]> git.ipfire.org Git - thirdparty/kernel/linux.git/commit
vhost/vdpa: reject overflowing PA map page counts on 32-bit
authorYousef Alhouseen <alhouseenyousef@gmail.com>
Wed, 24 Jun 2026 22:02:02 +0000 (15:02 -0700)
committerMichael S. Tsirkin <mst@redhat.com>
Mon, 3 Aug 2026 19:21:54 +0000 (15:21 -0400)
commit0619aaa34c0c2a2dcb07f0e9c8a34e7efb8c4cdf
tree1ceaea345977f15e232a4e873826547b23d1b1a1
parent1ed35ac7f3fe2b4396bdd29ac3a7f0ebc0829e94
vhost/vdpa: reject overflowing PA map page counts on 32-bit

vhost_vdpa_pa_map() adds the IOVA page offset to the user-controlled map
size before computing the number of pages to pin. On 32-bit systems,
where unsigned long is narrower than u64, that addition can overflow and
the code can pin and map fewer pages than the requested IOTLB range.

Reject sizes that overflow the unsigned long page-count calculation.

Fixes: 22af48cf91aa ("vdpa: factor out vhost_vdpa_pa_map() and vhost_vdpa_pa_unmap()")
Acked-by: Michael S. Tsirkin <mst@redhat.com>
Signed-off-by: Yousef Alhouseen <alhouseenyousef@gmail.com>
Signed-off-by: Michael S. Tsirkin <mst@redhat.com>
Message-ID: <CAMuQ4bX-iDvcUOPPY+NLz95tkRJYwWqvzAr=U48uNaub_HZLGw@mail.gmail.com>
drivers/vhost/vdpa.c