fix(armv8m): Reject undersized secure stack in AllocateContext (#1474)

Gate against undersized stack values which do not account for fixed values.

Thanks @aggarg for the help developing this!
This commit is contained in:
Kody Stribrny 2026-08-21 09:38:33 -07:00 • committed by GitHub
parent 5f109e6f55
commit ce36e04208
No known key found for this signature in database
GPG key ID: B5690EEEBB952194
15 changed files with 75 additions and 15 deletions

View file

@ -214,8 +214,12 @@ secureportNON_SECURE_CALLABLE void SecureContext_Init( void )
if( ulSecureContextIndex < secureconfigMAX_SECURE_CONTEXTS )
{
/* Allocate the stack space if possible. */
if( ulSecureStackSize > ( UINT32_MAX - securecontextSTACK_SEAL_SIZE ) )
if( ( ulSecureStackSize < securecontextSTACK_SEAL_SIZE ) ||
( ulSecureStackSize > ( UINT32_MAX - securecontextSTACK_SEAL_SIZE ) ) )
{
/* Reject stacks that are too small (the CONTROL word would be
* written before the allocation, corrupting the secure heap)
* and sizes that would overflow when the seal size is added. */
pucStackMemory = NULL;
}
else

View file

@ -214,8 +214,12 @@ secureportNON_SECURE_CALLABLE void SecureContext_Init( void )
if( ulSecureContextIndex < secureconfigMAX_SECURE_CONTEXTS )
{
/* Allocate the stack space if possible. */
if( ulSecureStackSize > ( UINT32_MAX - securecontextSTACK_SEAL_SIZE ) )
if( ( ulSecureStackSize < securecontextSTACK_SEAL_SIZE ) ||
( ulSecureStackSize > ( UINT32_MAX - securecontextSTACK_SEAL_SIZE ) ) )
{
/* Reject stacks that are too small (the CONTROL word would be
* written before the allocation, corrupting the secure heap)
* and sizes that would overflow when the seal size is added. */
pucStackMemory = NULL;
}
else

View file

@ -214,8 +214,12 @@ secureportNON_SECURE_CALLABLE void SecureContext_Init( void )
if( ulSecureContextIndex < secureconfigMAX_SECURE_CONTEXTS )
{
/* Allocate the stack space if possible. */
if( ulSecureStackSize > ( UINT32_MAX - securecontextSTACK_SEAL_SIZE ) )
if( ( ulSecureStackSize < securecontextSTACK_SEAL_SIZE ) ||
( ulSecureStackSize > ( UINT32_MAX - securecontextSTACK_SEAL_SIZE ) ) )
{
/* Reject stacks that are too small (the CONTROL word would be
* written before the allocation, corrupting the secure heap)
* and sizes that would overflow when the seal size is added. */
pucStackMemory = NULL;
}
else

View file

@ -214,8 +214,12 @@ secureportNON_SECURE_CALLABLE void SecureContext_Init( void )
if( ulSecureContextIndex < secureconfigMAX_SECURE_CONTEXTS )
{
/* Allocate the stack space if possible. */
if( ulSecureStackSize > ( UINT32_MAX - securecontextSTACK_SEAL_SIZE ) )
if( ( ulSecureStackSize < securecontextSTACK_SEAL_SIZE ) ||
( ulSecureStackSize > ( UINT32_MAX - securecontextSTACK_SEAL_SIZE ) ) )
{
/* Reject stacks that are too small (the CONTROL word would be
* written before the allocation, corrupting the secure heap)
* and sizes that would overflow when the seal size is added. */
pucStackMemory = NULL;
}
else

View file

@ -214,8 +214,12 @@ secureportNON_SECURE_CALLABLE void SecureContext_Init( void )
if( ulSecureContextIndex < secureconfigMAX_SECURE_CONTEXTS )
{
/* Allocate the stack space if possible. */
if( ulSecureStackSize > ( UINT32_MAX - securecontextSTACK_SEAL_SIZE ) )
if( ( ulSecureStackSize < securecontextSTACK_SEAL_SIZE ) ||
( ulSecureStackSize > ( UINT32_MAX - securecontextSTACK_SEAL_SIZE ) ) )
{
/* Reject stacks that are too small (the CONTROL word would be
* written before the allocation, corrupting the secure heap)
* and sizes that would overflow when the seal size is added. */
pucStackMemory = NULL;
}
else

View file

@ -214,8 +214,12 @@ secureportNON_SECURE_CALLABLE void SecureContext_Init( void )
if( ulSecureContextIndex < secureconfigMAX_SECURE_CONTEXTS )
{
/* Allocate the stack space if possible. */
if( ulSecureStackSize > ( UINT32_MAX - securecontextSTACK_SEAL_SIZE ) )
if( ( ulSecureStackSize < securecontextSTACK_SEAL_SIZE ) ||
( ulSecureStackSize > ( UINT32_MAX - securecontextSTACK_SEAL_SIZE ) ) )
{
/* Reject stacks that are too small (the CONTROL word would be
* written before the allocation, corrupting the secure heap)
* and sizes that would overflow when the seal size is added. */
pucStackMemory = NULL;
}
else

View file

@ -214,8 +214,12 @@ secureportNON_SECURE_CALLABLE void SecureContext_Init( void )
if( ulSecureContextIndex < secureconfigMAX_SECURE_CONTEXTS )
{
/* Allocate the stack space if possible. */
if( ulSecureStackSize > ( UINT32_MAX - securecontextSTACK_SEAL_SIZE ) )
if( ( ulSecureStackSize < securecontextSTACK_SEAL_SIZE ) ||
( ulSecureStackSize > ( UINT32_MAX - securecontextSTACK_SEAL_SIZE ) ) )
{
/* Reject stacks that are too small (the CONTROL word would be
* written before the allocation, corrupting the secure heap)
* and sizes that would overflow when the seal size is added. */
pucStackMemory = NULL;
}
else