[lvc-project] [PATCH] crypto: keembay-ocs: prevent underflow in sg_data_total - remainder
Fedor Pchelkin
pchelkin at ispras.ru
Tue Sep 8 17:59:38 MSK 2026
On Tue, 08. Sep 17:34, Dmitriy Okunev wrote:
> In the kmb_ocs_dma_prepare() function, the `remainder` is calculated
> as `total % blk_sz`, where `total = sg_data_total + buf_cnt`. In
> update requests, if `buf_cnt` is large and `total` is less than
> `rctx->blk_sz`, the `remainder` may exceed `sg_data_total`, which
> will lead to an overflow of `sg_data_total - remainder`. This results
> in an incorrect large value being passed to the `sg_nents_for_len()`
> function, which can lead to memory corruption.
>
> Add a check to return -EINVAL if `sg_data_total < remainder`,
> so that the subtraction is always safe.
>
> Found by Linux Verification Center (linuxtesting.org) with SVACE.
>
> Fixes: 472b04444cd3 ("crypto: keembay - Add Keem Bay OCS HCU driver")
> Signed-off-by: Dmitriy Okunev <dokunevdmitriy at gmail.com>
Для будущих патчей: адресаты при отправке патча в апстрим (master ветку
ядра) не совсем то, что адресаты при отправке патча в stable. Сейчас вы
указали адресатов как для stable (хотя апстримные мэйнтейнеры есть в
копии, но всё же).
Переотправлять не надо.
Для апстрима:
https://gitlab.linuxtesting.ru/lvc/guides/-/blob/clarify-lvc-patch-process/lvc_kernel/patch_dev_upstream.md#идентификация-адресатов
При портировании апстримного патча в stable:
https://gitlab.linuxtesting.ru/lvc/guides/-/blob/clarify-lvc-patch-process/lvc_kernel/patch_dev_stable_porting.md#идентификация-адресатов
More information about the lvc-project
mailing list