mirror of
https://github.com/espressif/esp-idf.git
synced 2026-10-01 18:50:34 +03:00
fix(esp_tee): Validate REE-supplied memory bounds (esp_tee_app_config) before use
This commit is contained in:
@@ -16,19 +16,9 @@
|
||||
extern "C" {
|
||||
#endif
|
||||
|
||||
FORCE_INLINE_ATTR bool esp_tee_ptr_in_ree(const void *p)
|
||||
{
|
||||
uintptr_t addr = (uintptr_t)p;
|
||||
return (
|
||||
(addr >= SOC_NS_IDRAM_START && addr < SOC_NS_IDRAM_END) ||
|
||||
(addr >= (uintptr_t)esp_tee_app_config.ns_drom_start &&
|
||||
addr < SOC_S_MMU_MMAP_RESV_START_VADDR)
|
||||
#if SOC_RTC_MEM_SUPPORTED
|
||||
|| (addr >= SOC_RTC_DATA_LOW && addr < SOC_RTC_DATA_HIGH)
|
||||
#endif
|
||||
);
|
||||
}
|
||||
|
||||
/* TODO: Revisit these bounds for high-performance RISC-V SoCs (e.g. ESP32-P4,
|
||||
* ESP32-S31) with different memory maps than current ESP-TEE targets.
|
||||
*/
|
||||
FORCE_INLINE_ATTR bool esp_tee_buf_in_ree(const void *p, size_t len)
|
||||
{
|
||||
uintptr_t start = (uintptr_t)p;
|
||||
@@ -40,13 +30,18 @@ FORCE_INLINE_ATTR bool esp_tee_buf_in_ree(const void *p, size_t len)
|
||||
|
||||
uintptr_t end = start + len;
|
||||
return ((start >= SOC_NS_IDRAM_START && end <= SOC_NS_IDRAM_END) ||
|
||||
(start >= (uintptr_t)esp_tee_app_config.ns_drom_start && end <= SOC_S_MMU_MMAP_RESV_START_VADDR)
|
||||
(start >= SOC_S_DROM_HIGH && end <= SOC_S_MMU_MMAP_RESV_START_VADDR)
|
||||
#if SOC_RTC_MEM_SUPPORTED
|
||||
|| (start >= SOC_RTC_DATA_LOW && end <= SOC_RTC_DATA_HIGH)
|
||||
#endif
|
||||
);
|
||||
}
|
||||
|
||||
FORCE_INLINE_ATTR bool esp_tee_ptr_in_ree(const void *p)
|
||||
{
|
||||
return esp_tee_buf_in_ree(p, 4);
|
||||
}
|
||||
|
||||
#ifdef __cplusplus
|
||||
}
|
||||
#endif
|
||||
|
||||
Reference in New Issue
Block a user