DragonFlyBSD Kernel Audit
← triage · dashboard
DF-2325

Signed left-shift undefined behavior in BAR resource sizing when ln2size == 31

Summary

pci_add_map() computes resource sizes as 1<<ln2size where literal 1 is signed int and ln2size can be up to 31 (from pci_mapsize on uint32_t BAR decoding 2 GiB). Shifting signed int into sign bit (1<<31) is UB in C. Typically produces INT_MIN (-2147483648) which when assigned to uint64_t count produces 0xFFFFFFFF80000000 causing wildly incorrect resource sizing. end=base+(1<<31)-1 wraps to value less than base producing inverted start/end range. Malicious PCI hardware reporting 2 GiB memory BAR. Functional DoS device BAR not programmed.

Discussion (0)

No comments yet.