Re: [PATCH v7 2/3] fpga: dfl-afu: validate DMA mapping length in afu_dma_map_region()
Greg KH <[email protected]> Mon, 18 May 2026 20:52:09 +0200
| Newsgroups | org.kernel.vger.linux-fpga,org.kernel.vger.linux-kernel,org.kernel.vger.stable |
|---|---|
| Message-ID | <2026051800-humbly-pandemic-2f19@gregkh> |
On Mon, May 18, 2026 at 10:52:17AM -0600, Sebastian Alba Vives wrote: > afu_ioctl_dma_map() accepts a 64-bit length from userspace via > DFL_FPGA_PORT_DMA_MAP ioctl without an upper bound check. The value > is passed to afu_dma_pin_pages() where npages is derived as > length >> PAGE_SHIFT and passed to pin_user_pages_fast() which takes > int nr_pages, causing implicit truncation if length is very large. > > Validate map.length at the ioctl entry point before calling > afu_dma_map_region(), rejecting values whose page count exceeds > INT_MAX. > > Signed-off-by: Sebastian Alba Vives <[email protected]> > --- > Changes in v7: > - No changes. Why no cc: stable?