From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from lists.ozlabs.org (lists.ozlabs.org [112.213.38.117]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.lore.kernel.org (Postfix) with ESMTPS id 3BE39CD5BD1 for ; Mon, 1 Jun 2026 09:50:39 +0000 (UTC) Received: from boromir.ozlabs.org (localhost [127.0.0.1]) by lists.ozlabs.org (Postfix) with ESMTP id 4gTThD3fSlz3c78; Mon, 01 Jun 2026 19:49:32 +1000 (AEST) Authentication-Results: lists.ozlabs.org; arc=none smtp.remote-ip=113.46.200.219 ARC-Seal: i=1; a=rsa-sha256; d=lists.ozlabs.org; s=201707; t=1780307372; cv=none; b=Odv6AtgnjF8CDATiI0+vEK0+vMsoKLkfm2g1GPchQJRMAmwJgVWf5Flw1q3zqR/i4dqadUrHk4enRze3s8b8gl5jOYK4nd4xQ0hfqoaPOkQhcmPOBlv1qux00+/9qElwWmdcE5pci6RTSHvpvAzMER3x9YxljDWEnW/7PfEwyYNqOtylxou+Mq/T5JlAUhfY4T57WfDfxFCLR8cQT7RPqWwiy8VEvCMFxCCLJ1h/IVSHav4SNUKltnkvfuKI7exi0w9hfAP/8Y7k2WSap1BhEx6woOy0jwpLBCF5VrWZGAkWYSEc5o8pz+rKYLBl+3X5aSexjq8qmlFag4lcfute8A== ARC-Message-Signature: i=1; a=rsa-sha256; d=lists.ozlabs.org; s=201707; t=1780307372; c=relaxed/relaxed; bh=K+OiX4qzF9ZF7Yx2d0GnuFscPpt9fElzoamptIjOMIU=; h=From:To:CC:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version:Content-Type; b=Dxu7ogG2uaa9jVGya9vHpSV+FFWTf+6Nbv8qQry6N5BgsT14P3HYRxPcn8Cbdl1T0/OK2CmNmbVOcHuBDiXkToxJTV7D4JJ/kLmXVsUgnt5j4kqnqMZQMnS3EE/XnHgCip6yA/zTDt8JiMsUF76H7ppT9rAaEuLmqrek+uEMe5EJZvQ4M7SOjkGU7zA7rsZuPdP5mLc6Wy37WRVrH8vAeOhNekH1Hw559tBtdEQ8uP7eA5tPY+CUmpuUvAPaniAikx9AQb/hApIiHRtUviK3ODTiRn3ON8hdQASKG7Q0EkxUF2NQC8Ou+wO1KFVctcPQSScWdDInUHqqekX3EgVVwg== ARC-Authentication-Results: i=1; lists.ozlabs.org; dmarc=pass (p=quarantine dis=none) header.from=huawei.com; dkim=pass (1024-bit key; unprotected) header.d=huawei.com header.i=@huawei.com header.a=rsa-sha256 header.s=dkim header.b=6PEkMrvD; dkim-atps=neutral; spf=pass (client-ip=113.46.200.219; helo=canpmsgout04.his.huawei.com; envelope-from=ruanjinjie@huawei.com; receiver=lists.ozlabs.org) smtp.mailfrom=huawei.com Authentication-Results: lists.ozlabs.org; dmarc=pass (p=quarantine dis=none) header.from=huawei.com Authentication-Results: lists.ozlabs.org; dkim=pass (1024-bit key; unprotected) header.d=huawei.com header.i=@huawei.com header.a=rsa-sha256 header.s=dkim header.b=6PEkMrvD; dkim-atps=neutral Authentication-Results: lists.ozlabs.org; spf=pass (sender SPF authorized) smtp.mailfrom=huawei.com (client-ip=113.46.200.219; helo=canpmsgout04.his.huawei.com; envelope-from=ruanjinjie@huawei.com; receiver=lists.ozlabs.org) Received: from canpmsgout04.his.huawei.com (canpmsgout04.his.huawei.com [113.46.200.219]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519) (No client certificate requested) by lists.ozlabs.org (Postfix) with ESMTPS id 4gTThC4DFhz2ytJ for ; Mon, 01 Jun 2026 19:49:31 +1000 (AEST) dkim-signature: v=1; a=rsa-sha256; d=huawei.com; s=dkim; c=relaxed/relaxed; q=dns/txt; h=From; bh=K+OiX4qzF9ZF7Yx2d0GnuFscPpt9fElzoamptIjOMIU=; b=6PEkMrvD8QwvG/Qh8st7O555IPcpZY1yUBR9xKCs1T8D6EkfggsVhqLn2vRBf/VV54OMTqMFc 8JLeZNIiExCm/NunZ0NVTUCvGhqzT0UkLHmFRrbXfroj23ki6QFGBSAayUm9W96Cu1fsF699YIs 6BNwUZJfmCGZIL1ilqpJjoU= Received: from mail.maildlp.com (unknown [172.19.162.140]) by canpmsgout04.his.huawei.com (SkyGuard) with ESMTPS id 