[lvc-project] [PATCH] crypto: keembay-ocs: prevent underflow in sg_data_total - remainder

Fedor Pchelkin pchelkin at ispras.ru
Tue Sep 8 17:59:38 MSK 2026


On Tue, 08. Sep 17:34, Dmitriy Okunev wrote:
> In the kmb_ocs_dma_prepare() function, the `remainder` is calculated
> as `total % blk_sz`, where `total = sg_data_total + buf_cnt`. In
> update requests, if `buf_cnt` is large and `total` is less than
> `rctx->blk_sz`, the `remainder` may exceed `sg_data_total`, which
> will lead to an overflow of `sg_data_total - remainder`. This results
> in an incorrect large value being passed to the `sg_nents_for_len()`
> function, which can lead to memory corruption.
> 
> Add a check to return -EINVAL if `sg_data_total < remainder`,
> so that the subtraction is always safe.
> 
> Found by Linux Verification Center (linuxtesting.org) with SVACE.
> 
> Fixes: 472b04444cd3 ("crypto: keembay - Add Keem Bay OCS HCU driver")
> Signed-off-by: Dmitriy Okunev <dokunevdmitriy at gmail.com>

Для будущих патчей: адресаты при отправке патча в апстрим (master ветку
ядра) не совсем то, что адресаты при отправке патча в stable.  Сейчас вы
указали адресатов как для stable (хотя апстримные мэйнтейнеры есть в
копии, но всё же).

Переотправлять не надо.

Для апстрима:
https://gitlab.linuxtesting.ru/lvc/guides/-/blob/clarify-lvc-patch-process/lvc_kernel/patch_dev_upstream.md#идентификация-адресатов

При портировании апстримного патча в stable:
https://gitlab.linuxtesting.ru/lvc/guides/-/blob/clarify-lvc-patch-process/lvc_kernel/patch_dev_stable_porting.md#идентификация-адресатов



More information about the lvc-project mailing list