Re: [PATCH v2] arc: validate DT CPU map strings before parsing them
Vineet Gupta <[email protected]> Sun, 12 Apr 2026 12:35:53 -0700
| Newsgroups | org.infradead.lists.linux-snps-arc,org.kernel.vger.linux-kernel |
|---|---|
| Message-ID | <[email protected]> |
On 4/6/26 00:00, Pengpeng Hou wrote: > arc_get_cpu_map() fetches the possible-cpus or present-cpus property > from the flat DT and immediately passes the raw pointer to > cpulist_parse(). That parser expects a NUL-terminated text buffer, but > this path does not prove that the DT property is terminated within its > declared bounds. > > Reject unterminated CPU-map properties before handing them to > cpulist_parse(). > > Changes since v1: > - fold the NUL-termination check into the initial lookup test, as > suggested by Vineet Gupta > > Signed-off-by: Pengpeng Hou <[email protected]> Acked-by: Vineet Gupta <[email protected]> I've queued it for next ARC pull request, after the rc1 since we are on the verge of merge window. Thx, -Vineet > --- > arch/arc/kernel/smp.c | 7 ++++++- > 1 file changed, 6 insertions(+), 1 deletion(-) > > diff --git a/arch/arc/kernel/smp.c b/arch/arc/kernel/smp.c > index b2f2c59279a6..632976c22107 100644 > --- a/arch/arc/kernel/smp.c > +++ b/arch/arc/kernel/smp.c > @@ -22,6 +22,7 @@ > #include <linux/irqdomain.h> > #include <linux/export.h> > #include <linux/of_fdt.h> > +#include <linux/string.h> > > #include <asm/mach_desc.h> > #include <asm/setup.h> > @@ -43,9 +44,10 @@ static int __init arc_get_cpu_map(const char *name, struct cpumask *cpumask) > { > unsigned long dt_root = of_get_flat_dt_root(); > const char *buf; > + int len; > > - buf = of_get_flat_dt_prop(dt_root, name, NULL); > - if (!buf) > + buf = of_get_flat_dt_prop(dt_root, name, &len); > + if (!buf || !memchr(buf, '\0', len)) > return -EINVAL; > > if (cpulist_parse(buf, cpumask)) > return -EINVAL; > > return 0; > } _______________________________________________ linux-snps-arc mailing list [email protected] http://lists.infradead.org/mailman/listinfo/linux-snps-arc