[PATCH] arc: validate DT CPU map strings before parsing them
Pengpeng Hou <[email protected]> Fri, 3 Apr 2026 13:41:47 +0800
| Newsgroups | org.infradead.lists.linux-snps-arc,org.kernel.vger.linux-kernel |
|---|---|
| Message-ID | <[email protected]> |
arc_get_cpu_map() fetches the possible-cpus or present-cpus property from the flat DT and immediately passes the raw pointer to cpulist_parse(). That parser expects a NUL-terminated text buffer, but this path does not prove that the DT property is terminated within its declared bounds. Reject unterminated CPU-map properties before handing them to cpulist_parse(). Signed-off-by: Pengpeng Hou <[email protected]> --- arch/arc/kernel/smp.c | 7 ++++++- 1 file changed, 6 insertions(+), 1 deletion(-) diff --git a/arch/arc/kernel/smp.c b/arch/arc/kernel/smp.c index b2f2c59279a6..e0f8218e9172 100644 --- a/arch/arc/kernel/smp.c +++ b/arch/arc/kernel/smp.c @@ -22,6 +22,7 @@ #include <linux/irqdomain.h> #include <linux/export.h> #include <linux/of_fdt.h> +#include <linux/string.h> #include <asm/mach_desc.h> #include <asm/setup.h> @@ -43,11 +44,15 @@ static int __init arc_get_cpu_map(const char *name, struct cpumask *cpumask) { unsigned long dt_root = of_get_flat_dt_root(); const char *buf; + int len; - buf = of_get_flat_dt_prop(dt_root, name, NULL); + buf = of_get_flat_dt_prop(dt_root, name, &len); if (!buf) return -EINVAL; + if (!memchr(buf, '\0', len)) + return -EINVAL; + if (cpulist_parse(buf, cpumask)) return -EINVAL; -- 2.50.1 (Apple Git-155) _______________________________________________ linux-snps-arc mailing list [email protected] http://lists.infradead.org/mailman/listinfo/linux-snps-arc