Re: [PATCH] io_uring/rsrc: bound io_coalesce_buffer() page array allocation
Gabriel Krisman Bertazi <[email protected]>
| Newsgroups | org.kernel.vger.io-uring,org.kernel.vger.linux-kernel |
|---|---|
| Organization | SUSE |
| Message-ID | <[email protected]> |
Yi Xie <[email protected]> writes: > kvmalloc_objs() in io_coalesce_buffer() does not check for size overflow > when nr_folios is large. Mirror the check used in memmap.c before > allocating the page pointer array. > > Signed-off-by: Yi Xie <[email protected]> Resending from yesterday as changing MUA is never harmless... I don't think this can happen. nr_folios comes from nr_pages in io_check_coalesce_buffer, and must be less or equal to it. But nr_pages is already checked in io_pin_pages, introduced by: https://lore.kernel.org/io-uring/178216289049.99876.2987989144128669864.b4-ty@b4/T/#t > --- > io_uring/rsrc.c | 2 ++ > 1 file changed, 2 insertions(+) > > diff --git a/io_uring/rsrc.c b/io_uring/rsrc.c > index 8d0f2ee24e0c..f1f8d6dd102c 100644 > --- a/io_uring/rsrc.c > +++ b/io_uring/rsrc.c > @@ -776,6 +776,8 @@ static bool io_coalesce_buffer(struct page ***pages, int *nr_pages, > unsigned i, j; > > /* Store head pages only*/ > + if (nr_folios > INT_MAX / sizeof(struct page *)) > + return false; > new_array = kvmalloc_objs(struct page *, nr_folios); > if (!new_array) > return false; > -- > 2.25.1 > -- Gabriel Krisman Bertazi