fix(esp_tee): Add missing input validation checks for TEE service calls

- MULTI_HEAP_ASSERT for TEE now aborts on failure, instead of ignoring the condition
- Prevent potential TEE OTA write bounds overflow
This commit is contained in:
Laukik Hase
2026-04-07 10:05:06 +05:30
parent 6ab1721056
commit 145ba4c42d
10 changed files with 416 additions and 154 deletions
@@ -1,10 +1,12 @@
/*
* SPDX-FileCopyrightText: 2025 Espressif Systems (Shanghai) CO LTD
* SPDX-FileCopyrightText: 2025-2026 Espressif Systems (Shanghai) CO LTD
*
* SPDX-License-Identifier: Apache-2.0
*/
#pragma once
#include <stddef.h>
#include <stdint.h>
#include "esp_attr.h"
#include "soc/soc.h"
#include "soc/ext_mem_defs.h"
@@ -16,10 +18,10 @@ extern "C" {
FORCE_INLINE_ATTR bool esp_tee_ptr_in_ree(const void *p)
{
intptr_t addr = (intptr_t)p;
uintptr_t addr = (uintptr_t)p;
return (
(addr >= SOC_NS_IDRAM_START && addr < SOC_NS_IDRAM_END) ||
(addr >= (intptr_t)esp_tee_app_config.ns_drom_start &&
(addr >= (uintptr_t)esp_tee_app_config.ns_drom_start &&
addr < SOC_S_MMU_MMAP_RESV_START_VADDR)
#if SOC_RTC_MEM_SUPPORTED
|| (addr >= SOC_RTC_DATA_LOW && addr < SOC_RTC_DATA_HIGH)
@@ -27,6 +29,19 @@ FORCE_INLINE_ATTR bool esp_tee_ptr_in_ree(const void *p)
);
}
FORCE_INLINE_ATTR bool esp_tee_buf_in_ree(const void *p, size_t len)
{
uintptr_t start = (uintptr_t)p;
/* Reject zero-length and overflow */
if (len == 0 || len > (SIZE_MAX - start)) {
return false;
}
return esp_tee_ptr_in_ree(p) &&
esp_tee_ptr_in_ree((const char *)p + len - 1);
}
#ifdef __cplusplus
}
#endif