Re: [PATCH 3/6] powerpc/spufs: bound NPC against local store size
"Arnd Bergmann" <[email protected]> Mon, 03 Aug 2026 11:14:03 +0200
| Newsgroups | org.ozlabs.lists.linuxppc-dev,org.kernel.vger.linux-kernel,org.kernel.vger.stable |
|---|---|
| Message-ID | <[email protected]> |
On Sun, Aug 2, 2026, at 17:51, Junrui Luo via B4 Relay wrote: > From: Junrui Luo <[email protected]> > > spu_process_callback() masks the low bits of the NPC register and uses > the result as an offset into the SPU local store: `ls_pointer = in_be32(ls > + npc)`. The following guard validates ls_pointer against LS_SIZE, but npc > itself is never bounds-checked. > > Fix by rejecting npc greater than LS_SIZE - sizeof(ls_pointer) before the > read, mirroring the adjacent ls_pointer guard and returning the same > -EFAULT. This one seems wrong: npc is a hardware register value that can't go out of range, unlike the ls_pointer value. I don't think there is any use for the check. Arnd