4gTTW55FRTz1prL8; Mon, 1 Jun 2026 17:41:37 +0800 (CST) Received: from dggpemf500011.china.huawei.com (unknown [7.185.36.131]) by mail.maildlp.com (Postfix) with ESMTPS id EF66D201E9; Mon, 1 Jun 2026 17:49:28 +0800 (CST) Received: from huawei.com (10.90.53.73) by dggpemf500011.china.huawei.com (7.185.36.131) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.1544.11; Mon, 1 Jun 2026 17:49:24 +0800 From: Jinjie Ruan To: , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , CC: Subject: [PATCH v15 14/23] LoongArch: kexec_file: Fix TOCTOU buffer overflow via memory region padding Date: Mon, 1 Jun 2026 17:47:56 +0800 Message-ID: <20260601094805.2928614-15-ruanjinjie@huawei.com> X-Mailer: git-send-email 2.34.1 In-Reply-To: <20260601094805.2928614-1-ruanjinjie@huawei.com> References: <20260601094805.2928614-1-ruanjinjie@huawei.com> X-Mailing-List: linuxppc-dev@lists.ozlabs.org List-Id: List-Help: List-Owner: List-Post: List-Archive: , List-Subscribe: , , List-Unsubscribe: Precedence: list MIME-Version: 1.0 Content-Transfer-Encoding: 8bit Content-Type: text/plain X-Originating-IP: [10.90.53.73] X-ClientProxiedBy: kwepems100002.china.huawei.com (7.221.188.206) To dggpemf500011.china.huawei.com (7.185.36.131) Sashiko AI code review pointed out there is a TOCTOU (Time-of-Check to Time-of-Use) race condition in prepare_elf_headers() between the initial pass that counts System RAM ranges and the second pass that populates them. If a memory hotplug event occurs between these two steps, the number of memory regions may increase, causing an out-of-bounds write to the cmem->ranges[] array. Fix this fundamentally by using `CRASH_HOTPLUG_SAFETY_PADDING` (128 slots) to expand the flexible array allocation ceiling upfront. This safely absorbs any concurrent memory region expansion. Concurrently, add a defensive boundary check to return -EAGAIN on unexpected overrun, fully eradicating the overflow window and ensuring system stability. Cc: Youling Tang Cc: Huacai Chen Cc: WANG Xuerui Cc: stable@vger.kernel.org Fixes: 1bcca8620a91 ("LoongArch: Add crash dump support for kexec_file") Signed-off-by: Jinjie Ruan --- arch/loongarch/kernel/machine_kexec_file.c | 8 +++++++- 1 file changed, 7 insertions(+), 1 deletion(-) diff --git a/arch/loongarch/kernel/machine_kexec_file.c b/arch/loongarch/kernel/machine_kexec_file.c index 5584b798ba46..3c369124586e 100644 --- a/arch/loongarch/kernel/machine_kexec_file.c +++ b/arch/loongarch/kernel/machine_kexec_file.c @@ -64,7 +64,8 @@ static int prepare_elf_headers(void **addr, unsigned long *sz) phys_addr_t start, end; struct crash_mem *cmem; - nr_ranges = 2; /* for exclusion of crashkernel region */ + /* for exclusion of crashkernel region */ + nr_ranges = 2 + CRASH_HOTPLUG_SAFETY_PADDING; for_each_mem_range(i, &start, &end) nr_ranges++; @@ -75,6 +76,11 @@ static int prepare_elf_headers(void **addr, unsigned long *sz) cmem->max_nr_ranges = nr_ranges; cmem->nr_ranges = 0; for_each_mem_range(i, &start, &end) { + if (unlikely(cmem->nr_ranges >= cmem->max_nr_ranges)) { + ret = -EAGAIN; + goto out; + } + cmem->ranges[cmem->nr_ranges].start = start; cmem->ranges[cmem->nr_ranges].end = end - 1; cmem->nr_ranges++; -- 2.34.1