On Thu, 24 Sep 2026, Hui Peng wrote: > In uart_set_info(), new_info->baud_base is multiplied by 16 and stored in > uport->uartclk (an unsigned int): > > uport->uartclk = new_info->baud_base * 16; > > While uart_set_info() checks if (uartclk == 0) and > if (new_info->baud_base < 9600), when new_info->baud_base exceeds > UINT_MAX / 16 with low bits set (for example, 0x10000001), multiplying > by 16 wraps around in 32-bit unsigned arithmetic to a small non-zero value > (16), bypassing both uartclk == 0 and new_info->baud_base < 9600 and > setting uport->uartclk = 16 (baud_base = 1, well below the required > minimum of 9600 * 16). > > Reject new_info->baud_base > UINT_MAX / 16 before multiplying by 16 in > uart_set_info(). > > Tested in QEMU against Linux 7.3.0-rc3 by calling ioctl(fd, TIOCSSERIAL, > &ss) with ss.baud_base = 0x10000001 on /dev/ttyS1: on the unfixed kernel > TIOCSSERIAL succeeds (ret = 0) and wraps uport->uartclk to 16 > (TIOCGSERIAL reports baud_base = 1), whereas with the fix applied > TIOCSSERIAL returns -EINVAL and preserves the existing uport->uartclk. > > Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2") > Fixes: 6eabce6608d6 ("serial: core: check uartclk for zero to avoid divide by zero") > Cc: stable@vger.kernel.org > Assisted-by: LLM > Signed-off-by: Hui Peng > --- > Changes in v4: > - Check new_info->baud_base > UINT_MAX / 16 before multiplying by 16, > as suggested by Ilpo Järvinen. > > Changes in v3: > - Add missing #include for UINT_MAX and move the > new_info->baud_base > UINT_MAX / 16 check to the uartclk == 0 check, as > suggested by Ilpo Järvinen. > > drivers/tty/serial/serial_core.c | 8 +++++++- > 1 file changed, 7 insertions(+), 1 deletion(-) > > diff --git a/drivers/tty/serial/serial_core.c b/drivers/tty/serial/serial_core.c > index 95774b0f1484..75bb1eaa27e7 100644 > --- a/drivers/tty/serial/serial_core.c > +++ b/drivers/tty/serial/serial_core.c > @@ -16,6 +16,7 @@ > #include > #include > #include > +#include > #include > #include > #include > @@ -931,8 +932,13 @@ static int uart_set_info(struct tty_struct *tty, struct tty_port *port, > old_custom_divisor = uport->custom_divisor; > > if (!(uport->flags & UPF_FIXED_PORT)) { > - unsigned int uartclk = new_info->baud_base * 16; > + unsigned int uartclk; > + > /* check needs to be done here before other settings made */ > + if (new_info->baud_base > UINT_MAX / 16) > + return -EINVAL; > + > + uartclk = new_info->baud_base * 16; > if (uartclk == 0) > return -EINVAL; > } > Reviewed-by: Ilpo Järvinen -- i.