Linux cryptographic layer development
 help / color / mirror / Atom feed
* [PATCH] crypto: nx - validate 'ignore' before subtracting in decompress
@ 2026-09-25 17:58 Aldo Ariel Panzardo
  2026-10-02  8:07 ` Herbert Xu
  2026-10-02 10:15 ` Herbert Xu
  0 siblings, 2 replies; 3+ messages in thread
From: Aldo Ariel Panzardo @ 2026-09-25 17:58 UTC (permalink / raw)
  To: haren, herbert; +Cc: linux-crypto, linux-kernel, stable, Aldo Ariel Panzardo

The decompress() function subtracts the header-supplied `ignore` value
(a u16 from the compressed stream) from `dlen` (the number of bytes
produced by the decompressor) without checking that ignore <= dlen.

If a caller decompresses a crafted buffer where `hdr->ignore` exceeds
the actual decompressed length, the subtraction wraps around to a
near-UINT_MAX value.  The subsequent memcpy() then copies gigabytes of
data past the destination buffer, causing an out-of-bounds kernel write.

Add a bounds check before the subtraction and return -EINVAL if the
value is inconsistent.

Cc: stable@vger.kernel.org
Signed-off-by: Aldo Ariel Panzardo <qwe.aldo@gmail.com>
---
 drivers/crypto/nx/nx-842.c | 3 +++
 1 file changed, 3 insertions(+)

--- a/drivers/crypto/nx/nx-842.c
+++ b/drivers/crypto/nx/nx-842.c
@@ -421,6 +421,8 @@
 
 	slen -= spadding;
 
+	if (ignore > dlen)
+		return -EINVAL;
 	dlen -= ignore;
 	if (ignore)
 		pr_debug("ignoring last %x bytes\n", ignore);

-- 
2.43.0

^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2026-10-02 10:15 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-25 17:58 [PATCH] crypto: nx - validate 'ignore' before subtracting in decompress Aldo Ariel Panzardo
2026-10-02  8:07 ` Herbert Xu
2026-10-02 10:15 ` Herbert Xu

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox