]> git.ipfire.org Git - thirdparty/linux.git/commitdiff
s390/dasd: Fix undersized format-check buffer
authorStefan Haberland <sth@linux.ibm.com>
Mon, 27 Jul 2026 14:28:40 +0000 (16:28 +0200)
committerJens Axboe <axboe@kernel.dk>
Fri, 31 Jul 2026 14:28:08 +0000 (08:28 -0600)
fmt_buffer_size in dasd_eckd_check_device_format() is declared as
int, even though one of the multiplicands, sizeof(struct eckd_count),
is a size_t. The expression

    trkcount * rpt_max * sizeof(struct eckd_count)

is therefore correctly evaluated at 64-bit width, but the result is
silently truncated when it is stored back into the 32-bit
fmt_buffer_size variable. For a sufficiently large track range
(start_unit/stop_unit are caller-controlled) this truncation
yields a buffer size far smaller than the number of tracks actually
requested. kzalloc() then succeeds with an undersized allocation,
while the subsequent channel program build still operates on the
untruncated track count and writes past the end of that buffer.

Compute the buffer size with check_mul_overflow() and keep it in a
size_t, so that a value that no longer fits results in -EINVAL
instead of a silently truncated allocation size.

Fixes: 8fd575200db5 ("s390/dasd: Add new ioctl BIODASDCHECKFMT")
Cc: stable@vger.kernel.org #4.7
Reviewed-by: Jan Höppner <hoeppner@linux.ibm.com>
Signed-off-by: Stefan Haberland <sth@linux.ibm.com>
Link: https://patch.msgid.link/20260727142840.567286-4-sth@linux.ibm.com
Signed-off-by: Jens Axboe <axboe@kernel.dk>
drivers/s390/block/dasd_eckd.c

index 74fe73b5738abcc93e5ebd2e9d7fc075a475ee33..d356a9f8f016fdb5e390acbc267a3c452ed87595 100644 (file)
@@ -20,6 +20,7 @@
 #include <linux/seq_file.h>
 #include <linux/uaccess.h>
 #include <linux/io.h>
+#include <linux/overflow.h>
 
 #include <asm/css_chars.h>
 #include <asm/machine.h>
@@ -3475,11 +3476,11 @@ static int dasd_eckd_check_device_format(struct dasd_device *base,
 {
        struct dasd_eckd_private *private = base->private;
        struct eckd_count *fmt_buffer;
-       struct irb irb;
+       size_t fmt_buffer_size;
+       unsigned int trkcount;
        int rpt_max, rpt_exp;
-       int fmt_buffer_size;
+       struct irb irb;
        int trk_per_cyl;
-       int trkcount;
        int tpm = 0;
        int rc;
 
@@ -3490,7 +3491,9 @@ static int dasd_eckd_check_device_format(struct dasd_device *base,
        rpt_exp = recs_per_track(&private->rdc_data, 0, cdata->expect.blksize);
 
        trkcount = cdata->expect.stop_unit - cdata->expect.start_unit + 1;
-       fmt_buffer_size = trkcount * rpt_max * sizeof(struct eckd_count);
+       if (check_mul_overflow(trkcount, rpt_max, &fmt_buffer_size) ||
+           check_mul_overflow(fmt_buffer_size, sizeof(struct eckd_count), &fmt_buffer_size))
+               return -EINVAL;
 
        fmt_buffer = kzalloc(fmt_buffer_size, GFP_KERNEL | GFP_DMA);
        if (!fmt_buffer)