git: 4505445ccdb9 - main - bhyve: tpm: allow the last dword of the CRB command buffer
- Go to: [ bottom of page ] [ top of archives ] [ this month ]
Date: Tue, 15 Sep 2026 14:04:57 UTC
The branch main has been updated by kevans:
URL: https://cgit.FreeBSD.org/src/commit/?id=4505445ccdb9555efc23262a971a18ca03486969
commit 4505445ccdb9555efc23262a971a18ca03486969
Author: Quentin Thébault <quentin.thebault@defenso.fr>
AuthorDate: 2026-08-07 14:02:08 +0000
Commit: Kyle Evans <kevans@FreeBSD.org>
CommitDate: 2026-09-15 14:04:28 +0000
bhyve: tpm: allow the last dword of the CRB command buffer
The bounds check rejected any access ending exactly at the end of the
register block, so a four byte write at offset 0xffc was refused,
returning EINVAL and killing the VM.
MFC after: 1 week
PR: 291063
Fixes: 75909086a45d ("bhyve: allow read/write to full CRB buffer")
Sponsored by: Defenso
Signed-off-by: Quentin Thébault <quentin.thebault@defenso.fr>
Reviewed-by: aokblast, kevans, markj
Pull-Request: https://github.com/freebsd/freebsd-src/pull/2362
---
usr.sbin/bhyve/tpm_intf_crb.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/usr.sbin/bhyve/tpm_intf_crb.c b/usr.sbin/bhyve/tpm_intf_crb.c
index 7058b47733f3..ef1a3a6bf34a 100644
--- a/usr.sbin/bhyve/tpm_intf_crb.c
+++ b/usr.sbin/bhyve/tpm_intf_crb.c
@@ -321,7 +321,7 @@ tpm_crb_mem_handler(struct vcpu *vcpu __unused, const int dir,
crb = arg1;
off = addr - TPM_CRB_ADDRESS;
- if (off > TPM_CRB_REGS_SIZE || off + size >= TPM_CRB_REGS_SIZE) {
+ if (off > TPM_CRB_REGS_SIZE || off + size > TPM_CRB_REGS_SIZE) {
return (EINVAL);
}