From: Leizhen Zhang <lzsx618@gmail.com>
To: nathan@kernel.org, nsc@kernel.org
Cc: rostedt@goodmis.org, linux-kbuild@vger.kernel.org,
linux-kernel@vger.kernel.org
Subject: [PATCH v2 8/8] tools/include: fix signed shift overflow in 32-bit unaligned accessors
Date: Thu, 8 Oct 2026 11:40:35 -0500 [thread overview]
Message-ID: <20261008164035.3668885-9-lzsx618@gmail.com> (raw)
In-Reply-To: <20261008164035.3668885-1-lzsx618@gmail.com>
In __get_unaligned_le32() and __get_unaligned_be32() the most significant
byte is promoted to int before being shifted left by 24. If the byte is
0x80 or higher, the result does not fit in an int, which is undefined
behaviour. This happens for every kernel virtual address, e.g. in
sorttable, and UBSan reports:
tools/include/tools/le_byteshift.h:14: runtime error: left shift of
255 by 24 places cannot be represented in type 'int'
Cast the byte to uint32_t before shifting.
Fixes: a07f7672d7cf ("tools/include: Add byteshift headers for endian access")
Assisted-by: Claude:claude-opus-5-5 UBSan
Signed-off-by: Leizhen Zhang <lzsx618@gmail.com>
---
v2:
- Use my real name in the From and Signed-off-by lines. No code
changes.
v1: https://lore.kernel.org/r/20261005104050.1786222-10-lzsx618@gmail.com
tools/include/tools/be_byteshift.h | 2 +-
tools/include/tools/le_byteshift.h | 2 +-
2 files changed, 2 insertions(+), 2 deletions(-)
diff --git a/tools/include/tools/be_byteshift.h b/tools/include/tools/be_byteshift.h
index f7d1d16989..2bda8d199c 100644
--- a/tools/include/tools/be_byteshift.h
+++ b/tools/include/tools/be_byteshift.h
@@ -11,7 +11,7 @@ static inline uint16_t __get_unaligned_be16(const uint8_t *p)
static inline uint32_t __get_unaligned_be32(const uint8_t *p)
{
- return p[0] << 24 | p[1] << 16 | p[2] << 8 | p[3];
+ return (uint32_t)p[0] << 24 | p[1] << 16 | p[2] << 8 | p[3];
}
static inline uint64_t __get_unaligned_be64(const uint8_t *p)
diff --git a/tools/include/tools/le_byteshift.h b/tools/include/tools/le_byteshift.h
index dc8565f397..e5c78a48a7 100644
--- a/tools/include/tools/le_byteshift.h
+++ b/tools/include/tools/le_byteshift.h
@@ -11,7 +11,7 @@ static inline uint16_t __get_unaligned_le16(const uint8_t *p)
static inline uint32_t __get_unaligned_le32(const uint8_t *p)
{
- return p[0] | p[1] << 8 | p[2] << 16 | p[3] << 24;
+ return p[0] | p[1] << 8 | p[2] << 16 | (uint32_t)p[3] << 24;
}
static inline uint64_t __get_unaligned_le64(const uint8_t *p)
--
2.34.1
prev parent reply other threads:[~2026-10-08 16:41 UTC|newest]
Thread overview: 9+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-08 16:40 [PATCH v2 0/8] kbuild: fix memory safety and UB bugs in host tools found by fuzzing Leizhen Zhang
2026-10-08 16:40 ` [PATCH v2 1/8] genksyms: fix infinite loop on declarations with parameter lists Leizhen Zhang
2026-10-08 16:40 ` [PATCH v2 2/8] fixdep: fix out-of-bounds read on a comment ending with a backslash Leizhen Zhang
2026-10-08 16:40 ` [PATCH v2 3/8] kallsyms: do not call qsort() with a NULL table Leizhen Zhang
2026-10-08 16:40 ` [PATCH v2 4/8] modpost: fix stack out-of-bounds read for unterminated PNP ids Leizhen Zhang
2026-10-08 16:40 ` [PATCH v2 5/8] modpost: fix handling of short reads in read_text_file() Leizhen Zhang
2026-10-08 16:40 ` [PATCH v2 6/8] modpost: fix pointer arithmetic on NULL in parse_source_files() Leizhen Zhang
2026-10-08 16:40 ` [PATCH v2 7/8] sorttable: avoid pointer arithmetic overflow when locating sort_needed Leizhen Zhang
2026-10-08 16:40 ` Leizhen Zhang [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20261008164035.3668885-9-lzsx618@gmail.com \
--to=lzsx618@gmail.com \
--cc=linux-kbuild@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=nathan@kernel.org \
--cc=nsc@kernel.org \
--cc=rostedt@goodmis.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®