fix: Validate TA-supplied pointers in secure-kernel syscalls - #252
Merged
tdrozdovsky merged 2 commits intoAug 5, 2026
Merged
Conversation
The copy helpers tee_svc_copy_to_user/tee_svc_copy_from_user and the live crypto syscalls (utee_hash_update/final, utee_cipher_init, cipher update, copy_in_attrs) dereferenced or memcpy'd TA-supplied pointer ranges with their tee_mmu_check_access_rights() guard commented out. A malicious or buggy TA could pass a NULL or wrapping range and drive an out-of-bounds copy in the secure world. This port has no per-TA MMU/MPU context or region table, and every call site requests TEE_MEMORY_ACCESS_ANY_OWNER, so ownership cannot (and is not meant to) be enforced. Implement tee_mmu_check_access_rights() as the accessibility check that is meaningful here - reject NULL+len and address-space-wrapping ranges, mirroring cmse_check_address_range()'s end-of-range test on the non-secure boundary - and restore the guard at every live call site, including the copy_in_attrs path that stores unvalidated attribute buffers later memcpy'd by op_attr_secret_value_from_user. Add a temporary CONFIG_APPS_ACCESS_RIGHTS_TEST negative test (mps2 AN505) that drives the guard with malformed ranges and asserts TEE_ERROR_ACCESS_DENIED. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
The CONFIG_APPS_ACCESS_RIGHTS_TEST app was a throwaway negative test for the guard added in the previous commit. The guard is now verified (host logic tests + on-target mps2 AN505 QEMU run, all cases rejected/accepted as expected), so drop the app and its build/menu wiring. The core guard in tee_svc.c / tee_svc_cryp.c is unaffected. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The copy helpers tee_svc_copy_to_user/tee_svc_copy_from_user and the live crypto syscalls (utee_hash_update/final, utee_cipher_init, cipher update, copy_in_attrs) dereferenced or memcpy'd TA-supplied pointer ranges with their tee_mmu_check_access_rights() guard commented out. A malicious or buggy TA could pass a NULL or wrapping range and drive an out-of-bounds copy in the secure world.
This port has no per-TA MMU/MPU context or region table, and every call site requests TEE_MEMORY_ACCESS_ANY_OWNER, so ownership cannot (and is not meant to) be enforced. Implement tee_mmu_check_access_rights() as the accessibility check that is meaningful here - reject NULL+len and address-space-wrapping ranges, mirroring cmse_check_address_range()'s end-of-range test on the non-secure boundary - and restore the guard at every live call site, including the copy_in_attrs path that stores unvalidated attribute buffers later memcpy'd by op_attr_secret_value_from_user.
Add a temporary CONFIG_APPS_ACCESS_RIGHTS_TEST negative test (mps2 AN505) that drives the guard with malformed ranges and asserts TEE_ERROR_ACCESS_DENIED.
Description
Please include a summary of the change and which issue is fixed. Please also include relevant motivation and context. List any dependencies that are required for this change.
Fixes # (issue)
Type of change
Please delete options that are not relevant.
How Has This Been Tested?
Please describe the tests that you ran to verify your changes. Provide instructions so we can reproduce. Please also list any relevant details for your test configuration
Test Configuration:
Checklist: