Repository navigation
Conversation
Clamp copy length to sizeof(info->mName) - 1 to prevent stack buffer overflow when /etc/xocl.txt contains a token longer than 256 bytes. Co-Authored-By: Claude <noreply@anthropic.com> Signed-off-by: Soren Soe <2106410+stsoe@users.noreply.github.com>
Replace blind pop_back() in the catch handler with a targeted find-and- erase of the specific command pointer from either submitted_cmds or running_cmds, depending on whether the monitor thread has already drained it. Prevents UAF when submit() throws concurrently with the monitor loop. Co-Authored-By: Claude <noreply@anthropic.com> Signed-off-by: Soren Soe <2106410+stsoe@users.noreply.github.com>
Change get_or_error() return type from const shared_ptr<ImplType>& to shared_ptr<ImplType> so the owning copy is made while the mutex is held. Returning a reference into the map after dropping the lock allowed a concurrent xrtDeviceClose() to erase the node, leaving a dangling reference at the call site. Co-Authored-By: Claude <noreply@anthropic.com> Signed-off-by: Soren Soe <2106410+stsoe@users.noreply.github.com>
Replace bare std::map instances for graph_cache and profiling_cache with the mutex-protected xrt_core::handle_map, matching the pattern used by xrt_bo.cpp, xrt_kernel.cpp and xrt_xclbin.cpp. Eliminates data races on concurrent open/close and start/stop of AIE graph and profiling handles. Co-Authored-By: Claude <noreply@anthropic.com> Signed-off-by: Soren Soe <2106410+stsoe@users.noreply.github.com>
In init_mems(), init_ips(), and ip_impl::ip_impl(), use get_axlf_section() to obtain the section size and clamp iteration to (size - sizeof(int32_t)) / sizeof(element) entries. sizeof(int32_t) is both the minimum readable size for m_count and the byte offset to the flexible array, as m_count is the only non-array member in each struct. Rejects negative m_count and sections too small to hold the count field. Co-Authored-By: Claude <noreply@anthropic.com> Signed-off-by: Soren Soe <2106410+stsoe@users.noreply.github.com>
Reject connectivity entries with negative arg_index or mem_data_index, or mem_data_index >= mems.size(), by throwing on invalid xclbin data. Also cast argidx to size_t before +1 in add_mem_at_idx() to prevent signed integer overflow when argidx == INT32_MAX. Co-Authored-By: Claude <noreply@anthropic.com> Signed-off-by: Soren Soe <2106410+stsoe@users.noreply.github.com>
Return -EINVAL when len == 0 and out is non-null. Without this guard, len-1 wraps to SIZE_MAX, causing memcpy to write the full error string into the caller's buffer regardless of its capacity. Co-Authored-By: Claude <noreply@anthropic.com> Signed-off-by: Soren Soe <2106410+stsoe@users.noreply.github.com>
Clamp num_uc to the number of ert_uc_health_info entries that fit within the packet payload before iterating in aie_error_message_v1(). Fixed overhead is 5 uint32_t words (version, npu_gen, ctx_state, num_uc, ctx_error_type); remaining words divided by entry size gives the maximum valid entry count. Co-Authored-By: Claude <noreply@anthropic.com> Signed-off-by: Soren Soe <2106410+stsoe@users.noreply.github.com>
Owner
Author
|
Closing in favour of PR against Xilinx/XRT upstream. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem solved by the commit
Security vulnerabilities identified in the AMD XRT AI Engine and common API
layer by an internal security audit (leet campaign, reporter: obittner,
tickets AIESW-42772–42902). This PR fixes the subset of tickets classified
as
xrt:apithat were not blocked on other in-progress work.Bug / issue (if any) fixed, which PR introduced the bug, how it was discovered
Eight issues fixed, all discovered by internal AI-assisted security audit:
core/edge/user/shim.cpp:deviceName.copy()used source length instead of destination capacity (char[256]) — classic stack buffer overflow from/etc/xocl.txt.core/common/api/hw_queue.cpp:launch()catch handler calledpop_back()blindly onsubmitted_cmds, racing with the monitor thread draining it torunning_cmdsor a concurrentlaunch()pushing another entry — UAF on the failed command.core/common/api/handle.h:get_or_error()returnedconst shared_ptr<T>&(a reference into the map) after dropping the mutex — concurrentremove_or_error()could destroy the node leaving a dangling reference. Also fixes downstream callers inxrt_bo.cppandhip/core/graph.hthat re-exposed the reference.core/common/api/aie/xrt_graph.cpp:graph_cacheandprofiling_cachewere barestd::mapglobals with no locking, unlike every other C-API handle table in the directory — concurrent open/close or start/stop caused data races on the red-black tree.core/common/api/xrt_xclbin.cpp:init_mems(),init_ips(), andip_impl::ip_impl()iteratedm_countentries from xclbin sections without bounding against actual section size — OOB heap read with attacker-controlled length.core/common/api/xrt_xclbin.cpp:ip_impl::ip_impl()passedcxn.arg_index(a rawint32_tfrom the xclbin) toadd_mem_at_idx()without sign or range checks — negative index caused OOB write behind the vector,INT32_MAXcaused signed overflow.core/common/api/xrt_error.cpp:xrtErrorGetString()computedlen-1without guarding againstlen==0— unsigned wraparound toSIZE_MAXbypassed the copy-length limit entirely.core/common/api/xrt_kernel.cpp:aie_error_message_v1()iteratedctx_health->aie4.num_uctimes without bounding against the packet payload size — device-suppliednum_uccould drive reads far past the 4 KB exec buffer.How problem was solved, alternative solutions (if any) and why they were rejected
Each fix is minimal and local to the affected function:
copy()length tosizeof(info->mName) - 1.running_cmdsto a class member (guarded bywork_mutex); replace blindpop_back()with targeted find-and-erase from whichever queue still holds the command.get_or_error()return type fromconst shared_ptr<T>&toshared_ptr<T>so the owning copy is made while the mutex is held. Matches the existingget()method.std::mapinstances withxrt_core::handle_map(the existing mutex-protected helper used by all other C-API handle tables).get_axlf_section()(which returns{ptr, size}) instead ofget_section<T>()(which discards size); clamp loop bounds to(size - sizeof(int32_t)) / sizeof(element).std::runtime_error; castargidxtosize_tbefore+1to prevent signed overflow.-EINVALwhenlen == 0andoutis non-null, before thelen-1subtraction.max_ucfromepkt->count(fixed overhead 5 words, 11 words per entry); clampnum_ucwithstd::minbefore the loop.Risks (if any) associated the changes in the commit
get_or_error()by-value is strictly safer (additional refcount);handle_mapwraps the samestd::map+std::mutexpattern already used everywhere else.running_cmdspromoted from monitor-local to class member — no behaviour change under normal operation; only the error path is different.What has been tested and how, request additional testing if necessary
xrt::runmanaged-command tests, xclbin load/parse tests, and any AIE graph multi-thread tests.xrtErrorGetStringwithlen==0, xclbin with exactlyMAX_KERNELSIP entries.Documentation impact (if any)
None.