]> git.ipfire.org Git - thirdparty/linux.git/commitdiff
x86/boot: Reject too long acpi_rsdp= values
authorThorsten Blum <thorsten.blum@linux.dev>
Sun, 21 Jun 2026 17:00:10 +0000 (19:00 +0200)
committerBorislav Petkov (AMD) <bp@alien8.de>
Sun, 12 Jul 2026 02:25:26 +0000 (19:25 -0700)
cmdline_find_option() returns the full length of the parsed acpi_rsdp=
value. get_cmdline_acpi_rsdp() then silently truncates values which do
not fit in the val[] buffer.

Prevent boot_kstrtoul() from parsing a truncated value and then the
kernel from silently using the wrong RSDP address, see discussion in
Link:.

Issue a warning so that the user is aware that s/he supplied a malformed
value and can get feedback instead of silent crashes.

  [ bp: Make commit message more precise. ]

Fixes: 3c98e71b42a7 ("x86/boot: Add "acpi_rsdp=" early parsing")
Signed-off-by: Thorsten Blum <thorsten.blum@linux.dev>
Signed-off-by: Borislav Petkov (AMD) <bp@alien8.de>
Cc: stable@vger.kernel.org
Link: https://lore.kernel.org/all/20260617130417.36651-4-thorsten.blum@linux.dev
arch/x86/boot/compressed/acpi.c

index f196b1d1ddf867b62161cb0528872526c82a693f..aed27604c11f0bbf9efde51b96486fd931d72442 100644 (file)
@@ -184,10 +184,15 @@ static unsigned long get_cmdline_acpi_rsdp(void)
        char val[MAX_ADDR_LEN] = { };
        int ret;
 
-       ret = cmdline_find_option("acpi_rsdp", val, MAX_ADDR_LEN);
+       ret = cmdline_find_option("acpi_rsdp", val, sizeof(val));
        if (ret < 0)
                return 0;
 
+       if (ret >= sizeof(val)) {
+               warn("acpi_rsdp= value too long; ignoring");
+               return 0;
+       }
+
        if (boot_kstrtoul(val, 16, &addr))
                return 0;
 #endif