]> git.ipfire.org Git - thirdparty/kernel/stable.git/commit
sctp: Fix undefined behavior in left shift operation
authorYu-Chun Lin <eleanor15x@gmail.com>
Tue, 18 Feb 2025 08:12:16 +0000 (16:12 +0800)
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Sat, 22 Mar 2025 19:54:19 +0000 (12:54 -0700)
commit94e7476fa7c5412c67a7cb5feb8b8180f69f09f7
tree2bf4a6f7ba017fe5d7889b3474aeb557d941b0a4
parent7ece63c977c11979007c2b65b3cc4bb6eabc1aab
sctp: Fix undefined behavior in left shift operation

[ Upstream commit 606572eb22c1786a3957d24307f5760bb058ca19 ]

According to the C11 standard (ISO/IEC 9899:2011, 6.5.7):
"If E1 has a signed type and E1 x 2^E2 is not representable in the result
type, the behavior is undefined."

Shifting 1 << 31 causes signed integer overflow, which leads to undefined
behavior.

Fix this by explicitly using '1U << 31' to ensure the shift operates on
an unsigned type, avoiding undefined behavior.

Signed-off-by: Yu-Chun Lin <eleanor15x@gmail.com>
Link: https://patch.msgid.link/20250218081217.3468369-1-eleanor15x@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
net/sctp/stream.c