From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-yw1-f170.google.com (mail-yw1-f170.google.com [209.85.128.170]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 7D5A423EAB0 for ; Mon, 18 May 2026 16:53:32 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.128.170 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1779123213; cv=none; b=Jb7NNnlv+uYv1zPMWuWbeK4Ypp7yIOvLqAcThznmay1zs16+sbqLh8+UGRJeRgjoLkwK9maymiU1yMgzlqq1WZHuJPM0DeADxKmkA5DqWVaggiCGYY81G6zVToiwoDh24Qt0LY3f378ACNwm0zAkF4ecKk1wA8gXR+YNj+Bc94E= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1779123213; c=relaxed/simple; bh=O58YtyLftv/aSr8x9baMQzWxATwo2ioj8rHnKr5cmYk=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=OWllpdmWUiQqzGWliO1t+2y6/Sc0n7CZjz/CdQG39j3+Oq4O7xz5f9I5B6k5lsDj8MW73+2rKsenCWJPtQNri0N0DSNvzgBcTF+cUUOQpa19l+ZYeTzN0IPIrTmd8WLLJYbG37vAYU47vgpx2Rm2Dkikd4PoFsQOggDG7qn8L+A= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=L3QAkuKr; arc=none smtp.client-ip=209.85.128.170 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="L3QAkuKr" Received: by mail-yw1-f170.google.com with SMTP id 00721157ae682-79a535e7c00so18637497b3.3 for ; Mon, 18 May 2026 09:53:32 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1779123211; x=1779728011; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to; bh=q6OJAQsGwoFPD7r4LZcpMPocelNw4jhWQiyjjqAx5Pk=; b=L3QAkuKrkQ0UziMDwTYwuZW6ExFK9XePVRNR6f7NZFO4FvsWxgc0g40/eAE4YdYDu4 FoOAe48oRZLErxQt5/6u8THA/MU5G2O7rRo+UpD/vy2lPKI8mkLiSa500bFn+UcYd/bm TG2O6JFipMb3MS0StKeIaV3UlAPY+uB5Px5ts00s1y1qRU+oFv9ycLvHX7oT7rKMIJOK IQIWP2yIr0oaRDhtQaT1UXT4q2JYWn7q5sSaV63VUtxc2+SId3fj2cRGaKuhsNXlTmpb 0yuJbq7Eo/UglSlirFgpqz2TpHPL0GqeccFE3wcLFNJsXifVWYWCxkp9CIwJOtYb3rGb bSBA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1779123211; x=1779728011; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to; bh=q6OJAQsGwoFPD7r4LZcpMPocelNw4jhWQiyjjqAx5Pk=; b=YTMVe11tpRO3kqxJZPhzv1z8SWmDNcr7ODsFwmBzsD0GjYgj8L9T/Ux5EDEEc9Om2y Tm0OwFsUrf3ynhEkSD2w0isl24dwzY4j69SnFIEaNPnZ6B1/eAQM27plVaf3Yz5J8zgr hY7BzDywabypN8b0Exu7kFfyl5TrMiKtjWhCBB3aQ5QMh81A8gkcwTWMtBlR+rwquPFb Z8DpvVy7qc8Ha6NEbZuvC4cYfTA+wQ5Cr9xVwm8EmREXVlWyj4DDR7HBG/lWKvaoOW6D PpiJo/UxAhWuyeFyIw7eqiNIOO04zE4QLxiGpBCGxxHqUkux5+2tq9YBeGWe7Nz2SMKO 4NDw== X-Forwarded-Encrypted: i=1; AFNElJ/30ehOFK4zSsAKWgxVFocteakYyShwNjMtEntZCd+1eO612IuBgrFn6UBG3nmXuktseNqaHzxe72O7Wpc=@vger.kernel.org X-Gm-Message-State: AOJu0YwQr2P81nTPJ7WgeO96FCh71lk8AhXsIWpx8/V724OtkSvkKjqc 8IA31aDiYhgwq3E61OR1qH3H4pXpbUESLLT109fdpIpZ/K56B2JCebop X-Gm-Gg: Acq92OEGIOv4A+1mu31W977xvIpCKnjl0fVRbnEPbm9Xw97K6rXUjJegGwuvZztNV1h 3bjuEsRssspeAK1MEy/a5K1CJ7sPWWh5rMB4b4BNVi4oWa6RnP5jRtAFpKRwvfLs3PMeELmGGDC Q7B7Jl4MYW8x5VJFlL4IHfxc8BEiRi5I3FU3s5MUecLn4CPZ21d2P6aDNNBH+2D3CEIACT3RB8O D1T1NaOxvn6nyqMW8rVXDYADQopn2EYiihBEvJPuI8D2Xl3urTxD0C2Jc/YvbU3IASCq+pIWFtz m9OzgOCja8qEdx5CQWU2ZLlmOEmgt9iDKIPYDoF9u3Xjmzd2uu/TMrAAcoYv4moVh/rcqjRYLLJ tulgnORwugHskCD0gW9oF0x9xpOb/9zBfdEWPKxr23c4bag05zVBuQ3jntb/KjrDl8nGHZJ8oN3 x9u2OwTTIa6ySSxxDgxMwCQopAM7vtLzuDnJARSbCII1njSQEaYcVivQCb2XSYey7N6ZP+efi/D YWCSw9NNoaPtUN1 X-Received: by 2002:a05:690c:19:b0:7bb:eaf:5101 with SMTP id 00721157ae682-7c9599a2f1emr185013507b3.16.1779123211650; Mon, 18 May 2026 09:53:31 -0700 (PDT) Received: from localhost.localdomain ([186.151.100.108]) by smtp.gmail.com with ESMTPSA id 00721157ae682-7cc965ab98dsm24232957b3.0.2026.05.18.09.53.30 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 18 May 2026 09:53:30 -0700 (PDT) From: Sebastian Alba Vives To: yilun.xu@linux.intel.com, gregkh@linuxfoundation.org Cc: linux-fpga@vger.kernel.org, conor.dooley@microchip.com, mdf@kernel.org, linux-kernel@vger.kernel.org, stable@vger.kernel.org, Sebastian Alba Vives Subject: [PATCH v7 0/3] fpga: bounds checks and input validation fixes Date: Mon, 18 May 2026 10:52:15 -0600 Message-ID: <20260518165218.35388-1-sebasjosue84@gmail.com> X-Mailer: git-send-email 2.43.0 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit This series adds three defensive fixes to FPGA drivers: Patch 1/3 fixes dfh_get_param_size() in the DFL driver where the loop bounds check is evaluated before incrementing size, potentially returning an inflated size that exceeds the feature region boundary. Patch 2/3 validates the DMA mapping length in afu_ioctl_dma_map() at the ioctl entry point before passing it down the call chain, preventing implicit integer truncation in pin_user_pages_fast(). Patch 3/3 fixes mpf_ops_parse_header() in the Microchip SPI FPGA manager where a zero header_size from the bitstream causes a one-byte read before the buffer start. Sebastian Alba Vives (3): fpga: dfl: add bounds check in dfh_get_param_size() fpga: dfl-afu: validate DMA mapping length in afu_dma_map_region() fpga: microchip-spi: fix zero header_size OOB read in mpf_ops_parse_header() drivers/fpga/dfl-afu-main.c | 3 +++ drivers/fpga/dfl.c | 2 ++ drivers/fpga/microchip-spi.c | 3 +++ 3 files changed, 8 insertions(+) -- 2.43.0