]> git.ipfire.org Git - thirdparty/kernel/linux.git/commitdiff
iommu/intel: Fix out-of-bounds memset in dmar_latency_disable()
authorLi RongQing <lirongqing@baidu.com>
Tue, 21 Jul 2026 09:34:10 +0000 (17:34 +0800)
committerWill Deacon <will@kernel.org>
Tue, 21 Jul 2026 11:34:51 +0000 (11:34 +0000)
dmar_latency_disable() intends to zero out only the single
latency_statistic entry for the given type, but the memset size was
computed as sizeof(*lstat) * DMAR_LATENCY_NUM, which clears the entire
array starting from &lstat[type].

When type > 0, this writes beyond the end of the allocated array,
corrupting adjacent memory.

Fix by using sizeof(*lstat) to clear only the target entry.

Fixes: 55ee5e67a59a ("iommu/vt-d: Add common code for dmar latency performance monitors")
Signed-off-by: Li RongQing <lirongqing@baidu.com>
Signed-off-by: Will Deacon <will@kernel.org>
drivers/iommu/intel/perf.c

index 02168f2f20a43fc0e54f22d8d1c572d74a28f7c6..bec98dcbb9ecaec58a14e821625259f9e48f1c36 100644 (file)
@@ -63,7 +63,7 @@ void dmar_latency_disable(struct intel_iommu *iommu, enum latency_type type)
                return;
 
        spin_lock_irqsave(&latency_lock, flags);
-       memset(&lstat[type], 0, sizeof(*lstat) * DMAR_LATENCY_NUM);
+       memset(&lstat[type], 0, sizeof(*lstat));
        spin_unlock_irqrestore(&latency_lock, flags);
 }