From: T Pratham <t-pratham@ti.com>
To: T Pratham <t-pratham@ti.com>,
Herbert Xu <herbert@gondor.apana.org.au>,
"David S. Miller" <davem@davemloft.net>
Cc: Sebin Francis <sebin.francis@ti.com>,
Manorit Chawdhry <m-chawdhry@ti.com>,
Vishal Mahaveer <vishalm@ti.com>,
Praneeth Bajjuri <praneeth@ti.com>,
<linux-crypto@vger.kernel.org>, <linux-kernel@vger.kernel.org>
Subject: [PATCH v3 03/12] crypto: ti - Fix potential memory corruption on highmem pages
Date: Thu, 10 Sep 2026 16:11:53 +0530 [thread overview]
Message-ID: <20260910104202.1537226-4-t-pratham@ti.com> (raw)
In-Reply-To: <20260910104202.1537226-1-t-pratham@ti.com>
Change sg_set_buf to sg_set_page in DTHEv2 dthe_copy_sg function to
avoid using sg_virt() on scatterlists. For scatterlists containing a
highmem page, sg_virt() yields invalid or null adrdess, causing
potential memory corruption. While we are here, also change function
signature to change buflen from int to unsigned int.
Fixes: 35645ca63caa1 ("crypto: ti - Add support for AES-CTR in DTHEv2 driver")
Signed-off-by: T Pratham <t-pratham@ti.com>
---
drivers/crypto/ti/dthev2-common.c | 4 ++--
drivers/crypto/ti/dthev2-common.h | 2 +-
2 files changed, 3 insertions(+), 3 deletions(-)
diff --git a/drivers/crypto/ti/dthev2-common.c b/drivers/crypto/ti/dthev2-common.c
index 4c6b72ba104ec..8628187a32e18 100644
--- a/drivers/crypto/ti/dthev2-common.c
+++ b/drivers/crypto/ti/dthev2-common.c
@@ -50,7 +50,7 @@ struct dthe_data *dthe_get_dev(struct dthe_tfm_ctx *ctx)
struct scatterlist *dthe_copy_sg(struct scatterlist *dst,
struct scatterlist *src,
- int buflen)
+ unsigned int buflen)
{
struct scatterlist *from_sg, *to_sg;
int sglen;
@@ -59,7 +59,7 @@ struct scatterlist *dthe_copy_sg(struct scatterlist *dst,
sglen = from_sg->length;
if (sglen > buflen)
sglen = buflen;
- sg_set_buf(to_sg, sg_virt(from_sg), sglen);
+ sg_set_page(to_sg, sg_page(from_sg), sglen, from_sg->offset);
from_sg = sg_next(from_sg);
to_sg = sg_next(to_sg);
}
diff --git a/drivers/crypto/ti/dthev2-common.h b/drivers/crypto/ti/dthev2-common.h
index d4a3b9c18bbc1..75d9a097650da 100644
--- a/drivers/crypto/ti/dthev2-common.h
+++ b/drivers/crypto/ti/dthev2-common.h
@@ -126,7 +126,7 @@ struct dthe_data *dthe_get_dev(struct dthe_tfm_ctx *ctx);
**/
struct scatterlist *dthe_copy_sg(struct scatterlist *dst,
struct scatterlist *src,
- int buflen);
+ unsigned int buflen);
int dthe_register_aes_algs(void);
void dthe_unregister_aes_algs(void);
--
2.34.1
next prev parent reply other threads:[~2026-09-10 10:43 UTC|newest]
Thread overview: 13+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-10 10:41 [PATCH v3 00/12] Fix several issues in DTHEv2 driver T Pratham
2026-09-10 10:41 ` [PATCH v3 01/12] crypto: ti - Use list_first_entry_or_null() in dthe_get_dev() T Pratham
2026-09-10 10:41 ` [PATCH v3 02/12] crypto: ti - Fix spinlock inconsistency in DTHEv2 T Pratham
2026-09-10 10:41 ` T Pratham [this message]
2026-09-10 10:41 ` [PATCH v3 04/12] crypto: ti - Fix use-after-free of dev_data on DTHEv2 driver removal T Pratham
2026-09-10 10:41 ` [PATCH v3 05/12] crypto: ti - Trim scatterlists to correct length in AES T Pratham
2026-09-10 10:41 ` [PATCH v3 06/12] crypto: ti - Align buffers to cacheline for DMA T Pratham
2026-09-10 10:41 ` [PATCH v3 07/12] crypto: ti - Separate padding buffer for src and dst T Pratham
2026-09-10 10:41 ` [PATCH v3 08/12] crypto: ti - Validate sg_nents_for_len() return value in DTHEv2 AES T Pratham
2026-09-10 10:41 ` [PATCH v3 09/12] crypto: ti - Validate sg_nents_for_len() return value in DTHEv2 AEAD T Pratham
2026-09-10 10:42 ` [PATCH v3 10/12] crypto: ti - Terminate DMA on all error paths in AES to clear descriptors T Pratham
2026-09-10 10:42 ` [PATCH v3 11/12] crypto: ti - Terminate DMA on all error paths in AEAD " T Pratham
2026-09-10 10:42 ` [PATCH v3 12/12] crypto: ti - Do AEAD software fallback on only ENOMEM T Pratham
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260910104202.1537226-4-t-pratham@ti.com \
--to=t-pratham@ti.com \
--cc=davem@davemloft.net \
--cc=herbert@gondor.apana.org.au \
--cc=linux-crypto@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=m-chawdhry@ti.com \
--cc=praneeth@ti.com \
--cc=sebin.francis@ti.com \
--cc=vishalm@ti.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox