]> git.ipfire.org Git - thirdparty/kernel/linux.git/commit
iommu: Do not call drivers for empty gathers
authorJason Gunthorpe <jgg@nvidia.com>
Mon, 2 Mar 2026 22:22:52 +0000 (18:22 -0400)
committerJoerg Roedel <joerg.roedel@amd.com>
Fri, 27 Mar 2026 08:07:13 +0000 (09:07 +0100)
commit90c5def10bea574b101b7a520c015ca81742183f
tree67e24090ebc1406fec613e29750e90d673653926
parentc369299895a591d96745d6492d4888259b004a9e
iommu: Do not call drivers for empty gathers

An empty gather is coded with start=U64_MAX, end=0 and several drivers go
on to convert that to a size with:

 end - start + 1

Which gives 2 for an empty gather. This then causes Weird Stuff to
happen (for example an UBSAN splat in VT-d) that is hopefully harmless,
but maybe not.

Prevent drivers from being called right in iommu_iotlb_sync().

Auditing shows that AMD, Intel, Mediatek and RSIC-V drivers all do things
on these empty gathers.

Further, there are several callers that can trigger empty gathers,
especially in unusual conditions. For example iommu_map_nosync() will call
a 0 size unmap on some error paths. Also in VFIO, iommupt and other
places.

Cc: stable@vger.kernel.org
Reported-by: Janusz Krzysztofik <janusz.krzysztofik@linux.intel.com>
Closes: https://lore.kernel.org/r/11145826.aFP6jjVeTY@jkrzyszt-mobl2.ger.corp.intel.com
Signed-off-by: Jason Gunthorpe <jgg@nvidia.com>
Reviewed-by: Lu Baolu <baolu.lu@linux.intel.com>
Reviewed-by: Samiullah Khawaja <skhawaja@google.com>
Reviewed-by: Robin Murphy <robin.murphy@arm.com>
Reviewed-by: Vasant Hegde <vasant.hegde@amd.com>
Signed-off-by: Joerg Roedel <joerg.roedel@amd.com>
include/linux/iommu.h