Re: [PATCH] PCI: sysfs: Reject unaligned resource I/O port accesses

Bjorn Helgaas <[email protected]>
Newsgroups org.kernel.vger.linux-pci,org.kernel.vger.linux-kernel
Message-ID <20260821164239.GA975848@bhelgaas>
On Fri, Aug 21, 2026 at 07:16:32AM +0530, Deepanshu Kartikey wrote:
> On Sun, Aug 9, 2026 at 10:29 AM Deepanshu Kartikey
> <[email protected]> wrote:
> >
> > pci_resource_io() validates that off+count stays within the BAR's
> > range but never checks that the resulting port is aligned to the
> > access size. A pwrite64()/pread64() on a resourceN file with an odd
> > offset and count=2 or count=4 reaches outw()/outl() with a misaligned
> > address. On arm64 this becomes a store/load to a Device-memory
> > mapping (PCI_IOBASE + port), which architecturally requires natural
> > alignment, causing an alignment fault and kernel oops.
> >
> > Reject misaligned accesses before they reach the low-level accessor.
> >
> > Reported-by: [email protected]
> > Closes: https://syzkaller.appspot.com/bug?extid=7134530b25073b4ef373
> > Signed-off-by: Deepanshu Kartikey <[email protected]>
> > ---
> >  drivers/pci/pci-sysfs.c | 3 +++
> >  1 file changed, 3 insertions(+)
> >
> > diff --git a/drivers/pci/pci-sysfs.c b/drivers/pci/pci-sysfs.c
> > index 5ec0b245a69b..72f0404a34e9 100644
> > --- a/drivers/pci/pci-sysfs.c
> > +++ b/drivers/pci/pci-sysfs.c
> > @@ -1175,6 +1175,9 @@ static ssize_t pci_resource_io(struct file *filp, struct kobject *kobj,
> >         if (port + count - 1 > pci_resource_end(pdev, bar))
> >                 return -EINVAL;
> >
> > +       if (!IS_ALIGNED(port, count))
> > +               return -EINVAL;
> > +
> >         switch (count) {
> >         case 1:
> >                 if (write)
> > --
> > 2.43.0
> >
> 
> Gentle Reminder. Please let me know the status of this patch

We're in the middle of the merge window, so won't be adding new
material until after v7.3-rc1 (probably Aug 31).
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.