From: Som Tripathi <tripathisom142004@gmail.com>
To: gregkh@linuxfoundation.org
Cc: error27@gmail.com, linux-staging@lists.linux.dev,
linux-kernel@vger.kernel.org,
Som Tripathi <tripathisom142004@gmail.com>
Subject: [PATCH] staging: vme_user: fix bounds check when vme_get_size() returns zero
Date: Thu, 6 Aug 2026 20:25:06 -0500 [thread overview]
Message-ID: <20260807012506.579588-1-tripathisom142004@gmail.com> (raw)
vme_get_size() returns zero on failure, as its kerneldoc in vme.c
states. vme_user_read() and vme_user_write() assign it to a size_t and
check the file position with:
if ((*ppos < 0) || (*ppos > (image_size - 1)))
When image_size is zero, image_size - 1 wraps to SIZE_MAX. The test is
then never true, so the check does nothing. The following statement,
count = image_size - *ppos;
wraps the same way whenever *ppos is greater than zero.
This is not an out-of-bounds access. resource_to_user() and
resource_from_user() clamp count to size_buf, buffer_to_user() and
buffer_from_user() clamp it to size_buf - *ppos, and vme_master_read()
and vme_master_write() reject an offset greater than the window
length. What happens instead is that read() and write() operate on a
window whose size the driver failed to read, rather than returning at
the check.
Compare *ppos against image_size directly. The two forms agree for a
non-zero size, the new one is also correct for zero, and both wraps go
away.
Found by reading the code after Dan Carpenter listed this as one of
three outstanding bugs in this driver; see the Link below. Compile
tested only. I have no VME hardware.
Fixes: f00a86d98a1e ("Staging: vme: add VME userspace driver")
Link: https://lore.kernel.org/all/aj0WWwiOzjLGbY5z@stanley.mountain/
Signed-off-by: Som Tripathi <tripathisom142004@gmail.com>
Assisted-by: Claude:claude-opus-5
---
drivers/staging/vme_user/vme_user.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/drivers/staging/vme_user/vme_user.c b/drivers/staging/vme_user/vme_user.c
index a472a38ef..0df30a3c3 100644
--- a/drivers/staging/vme_user/vme_user.c
+++ b/drivers/staging/vme_user/vme_user.c
@@ -213,7 +213,7 @@ static ssize_t vme_user_read(struct file *file, char __user *buf, size_t count,
image_size = vme_get_size(image[minor].resource);
/* Ensure we are starting at a valid location */
- if ((*ppos < 0) || (*ppos > (image_size - 1))) {
+ if ((*ppos < 0) || (*ppos >= image_size)) {
mutex_unlock(&image[minor].mutex);
return 0;
}
@@ -255,7 +255,7 @@ static ssize_t vme_user_write(struct file *file, const char __user *buf,
image_size = vme_get_size(image[minor].resource);
/* Ensure we are starting at a valid location */
- if ((*ppos < 0) || (*ppos > (image_size - 1))) {
+ if ((*ppos < 0) || (*ppos >= image_size)) {
mutex_unlock(&image[minor].mutex);
return 0;
}
--
2.55.0.windows.1
next reply other threads:[~2026-08-07 1:25 UTC|newest]
Thread overview: 3+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-07 1:25 Som Tripathi [this message]
2026-08-07 6:31 ` [PATCH] staging: vme_user: fix bounds check when vme_get_size() returns zero Dan Carpenter
2026-08-07 6:44 ` Greg KH
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260807012506.579588-1-tripathisom142004@gmail.com \
--to=tripathisom142004@gmail.com \
--cc=error27@gmail.com \
--cc=gregkh@linuxfoundation.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-staging@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.