From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from mailout4.w1.samsung.com ([210.118.77.14]:39364 "EHLO mailout4.w1.samsung.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1752217AbbGAMs5 (ORCPT ); Wed, 1 Jul 2015 08:48:57 -0400 Received: from eucpsbgm2.samsung.com (unknown [203.254.199.245]) by mailout4.w1.samsung.com (Oracle Communications Messaging Server 7.0.5.31.0 64bit (built May 5 2014)) with ESMTP id <0NQT003PC7LIVIB0@mailout4.w1.samsung.com> for stable@vger.kernel.org; Wed, 01 Jul 2015 13:48:54 +0100 (BST) From: Marek Szyprowski To: linux-arm-kernel@lists.infradead.org Cc: Marek Szyprowski , Russell King - ARM Linux , Hyungwon Hwang , Inki Dae , stable@vger.kernel.org Subject: [PATCH] arm: dma-mapping: fix off-by-one error in bitmap size check Date: Wed, 01 Jul 2015 14:48:03 +0200 Message-id: <1435754903-25108-1-git-send-email-m.szyprowski@samsung.com> Sender: stable-owner@vger.kernel.org List-ID: nr_bitmaps member of mapping structure stores the number of already allocated bitmaps and it is interpreted as loop iterator (it starts from 0 not from 1), so a comparison against number of possible bitmap extensions should include this fact. This patch fixes this by changing the extension failure condition. This issue has been introduced by commit 4d852ef8c2544ce21ae41414099a7504c61164a0 ("arm: dma-mapping: Add support to extend DMA IOMMU mappings"). Reported-by: Hyungwon Hwang Signed-off-by: Marek Szyprowski CC: stable@vger.kernel.org # v3.15+ --- arch/arm/mm/dma-mapping.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/arch/arm/mm/dma-mapping.c b/arch/arm/mm/dma-mapping.c index a64b7f621067..05619542a1c0 100644 --- a/arch/arm/mm/dma-mapping.c +++ b/arch/arm/mm/dma-mapping.c @@ -2015,7 +2015,7 @@ static int extend_iommu_mapping(struct dma_iommu_mapping *mapping) { int next_bitmap; - if (mapping->nr_bitmaps > mapping->extensions) + if (mapping->nr_bitmaps => mapping->extensions) return -EINVAL; next_bitmap = mapping->nr_bitmaps; -- 1.9.2