]> git.ipfire.org Git - thirdparty/kernel/linux.git/commitdiff
riscv: hwprobe: Avoid uninitialized read in hwprobe_get_cpus()
authorMark Harris <mark.hsj@gmail.com>
Tue, 14 Jul 2026 00:30:56 +0000 (17:30 -0700)
committerPaul Walmsley <pjw@kernel.org>
Wed, 15 Jul 2026 17:12:40 +0000 (11:12 -0600)
When cpusetsize < cpumask_size(), hwprobe_get_cpus() did not fully
initialize its copy of the cpu mask, which could cause non-deterministic
results from the riscv_hwprobe syscall on a system with more than 8 CPUs
when the supplied cpu mask is empty.  Address this by fully initializing
the cpu mask.

Fixes: e178bf146e4b ("RISC-V: hwprobe: Introduce which-cpus flag")
Signed-off-by: Mark Harris <mark.hsj@gmail.com>
Reviewed-by: Nam Cao <namcao@linutronix.de>
Reviewed-by: Michael Ellerman <mpe@kernel.org>
Link: https://patch.msgid.link/20260714003056.73707-1-mark.hsj@gmail.com
Signed-off-by: Paul Walmsley <pjw@kernel.org>
arch/riscv/kernel/sys_hwprobe.c

index 1659d31fd288fc296d711c111e8d1a2e2fc8026a..caf6762427c87e1c1b5ec86146a46553d3cdf216 100644 (file)
@@ -450,6 +450,7 @@ static int hwprobe_get_cpus(struct riscv_hwprobe __user *pairs,
        if (cpusetsize > cpumask_size())
                cpusetsize = cpumask_size();
 
+       cpumask_clear(&cpus);
        ret = copy_from_user(&cpus, cpus_user, cpusetsize);
        if (ret)
                return -EFAULT;