From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-oa1-f70.google.com (mail-oa1-f70.google.com [209.85.160.70]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 7CDD6283FD9 for ; Mon, 24 Aug 2026 01:58:46 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.160.70 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787536728; cv=none; b=VhpJp9fwT/27hCDG9T3CX2Yz6Ya5lDGkIaSqMQnNBrAfY469ZHLrDaUtmGinPzv3oeEHnJcEw7M2EF0sgU/bDguSsxK5hpNmmVfYfMCBFz0e2AoJQoIHmlBRsP+3A/pxYTycZboha1ymGk4V1gUE9JQFQ/gf3rUpmyJOBh2KC00= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787536728; c=relaxed/simple; bh=9rEMCJg7b8Y5yw6ZYCIjVrrCcns1CG1RicoFOElk4z8=; h=MIME-Version:Date:In-Reply-To:Message-ID:Subject:From:To: Content-Type; b=fjFZNqs8c/iAllI9Uf9AtJea1oCOJyBOfxlj3pf2XsAIC/mUOfEMzCdy7U/ZstaiF/szVUDEPHsegmvisDPuU9hai+Vu7PcaaXlraOLcpCz6FpTxEH+9o6FYCo+1lkJmlwlfFfyj5bTFzylUjEGQLf9Vy2xWcdqZHqPxsUJMDXo= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=fail (p=none dis=none) header.from=syzkaller.appspotmail.com; spf=pass smtp.mailfrom=M3KW2WVRGUFZ5GODRSRYTGD7.apphosting.bounces.google.com; arc=none smtp.client-ip=209.85.160.70 Authentication-Results: smtp.subspace.kernel.org; dmarc=fail (p=none dis=none) header.from=syzkaller.appspotmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=M3KW2WVRGUFZ5GODRSRYTGD7.apphosting.bounces.google.com Received: by mail-oa1-f70.google.com with SMTP id 586e51a60fabf-45ecef50eeeso4503505fac.2 for ; Sun, 23 Aug 2026 18:58:46 -0700 (PDT) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787536725; x=1788141525; h=content-type:to:from:subject:message-id:in-reply-to:date :mime-version:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to:content-type; bh=tmFJu3lghuErynC3tMvAbTZo8vSDnrBbH6B405KewdA=; b=TqKRWzOJJUbX/FPNhNila6XBL2cN2z9PN4s297rnmt6wcwv8QnIGwCEQzWS2rMnSPr D0xRHKABljgYRhBcOrqUcvLuL0j5LHh4Q+4LFkOiDKIMVvSTyjRUKG+EF1/r2kunwL/Q QlKKgYu4Ah8HX1hALPXM+u/tEfdKL9KmeV9gRt5syF7RHW/1/CVvbZP4FYOmML071MVZ jK0WBVaPomHvJ7eMtkzW6V7VQsE9fRYxvGA41hfST3igsB54sbDRsR9GCmNDm3LDNSKn 2u9Eb7u10MkX6EPjiRzR+7L15rTuSfWGgoDY81o2CR5k/fEq5pGiHVsrFAIHHsaYzLUU FaUw== X-Gm-Message-State: AFuF++nXcAlqSxxyzAeOowwpvH0S56htEks3AcX4VaXDE0FaOmQXhMy1 1+0hQmeCbOzV8xeW9bkq08ozjV8rgip0rZwy/tXf+y+E/lSSfiHzogONbrGzpvShWdBU8DIOIoR Xc93o69l3YrN8nIXWu4uehLvwZBBSnliI0FLzOeaPru6Xr7f5NXZB7krYL5k= Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Received: by 2002:a05:6871:c8d5:b0:44c:5d96:337 with SMTP id 586e51a60fabf-463516883c1mr21371265fac.13.1787536725413; Sun, 23 Aug 2026 18:58:45 -0700 (PDT) Date: Sun, 23 Aug 2026 18:58:45 -0700 In-Reply-To: <6a8b41b4.dbb3a75c.13dd47.0052.GAE@google.com> X-Google-Appengine-App-Id: s~syzkaller X-Google-Appengine-App-Id-Alias: syzkaller Message-ID: <6a8ba555.dbb3a75c.13dd47.005a.GAE@google.com> Subject: Forwarded: [PATCH] net: atm: fix shift-out-of-bounds in __vcc_connect() From: syzbot To: linux-kernel@vger.kernel.org, syzkaller-bugs@googlegroups.com Content-Type: text/plain; charset="UTF-8" For archival purposes, forwarding an incoming command email to linux-kernel@vger.kernel.org, syzkaller-bugs@googlegroups.com. *** Subject: [PATCH] net: atm: fix shift-out-of-bounds in __vcc_connect() Author: kartikey406@gmail.com #syz test: git://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git master dev->ci_range.vpi_bits and vci_bits can legitimately be ATM_CI_MAX (-1), a sentinel meaning "no range configured, use maximum" (see include/uapi/linux/atmdev.h). Some drivers, such as usbatm_atm_init() in drivers/usb/atm/usbatm.c, set this sentinel and never resolve it to an actual bit width. __vcc_connect() uses these fields directly as a shift amount without checking for the sentinel, so binding a PVC socket on such a device triggers a negative shift: UBSAN: shift-out-of-bounds in net/atm/common.c:381:10 shift exponent -1 is negative Skip the range check when ci_range.vpi_bits/vci_bits is still ATM_CI_MAX, since that value means "unrestricted". Reported-by: syzbot+6665d3db5fef15914802@syzkaller.appspotmail.com Closes: https://syzkaller.appspot.com/bug?extid=6665d3db5fef15914802 Signed-off-by: Deepanshu Kartikey --- net/atm/common.c | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/net/atm/common.c b/net/atm/common.c index 81195727fa18..73057bb016f7 100644 --- a/net/atm/common.c +++ b/net/atm/common.c @@ -378,8 +378,11 @@ static int __vcc_connect(struct atm_vcc *vcc, struct atm_dev *dev, short vpi, int error; if ((vpi != ATM_VPI_UNSPEC && vpi != ATM_VPI_ANY && + dev->ci_range.vpi_bits != ATM_CI_MAX && vpi >> dev->ci_range.vpi_bits) || (vci != ATM_VCI_UNSPEC && - vci != ATM_VCI_ANY && vci >> dev->ci_range.vci_bits)) + vci != ATM_VCI_ANY && + dev->ci_range.vci_bits != ATM_CI_MAX && + vci >> dev->ci_range.vci_bits)) return -EINVAL; if (vci > 0 && vci < ATM_NOT_RSV_VCI && !capable(CAP_NET_BIND_SERVICE)) return -EPERM; -- 2.34.1