Re: [PATCH v7 2/3] fpga: dfl-afu: validate DMA mapping length in afu_dma_map_region()

Greg KH <[email protected]> Mon, 18 May 2026 20:52:09 +0200
Newsgroups org.kernel.vger.linux-fpga,org.kernel.vger.linux-kernel,org.kernel.vger.stable
Message-ID <2026051800-humbly-pandemic-2f19@gregkh>
On Mon, May 18, 2026 at 10:52:17AM -0600, Sebastian Alba Vives wrote:
> afu_ioctl_dma_map() accepts a 64-bit length from userspace via
> DFL_FPGA_PORT_DMA_MAP ioctl without an upper bound check. The value
> is passed to afu_dma_pin_pages() where npages is derived as
> length >> PAGE_SHIFT and passed to pin_user_pages_fast() which takes
> int nr_pages, causing implicit truncation if length is very large.
> 
> Validate map.length at the ioctl entry point before calling
> afu_dma_map_region(), rejecting values whose page count exceeds
> INT_MAX.
> 
> Signed-off-by: Sebastian Alba Vives <[email protected]>
> ---
> Changes in v7:
>   - No changes.

Why no cc: stable?