β¬’ DragonFlyBSD Kernel Audit
← triage Β· dashboard
DF-1415

Unchecked gpio pin count from u16 structuresize indexes fixed gpio_pin[8] array

Summary

atom_gpio_pin_lut_v2_1 has gpio_pin[8]. count=(structuresize-header)/sizeof(pin) from BIOS u16. get_gpio_i2c_info :363 and get_gpio_pin_info :529 loop i<count. structuresize=0xffff -> count~8191. OOB read up to 64KB past validated window. Crafted VBIOS. Fix: cap count<=ARRAY_SIZE(gpio_pin).

Discussion (0)

No comments yet.

PoC verification

Evidence pack

findings/poc/DF-1415 Β· 8 files
FileTypeDescriptionSize
fix.diff suggested-fix Cap gpio pin count to ARRAY_SIZE(header->asGPIO_Pin) before iterating. 556 B view raw
VERDICT.md verdict Full source-trace analysis 1.9 KB ↓ raw
build.sh build-script Kernel build validation 550 B view raw
run.sh run-script PoC runner (not runnable on guest) 472 B view raw
fix_build.log build-log Full kernel build output (make nativekernel rc=0) 5.6 MB ↓ download
env.txt environment Guest environment 277 B view raw
../fix_build_combined.log build-log Combined 41-finding kernel build (rc=0, -Werror clean) 5.6 MB ↓ download
../fix_build_summary.txt build-summary Summary of the combined 41-finding kernel build 826 B view raw
VERDICT.md verdict Full source-trace analysis
↓ download raw

DF-1415 β€” Verification Verdict

Verdict: CONFIRMED-BY-SOURCE-TRACE (HW-gated)

Status: inconclusive (HW-gated / not reachable as unprivileged maxx) Impact: none (cannot reproduce on QEMU guest β€” no GPU/HW, or root/operator-only) Confidence: certain (source-trace confirmed bug is real)

Mechanism

atom_gpio_pin_lut_v2_1 has gpio_pin[8]. count=(structuresize-header)/sizeof(pin) from BIOS u16 at :1812. get_gpio_pin_info (:1816) loops i<count. structuresize=0xffff β†’ count~8191. OOB read up to 64KB past validated window. The sizeof check at :1806 validates header+1 entry only.

Source: sys/dev/drm/amd/display/dc/bios/bios_parser.c:1812-1816

Why it cannot be reproduced on this guest

HW-gated. amdgpu display module requires AMD GPU. No GPU in QEMU guest.

Phase 6: Escalation Assessment

This is a HW-gated GPU module (amdgpu display DC BIOS) finding. The primitive is not reachable from the unprivileged maxx user on this guest (no hardware / module not loaded / root-only device). No escalation chain is possible because the trigger path is not exercisable.

For GPU findings: the module (radeon.ko/amdgpu.ko/i915.ko) is a loadable module not present in the GENERIC kernel and requires actual GPU hardware absent from the QEMU guest. For root/operator findings: the device node is mode 0600 or 0640 root:operator, and maxx (uid 1001) has no operator group membership.

Fix

Cap count <= ARRAY_SIZE(header->asGPIO_Pin) (=8) before looping.

Fix description: Cap gpio pin count to ARRAY_SIZE(header->asGPIO_Pin) before iterating.

The full git-apply-able diff is in fix.diff. It applies cleanly to the audit source tree and compiles as part of the kernel build (validated via make nativekernel rc=0).

Classification

  • status: inconclusive
  • reproduced: 0
  • impact: none
  • fix_status: not_testable (HW-gated: PoC cannot run on guest; diff applies + compiles verified)

Confirmed kernel references

Detail

Exploit chain

none (OOB heap read / info leak β€” read-only. HW-gated: crafted VBIOS on AMD GPU. Not reachable from QEMU.)

Evidence (decisive lines)

Source trace: bios_parser.c:1812 'count = (le16_to_cpu(header->sHeader.usStructureSize) - sizeof(ATOM_COMMON_TABLE_HEADER)) / sizeof(ATOM_GPIO_PIN_ASSIGNMENT)' β€” no cap. :1816 'for (i = 0; i < count; ++i)' with header->asGPIO_Pin[8].

PoC changes

Authored fix.diff: cap count <= ARRAY_SIZE(header->asGPIO_Pin) (=8) before looping in get_gpio_pin_info.

Verified recommended fix

Cap gpio pin count to ARRAY_SIZE(header->asGPIO_Pin) before iterating. matches finding proposal. Full diff in findings/poc/DF-1415/fix.diff.

Verdict

CONFIRMED BY SOURCE TRACE. atom_gpio_pin_lut_v2_1 has gpio_pin[8]. count=(structuresize-header)/sizeof(pin) from BIOS u16 at :1812. get_gpio_pin_info (:1816) loops i<count. structuresize=0xffff β†’ count~8191 β†’ OOB read up to 64KB. Bug is real but HW-gated: amdgpu display module requires AMD GPU.