN(CRB_CTRL_CMD_SIZE, remaining);
+
+ if (to_copy) {
+ memcpy(mem, s->response_buffer->data + s->response_offset, to_copy);
+ }
if (to_copy < CRB_CTRL_CMD_SIZE) {
memset((guint8 *)mem + to_copy, 0, CRB_CTRL_CMD_SIZE - to_copy);