All of lore.kernel.org
 help / color / mirror / Atom feed
* [withdrawn] kernel-taskstatsc-parse-fix-buffer-allocation-size.patch removed from -mm tree
@ 2026-07-23 19:28 Andrew Morton
  0 siblings, 0 replies; only message in thread
From: Andrew Morton @ 2026-07-23 19:28 UTC (permalink / raw)
  To: mm-commits, stable, oleg.deomi, bsingharora, akpm, akpm


The quilt patch titled
     Subject: kernel/taskstats.c:parse(): fix buffer allocation size
has been removed from the -mm tree.  Its filename was
     kernel-taskstatsc-parse-fix-buffer-allocation-size.patch

This patch was dropped because it was withdrawn

------------------------------------------------------
From: Andrew Morton <akpm@linux-foundation.org>
Subject: kernel/taskstats.c:parse(): fix buffer allocation size
Date: Tue Jul 21 04:30:41 PM PDT 2026

parse() is failing to allow for the nla_strscpy()'s null termination of
the cpumask string.  This can result in the cpumask string being
truncated.

This can result in an inappropriate -EINVAL failure or in reporting for an
incorrect span of CPUs.

Fixes: f9fd8914c1ac ("[PATCH] per-task delay accounting taskstats interface: control exit data through cpumasks")
Reported-by: Oleg Deomi <oleg.deomi@gmail.com>
Closes: https://lore.kernel.org/CAByWkfZ6b1=3H9pwkz-dDQOs9cZaF-HYQ6b9Yb0=Hq2r1Vv_Pw@mail.gmail.com
Cc: Balbir Singh <bsingharora@gmail.com>
Cc: <stable@vger.kernel.org>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
---

 kernel/taskstats.c |    2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

--- a/kernel/taskstats.c~kernel-taskstatsc-parse-fix-buffer-allocation-size
+++ a/kernel/taskstats.c
@@ -368,7 +368,7 @@ static int parse(struct nlattr *na, stru
 		return -E2BIG;
 	if (len < 1)
 		return -EINVAL;
-	data = kmalloc(len, GFP_KERNEL);
+	data = kmalloc(len + 1, GFP_KERNEL);
 	if (!data)
 		return -ENOMEM;
 	nla_strscpy(data, na, len);
_

Patches currently in -mm which might be from akpm@linux-foundation.org are

mm-mincore-use-walk_page_range_vma-in-do_mincore-fix.patch
csky-implement-flush_cache_vmap-in-c.patch
mm-annotate-data-race-in-cpu_needs_drain-fix.patch
mm-zsmalloc-encode-class-index-in-obj-value-for-lockless-class-lookup-fix.patch
mm-zsmalloc-drop-pool-lock-from-zs_free-on-64-bit-systems-fix.patch
mm-zsmalloc-drop-pool-lock-from-zs_free-on-64-bit-systems-fix-fix.patch
mm-rmap-use-huge_ptep_get-in-try_to_migrate_one-checkpatch-fixes.patch
mm-mprotect-use-huge_ptep_get-for-hugetlb-fix.patch
mm-drop-stale-folio_ref_count==1-check-in-do_swap_page-reuse-logic-fix.patch
alloc_tag-add-ioctl-to-proc-allocinfo-fix.patch
mm-vma-add-and-use-vma__pgoff-fix.patch
drivers-media-v4l2-core-v4l2-vp9c-reduce-inlining.patch


^ permalink raw reply	[flat|nested] only message in thread

only message in thread, other threads:[~2026-07-23 19:28 UTC | newest]

Thread overview: (only message) (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-07-23 19:28 [withdrawn] kernel-taskstatsc-parse-fix-buffer-allocation-size.patch removed from -mm tree Andrew Morton

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.