* [PATCH] riscv: ptrace: Zero-initialize regset buffers before copyin
@ 2026-08-26 11:57 Zongmin Zhou
2026-10-07 16:46 ` Paul Walmsley
0 siblings, 1 reply; 2+ messages in thread
From: Zongmin Zhou @ 2026-08-26 11:57 UTC (permalink / raw)
To: oleg, pjw, palmer, aou, alex
Cc: andybnac, debug, linux-riscv, linux-kernel, Zongmin Zhou
From: Zongmin Zhou <zhouzongmin@kylinos.cn>
user_regset_copyin() only copies `count` bytes, so a PTRACE_SETREGSET
request with a short iov_len leaves the rest of the stack buffer
uninitialized. In riscv_vr_set() that garbage is validated and copied
into the target's vstate, and in riscv_cfi_set() it can be stored as
the target's shadow stack pointer. Zero both buffers, as the get path
already does.
Fixes: 9300f0043974 ("RISC-V: Add ptrace support for vectors")
Fixes: 2af7c9cf021c ("riscv/ptrace: expose riscv CFI status and state via ptrace and in core files")
Signed-off-by: Zongmin Zhou <zhouzongmin@kylinos.cn>
---
arch/riscv/kernel/ptrace.c | 2 ++
1 file changed, 2 insertions(+)
diff --git a/arch/riscv/kernel/ptrace.c b/arch/riscv/kernel/ptrace.c
index f336a183667e..e089dd192b13 100644
--- a/arch/riscv/kernel/ptrace.c
+++ b/arch/riscv/kernel/ptrace.c
@@ -230,6 +230,7 @@ static int riscv_vr_set(struct task_struct *target,
return -ENODATA;
/* Copy rest of the vstate except datap */
+ memset(&ptrace_vstate, 0, sizeof(ptrace_vstate));
ret = user_regset_copyin(&pos, &count, &kbuf, &ubuf, &ptrace_vstate, 0,
sizeof(struct __riscv_v_regset_state));
if (unlikely(ret))
@@ -339,6 +340,7 @@ static int riscv_cfi_set(struct task_struct *target,
regs = task_pt_regs(target);
+ memset(&user_cfi, 0, sizeof(user_cfi));
ret = user_regset_copyin(&pos, &count, &kbuf, &ubuf, &user_cfi, 0, -1);
if (ret)
return ret;
--
2.34.1
No virus found
Checked by Hillstone Network AntiVirus
^ permalink raw reply [flat|nested] 2+ messages in thread
* Re: [PATCH] riscv: ptrace: Zero-initialize regset buffers before copyin
2026-08-26 11:57 [PATCH] riscv: ptrace: Zero-initialize regset buffers before copyin Zongmin Zhou
@ 2026-10-07 16:46 ` Paul Walmsley
0 siblings, 0 replies; 2+ messages in thread
From: Paul Walmsley @ 2026-10-07 16:46 UTC (permalink / raw)
To: Zongmin Zhou
Cc: oleg, pjw, palmer, aou, alex, andybnac, debug, linux-riscv,
linux-kernel, Zongmin Zhou
On Wed, 26 Aug 2026, Zongmin Zhou wrote:
> From: Zongmin Zhou <zhouzongmin@kylinos.cn>
>
> user_regset_copyin() only copies `count` bytes, so a PTRACE_SETREGSET
> request with a short iov_len leaves the rest of the stack buffer
> uninitialized. In riscv_vr_set() that garbage is validated and copied
> into the target's vstate, and in riscv_cfi_set() it can be stored as
> the target's shadow stack pointer. Zero both buffers, as the get path
> already does.
>
> Fixes: 9300f0043974 ("RISC-V: Add ptrace support for vectors")
> Fixes: 2af7c9cf021c ("riscv/ptrace: expose riscv CFI status and state via ptrace and in core files")
> Signed-off-by: Zongmin Zhou <zhouzongmin@kylinos.cn>
Thanks, queued for v7.3-rc.
- Paul
^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2026-10-07 16:46 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-08-26 11:57 [PATCH] riscv: ptrace: Zero-initialize regset buffers before copyin Zongmin Zhou
2026-10-07 16:46 ` Paul Walmsley
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®