From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id C0504466B5E; Wed, 23 Sep 2026 14:29:24 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790173765; cv=none; b=h/vmAA6mAlg1kAvPAfjq6nMuiBrbvoMXVQw/imI/H94PkW/x13oqgv2JxOBrpHGaeDa3VCUcMnHFSwDNiUqShuftUXSoLSbF9Hz5j4V9KdfJtvp0tRwpt38fUelhCbUvtZgSK9c0TfZhb2WrZm5BOkQvmVRGlYsYDn6eGk57Tck= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790173765; c=relaxed/simple; bh=XsEkSz9Rrkd3Q3j/N3vsQQYGRLagy6l3G3I+yl/TMTQ=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version:Content-Type; b=ZRn1qfxep5Bns6iTpH2vjOFzi60cc/NZcnCiSkQyEeJLMkL6SBvs0b6Ja6P4Fd7O5C5GPS2rR8v50Nzr+FtJ3RbfkBNqaBT6fpNybqgxZ48bQ9qOa3Y29mBkIw86P7rinOM5LM3pvIbYouRzxkWsuF1yzoaZEf9htxdqjJg0ztE= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=dodZyRb/; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="dodZyRb/" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 2E4331F000FF; Wed, 23 Sep 2026 14:29:24 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1790173764; bh=eiwmnUxzGMBV1WAYpShvYh43iLScb/PJjG4MJB9jdCE=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=dodZyRb/2fbzlML3z4BnG9JqCeWgtdd3EE8FDF99zl7q97biCsw2tVbDNRzX3VfAN /t4oy/wvd5LY7SNSW0KKBaq0BuXZiQsLy4rL/DaDIvjwu2vyI46x2SDiGEIKiUB+eu qaqGSgHgVxB6j9dF4QwBhTrPs6pQ+J2vVidd6b1c= From: Greg Kroah-Hartman To: stable@vger.kernel.org Cc: Greg Kroah-Hartman , patches@lists.linux.dev, iommu@lists.linux.dev, Pranjal Shrivastava , Kevin Tian , Leon Romanovsky , David Hu , =?UTF-8?q?Christian=20K=C3=B6nig?= Subject: [PATCH 7.2 292/438] dma-buf: Fix silent overflow for phys vec to sgt Date: Wed, 23 Sep 2026 16:05:13 +0200 Message-ID: <20260923140652.346742302@linuxfoundation.org> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260923140644.756254324@linuxfoundation.org> References: <20260923140644.756254324@linuxfoundation.org> User-Agent: quilt/0.69 X-stable: review X-Patchwork-Hint: ignore Precedence: bulk X-Mailing-List: patches@lists.linux.dev List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit 7.2-stable review patch. If anyone has any objections, please let me know. ------------------ From: David Hu commit b344ca94e8cc85796f16ea25e2e5a8e0303fe813 upstream. In case MMIO size is bigger than 4G and peer2peer DMA goes through host bridge, we trigger a code path that assigns the total linked IOVA (which is greater than 4G) to mapped_len. Previously, `mapped_len` was declared as 32-bit `unsigned int`. When accumulating `size_t` lengths, this leads to a silent wrap-around. This truncation causes truncated lengths to be passed to functions like `fill_sg_entry()`. Fix this by changing `mapped_len` to `size_t` (64-bit). While at it, fix similar potential overflow issues in `calc_sg_nents` by using `check_add_overflow()` for `nents` and using `unsigned int` for the loop iterator in `fill_sg_entry` to match. Fixes: 3aa31a8bb11e ("dma-buf: provide phys_vec to scatter-gather mapping routine") Cc: stable@vger.kernel.org Cc: iommu@lists.linux.dev Reviewed-by: Pranjal Shrivastava Reviewed-by: Kevin Tian Reviewed-by: Leon Romanovsky Signed-off-by: David Hu Signed-off-by: Christian König Link: https://lore.kernel.org/r/20260901170849.4052816-2-dhu@x6u.co Signed-off-by: Greg Kroah-Hartman --- drivers/dma-buf/dma-buf-mapping.c | 16 ++++++++++++---- 1 file changed, 12 insertions(+), 4 deletions(-) --- a/drivers/dma-buf/dma-buf-mapping.c +++ b/drivers/dma-buf/dma-buf-mapping.c @@ -5,12 +5,13 @@ */ #include #include +#include static struct scatterlist *fill_sg_entry(struct scatterlist *sgl, size_t length, dma_addr_t addr) { unsigned int len, nents; - int i; + unsigned int i; nents = DIV_ROUND_UP(length, UINT_MAX); for (i = 0; i < nents; i++) { @@ -40,8 +41,12 @@ static unsigned int calc_sg_nents(struct size_t i; if (!state || !dma_use_iova(state)) { - for (i = 0; i < nr_ranges; i++) - nents += DIV_ROUND_UP(phys_vec[i].len, UINT_MAX); + for (i = 0; i < nr_ranges; i++) { + unsigned int added = DIV_ROUND_UP(phys_vec[i].len, UINT_MAX); + + if (check_add_overflow(nents, added, &nents)) + return 0; + } } else { /* * In IOVA case, there is only one SG entry which spans @@ -95,9 +100,10 @@ struct sg_table *dma_buf_phys_vec_to_sgt size_t nr_ranges, size_t size, enum dma_data_direction dir) { - unsigned int nents, mapped_len = 0; struct dma_buf_dma *dma; struct scatterlist *sgl; + size_t mapped_len = 0; + unsigned int nents; dma_addr_t addr; size_t i; int ret; @@ -133,6 +139,8 @@ struct sg_table *dma_buf_phys_vec_to_sgt } nents = calc_sg_nents(dma->state, phys_vec, nr_ranges, size); + + /* sg_alloc_table will cleanly fail and return -EINVAL if nents == 0 */ ret = sg_alloc_table(&dma->sgt, nents, GFP_KERNEL | __GFP_ZERO); if (ret) goto err_free_state;