From 795acbcc88a4ac789c41d445e1180e30038d2ee4 Mon Sep 17 00:00:00 2001 From: Khalid Ali Date: Thu, 23 Apr 2026 18:50:42 +0000 Subject: [PATCH 1/3] [Cherry-pick] StandaloneMmPkg: Fix possible infinite loop due invalid hob The second call to CreateMmFoundationHobList () expects the address of the beginning of the platform hob list in the third parameter. However it has being given the beginning of the HobList which is PHIT. This causes later wrong address calculations which in turns puts MM core in infinite loop, because the IPL passed hob without EFI_HOB_TYPE_END_OF_HOB_LIST. Signed-off-by: Khalid Ali (cherry picked from commit 962c1f2) --- StandaloneMmPkg/Drivers/StandaloneMmIplPei/StandaloneMmIplPei.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/StandaloneMmPkg/Drivers/StandaloneMmIplPei/StandaloneMmIplPei.c b/StandaloneMmPkg/Drivers/StandaloneMmIplPei/StandaloneMmIplPei.c index e71fc42981..e658d01a68 100644 --- a/StandaloneMmPkg/Drivers/StandaloneMmIplPei/StandaloneMmIplPei.c +++ b/StandaloneMmPkg/Drivers/StandaloneMmIplPei/StandaloneMmIplPei.c @@ -551,7 +551,7 @@ CreateMmHobList ( Status = CreateMmFoundationHobList ( (UINT8 *)HobList + PhitHobSize + PlatformHobSize, &FoundationHobSize, - HobList, + (UINT8 *)HobList + PhitHobSize, PlatformHobSize, MmFvBase, MmFvSize, From 0aa1c1e08ba06622741f8b41970ee3f38268a83d Mon Sep 17 00:00:00 2001 From: Khalid Ali Date: Mon, 26 Jan 2026 16:17:36 +0000 Subject: [PATCH 2/3] [Cherry-pick] StandaloneMmPkg/Core: Move MMI depth tracker below MMI check Fixes: #11764 Currently, mMmiManageCallingDepth is incremented always whether MMI handler is present or not. However get decremented only when MMI handler is found. This causes mMmiManageCallingDepth to grow infinitely as long as MMI handler isn't present. Increment mMmiManageCallingDepth only when MMI handler presence is confirmed. Signed-off-by: Khalid Ali (cherry picked from commit 05cec0b) --- StandaloneMmPkg/Core/Mmi.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/StandaloneMmPkg/Core/Mmi.c b/StandaloneMmPkg/Core/Mmi.c index fb205df490..47ef20df78 100644 --- a/StandaloneMmPkg/Core/Mmi.c +++ b/StandaloneMmPkg/Core/Mmi.c @@ -173,7 +173,6 @@ MmiManage ( BOOLEAN WillReturn; EFI_STATUS Status; - mMmiManageCallingDepth++; WillReturn = FALSE; Status = EFI_NOT_FOUND; ReturnStatus = Status; @@ -198,6 +197,7 @@ MmiManage ( Head = &MmiEntry->MmiHandlers; } + mMmiManageCallingDepth++; for (Link = Head->ForwardLink; Link != Head; Link = Link->ForwardLink) { MmiHandler = CR (Link, MMI_HANDLER, Link, MMI_HANDLER_SIGNATURE); From 4c82fcebc8e13321571f3a81c212195a89f0a5bf Mon Sep 17 00:00:00 2001 From: Khalid Ali Date: Mon, 26 Jan 2026 16:07:50 +0000 Subject: [PATCH 3/3] [cherry-pick] MdeModulePkg/Core: Move SMI depth tracker below SMI presence check Fixes: #11764 Currently, mSmiManageCallingDepth is incremented always whether SMI handler is present or not. However get decremented only when SMI handler is found. This causes mSmiManageCallingDepth to grow infinitely as long as SMI handler isn't present. Increment mSmiManageCallingDepth only when SMI handler presence is confirmed. Signed-off-by: Khalid Ali (cherry picked from commit bd8667a) --- MdeModulePkg/Core/PiSmmCore/Smi.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/MdeModulePkg/Core/PiSmmCore/Smi.c b/MdeModulePkg/Core/PiSmmCore/Smi.c index 6b56fa5f69..de2c8a52de 100644 --- a/MdeModulePkg/Core/PiSmmCore/Smi.c +++ b/MdeModulePkg/Core/PiSmmCore/Smi.c @@ -151,7 +151,6 @@ SmiManage ( EFI_STATUS Status; PERF_FUNCTION_BEGIN (); - mSmiManageCallingDepth++; WillReturn = FALSE; Status = EFI_NOT_FOUND; ReturnStatus = Status; @@ -175,6 +174,7 @@ SmiManage ( } Head = &SmiEntry->SmiHandlers; + mSmiManageCallingDepth++; for (Link = Head->ForwardLink; Link != Head; Link = Link->ForwardLink) { SmiHandler = CR (Link, SMI_HANDLER, Link, SMI_HANDLER_SIGNATURE);