From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org X-Spam-Level: X-Spam-Status: No, score=-13.0 required=3.0 tests=BAYES_00,DKIMWL_WL_HIGH, DKIM_SIGNED,DKIM_VALID,HEADER_FROM_DIFFERENT_DOMAINS,INCLUDES_PATCH, MAILING_LIST_MULTI,SIGNED_OFF_BY,SPF_HELO_NONE,SPF_PASS,URIBL_BLOCKED, USER_AGENT_GIT autolearn=unavailable autolearn_force=no version=3.4.0 Received: from mail.kernel.org (mail.kernel.org [198.145.29.99]) by smtp.lore.kernel.org (Postfix) with ESMTP id 4ECBCC433E0 for ; Sat, 25 Jul 2020 02:14:39 +0000 (UTC) Received: from merlin.infradead.org (merlin.infradead.org [205.233.59.134]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by mail.kernel.org (Postfix) with ESMTPS id 1A4DB2067D for ; Sat, 25 Jul 2020 02:14:39 +0000 (UTC) Authentication-Results: mail.kernel.org; dkim=pass (2048-bit key) header.d=lists.infradead.org header.i=@lists.infradead.org header.b="PhDfigfw" DMARC-Filter: OpenDMARC Filter v1.3.2 mail.kernel.org 1A4DB2067D Authentication-Results: mail.kernel.org; dmarc=none (p=none dis=none) header.from=huawei.com Authentication-Results: mail.kernel.org; spf=none smtp.mailfrom=linux-arm-kernel-bounces+linux-arm-kernel=archiver.kernel.org@lists.infradead.org DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=lists.infradead.org; s=merlin.20170209; h=Sender:Content-Transfer-Encoding: Content-Type:Cc:List-Subscribe:List-Help:List-Post:List-Archive: List-Unsubscribe:List-Id:MIME-Version:Message-ID:Date:Subject:To:From: Reply-To:Content-ID:Content-Description:Resent-Date:Resent-From:Resent-Sender :Resent-To:Resent-Cc:Resent-Message-ID:In-Reply-To:References:List-Owner; bh=11URHff8pzq7qJRbdJ5TZGhr4rHc1ntICtUUCsTUrDQ=; b=PhDfigfwaSksaHfORu1CtQ9yhj A92fwaPUjkwJ1ow9pWeTbSsodcSRJ0nuFjggyNyPmLPSysePc4JL2yyNoBYuovp9fVb7lB90hrJrH Oz4PgYR2L0N+zDYnTGc7vGk8kpFQDzvWQG/E+b0fcPpDwuoLZ1F9jeFBXeS3bX8qQSg7scACsMpwr A5nM2u/KaZd1Ep3LsFyrKum1O5bKvCLIzv9ornXLOxS/Wkdff8r3Jp7fVNM+1LruWMSrIvnkJ9pae PSode4p0Yu58JgJf/Ps6aOET4llJwYVQkvYXDnEAJVUn5GIx+WRbnwXxmn6TB/TaNnPi3IO+X0/Rb I0odKMBA==; Received: from localhost ([::1] helo=merlin.infradead.org) by merlin.infradead.org with esmtp (Exim 4.92.3 #3 (Red Hat Linux)) id 1jz9gb-0000T5-6c; Sat, 25 Jul 2020 02:13:17 +0000 Received: from szxga04-in.huawei.com ([45.249.212.190] helo=huawei.com) by merlin.infradead.org with esmtps (Exim 4.92.3 #3 (Red Hat Linux)) id 1jz9gY-0000SX-Nl for linux-arm-kernel@lists.infradead.org; Sat, 25 Jul 2020 02:13:15 +0000 Received: from DGGEMS414-HUB.china.huawei.com (unknown [172.30.72.58]) by Forcepoint Email with ESMTP id EAEEB29C9854D53028D0; Sat, 25 Jul 2020 10:13:10 +0800 (CST) Received: from huawei.com (10.179.179.12) by DGGEMS414-HUB.china.huawei.com (10.3.19.214) with Microsoft SMTP Server id 14.3.487.0; Sat, 25 Jul 2020 10:13:00 +0800 From: guodeqing To: Subject: [PATCH,v2] arm64: fix the illegal address access in some cases Date: Sat, 25 Jul 2020 10:08:06 +0800 Message-ID: <1595642886-78334-1-git-send-email-geffrey.guo@huawei.com> X-Mailer: git-send-email 2.7.4 MIME-Version: 1.0 X-Originating-IP: [10.179.179.12] X-CFilter-Loop: Reflected X-CRM114-Version: 20100106-BlameMichelson ( TRE 0.8.0 (BSD) ) MR-646709E3 X-CRM114-CacheID: sfid-20200724_221315_020615_B772FF65 X-CRM114-Status: UNSURE ( 8.35 ) X-CRM114-Notice: Please train this message. X-BeenThere: linux-arm-kernel@lists.infradead.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Cc: robin.murphy@arm.com, luke.starrett@broadcom.com, will@kernel.org, linux-arm-kernel@lists.infradead.org, geffrey.guo@huawei.com Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit Sender: "linux-arm-kernel" Errors-To: linux-arm-kernel-bounces+linux-arm-kernel=archiver.kernel.org@lists.infradead.org The ihl value of ip header is smaller than 5 in some cases, if the ihl value is smaller than 5, then the next code will access the illegal address, and the system will panic. ip_fast_csum() must be able to handle any value that could fit in the ihl field of the ip protocol header. Here I add the check of the ihl value to solve this problem. Fixes: 0e455d8e80aa (arm64: Implement optimised IP checksum helpers) Signed-off-by: guodeqing --- arch/arm64/include/asm/checksum.h | 3 +++ 1 file changed, 3 insertions(+) diff --git a/arch/arm64/include/asm/checksum.h b/arch/arm64/include/asm/checksum.h index b6f7bc6..5a7d9ac 100644 --- a/arch/arm64/include/asm/checksum.h +++ b/arch/arm64/include/asm/checksum.h @@ -25,6 +25,9 @@ static inline __sum16 ip_fast_csum(const void *iph, unsigned int ihl) __uint128_t tmp; u64 sum; + if (unlikely(ihl < 5)) + return 1; + tmp = *(const __uint128_t *)iph; iph += 16; ihl -= 4; -- 2.7.4 _______________________________________________ linux-arm-kernel mailing list linux-arm-kernel@lists.infradead.org http://lists.infradead.org/mailman/listinfo/linux-arm-kernel