[PATCH] lib: sbi_trap_v_ldst: fix mask buffer overflow on VLEN > 128

Sebastian Alba Vives sebasjosue84 at gmail.com
Mon Sep 21 20:06:33 PDT 2026


mask_len counts mask bits: it is derived from vlenb * 8, and the mask
indexing below divides by 8 to turn a bit index into a byte index.
get_vreg() counts bytes: its size argument feeds "vsetvli x0, %0, e8,
m8" and a vse8.v, both of which operate on 8-bit elements.

Both emulators pass mask_len directly as get_vreg()'s size, so the
firmware writes eight times more than intended into mask[], a
MASK_BUFFLEN / 8 == 128 byte stack buffer. The write stays in bounds
only while vlenb * 8 <= 128, that is VLEN <= 128. Above that it runs
past the end of the buffer and corrupts the M-mode stack, including the
saved return address.

The pre-rework code passed vlenb, a byte count, which was correct; the
chunked version replaced it with a bit count.

Reachable from S-mode or U-mode with a single masked, misaligned vector
load or store on a hart whose VLEN exceeds 128 bits. Observed on
qemu-system-riscv64 with -cpu rv64,v=true,vlen=256,zicclsm=false: the
firmware takes an instruction access fault in M-mode with mepc and ra
both zero. The same payload at vlen=128 enters the emulator and
completes normally.

Convert pos and size to bytes at both call sites. mask_len is a power of
two and at least 8, and pos is already a multiple of mask_len, so both
divisions are exact.

Fixes: a8be5e94 ("lib: sbi: Rework misaligned vector load/store")
Signed-off-by: Sebastian Alba Vives <sebasjosue84 at gmail.com>
---
 lib/sbi/sbi_trap_v_ldst.c | 10 ++++++----
 1 file changed, 6 insertions(+), 4 deletions(-)

diff --git a/lib/sbi/sbi_trap_v_ldst.c b/lib/sbi/sbi_trap_v_ldst.c
index 540f655f..9f1c312a 100644
--- a/lib/sbi/sbi_trap_v_ldst.c
+++ b/lib/sbi/sbi_trap_v_ldst.c
@@ -213,8 +213,9 @@ int sbi_misaligned_v_ld_emulator(ulong insn, struct sbi_trap_context *tcntx)
 		if (masked) {
 			if (vstart == orig_vstart || vstart % mask_len == 0)
 				/* Fetch a mask_len chunk of mask */
-				get_vreg(vlenb, 0, vstart / mask_len * mask_len,
-					 mask_len, mask);
+				get_vreg(vlenb, 0,
+					 vstart / mask_len * mask_len / 8,
+					 mask_len / 8, mask);
 
 			if (~mask[vstart % mask_len / 8] & BIT(vstart % 8))
 				continue;
@@ -326,8 +327,9 @@ int sbi_misaligned_v_st_emulator(ulong insn, struct sbi_trap_context *tcntx)
 		if (masked) {
 			if (vstart == orig_vstart || vstart % mask_len == 0)
 				/* Fetch a mask_len chunk of mask */
-				get_vreg(vlenb, 0, vstart / mask_len * mask_len,
-					 mask_len, mask);
+				get_vreg(vlenb, 0,
+					 vstart / mask_len * mask_len / 8,
+					 mask_len / 8, mask);
 
 			if (~mask[vstart % mask_len / 8] & BIT(vstart % 8))
 				continue;

base-commit: 3593a5facc4c6938b90429a6973ba9ee21fc5899
-- 
2.43.0




More information about the opensbi mailing list