All of lore.kernel.org
 help / color / mirror / Atom feed
* [PATCH]: iommu fix potential overflow in alloc_iommu()
@ 2008-07-21 14:15 Prarit Bhargava
  2008-07-21 14:15 ` [PATCH]: PCI: GART iommu alignment fixes Prarit Bhargava
  2008-07-21 15:16 ` [PATCH]: iommu fix potential overflow in alloc_iommu() FUJITA Tomonori
  0 siblings, 2 replies; 7+ messages in thread
From: Prarit Bhargava @ 2008-07-21 14:15 UTC (permalink / raw)
  To: linux-kernel, linux-pci; +Cc: Prarit Bhargava

(This didn't appear on LKML or any of the mirrors ... trying again)

It is possible that alloc_iommu()'s boundary_size overflows as
dma_get_seg_boundary can return 0xffffffff.  In that case, further usage of
boundary_size triggers a BUG_ON() in the iommu code.

Signed-off-by: Prarit Bhargava <prarit@redhat.com>

diff --git a/arch/x86/kernel/pci-gart_64.c b/arch/x86/kernel/pci-gart_64.c
index faf3229..baecb47 100644
--- a/arch/x86/kernel/pci-gart_64.c
+++ b/arch/x86/kernel/pci-gart_64.c
@@ -91,7 +91,7 @@ static unsigned long alloc_iommu(struct device *dev, int size)
 
 	base_index = ALIGN(iommu_bus_base & dma_get_seg_boundary(dev),
 			   PAGE_SIZE) >> PAGE_SHIFT;
-	boundary_size = ALIGN(dma_get_seg_boundary(dev) + 1,
+	boundary_size = ALIGN((unsigned long long)dma_get_seg_boundary(dev) + 1,
 			      PAGE_SIZE) >> PAGE_SHIFT;
 
 	spin_lock_irqsave(&iommu_bitmap_lock, flags);

^ permalink raw reply related	[flat|nested] 7+ messages in thread

end of thread, other threads:[~2008-07-21 15:48 UTC | newest]

Thread overview: 7+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2008-07-21 14:15 [PATCH]: iommu fix potential overflow in alloc_iommu() Prarit Bhargava
2008-07-21 14:15 ` [PATCH]: PCI: GART iommu alignment fixes Prarit Bhargava
2008-07-21 15:16   ` FUJITA Tomonori
2008-07-21 15:16 ` [PATCH]: iommu fix potential overflow in alloc_iommu() FUJITA Tomonori
2008-07-21 15:21   ` Prarit Bhargava
2008-07-21 15:46     ` FUJITA Tomonori
2008-07-21 15:47       ` Prarit Bhargava

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.