]> git.ipfire.org Git - thirdparty/linux.git/commitdiff
arc: validate DT CPU map strings before parsing them
authorPengpeng Hou <pengpeng@iscas.ac.cn>
Fri, 10 Jul 2026 22:26:04 +0000 (15:26 -0700)
committerVineet Gupta <vgupta@kernel.org>
Fri, 10 Jul 2026 22:26:04 +0000 (15:26 -0700)
arc_get_cpu_map() fetches the possible-cpus or present-cpus property
from the flat DT and immediately passes the raw pointer to
cpulist_parse(). That parser expects a NUL-terminated text buffer, but
this path does not prove that the DT property is terminated within its
declared bounds.

Reject unterminated CPU-map properties before handing them to
cpulist_parse().

Changes since v1:
- fold the NUL-termination check into the initial lookup test, as
  suggested by Vineet Gupta

Signed-off-by: Pengpeng Hou <pengpeng@iscas.ac.cn>
Signed-off-by: Vineet Gupta <vgupta@kernel.org>
arch/arc/kernel/smp.c

index b2f2c59279a6799ad89daf3ce709b8d010915920..2d99dffed0ce5c099191d76e6571a1c67a874196 100644 (file)
@@ -22,6 +22,7 @@
 #include <linux/irqdomain.h>
 #include <linux/export.h>
 #include <linux/of_fdt.h>
+#include <linux/string.h>
 
 #include <asm/mach_desc.h>
 #include <asm/setup.h>
@@ -43,9 +44,10 @@ static int __init arc_get_cpu_map(const char *name, struct cpumask *cpumask)
 {
        unsigned long dt_root = of_get_flat_dt_root();
        const char *buf;
+       int len;
 
-       buf = of_get_flat_dt_prop(dt_root, name, NULL);
-       if (!buf)
+       buf = of_get_flat_dt_prop(dt_root, name, &len);
+       if (!buf || !memchr(buf, '\0', len))
                return -EINVAL;
 
        if (cpulist_parse(buf, cpumask))