mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH] riscv: ptrace: Zero-initialize regset buffers before copyin
@ 2026-08-26 11:57 Zongmin Zhou
  2026-10-07 16:46 ` Paul Walmsley
  0 siblings, 1 reply; 2+ messages in thread
From: Zongmin Zhou @ 2026-08-26 11:57 UTC (permalink / raw)
  To: oleg, pjw, palmer, aou, alex
  Cc: andybnac, debug, linux-riscv, linux-kernel, Zongmin Zhou

From: Zongmin Zhou <zhouzongmin@kylinos.cn>

user_regset_copyin() only copies `count` bytes, so a PTRACE_SETREGSET
request with a short iov_len leaves the rest of the stack buffer
uninitialized. In riscv_vr_set() that garbage is validated and copied
into the target's vstate, and in riscv_cfi_set() it can be stored as
the target's shadow stack pointer. Zero both buffers, as the get path
already does.

Fixes: 9300f0043974 ("RISC-V: Add ptrace support for vectors")
Fixes: 2af7c9cf021c ("riscv/ptrace: expose riscv CFI status and state via ptrace and in core files")
Signed-off-by: Zongmin Zhou <zhouzongmin@kylinos.cn>
---
 arch/riscv/kernel/ptrace.c | 2 ++
 1 file changed, 2 insertions(+)

diff --git a/arch/riscv/kernel/ptrace.c b/arch/riscv/kernel/ptrace.c
index f336a183667e..e089dd192b13 100644
--- a/arch/riscv/kernel/ptrace.c
+++ b/arch/riscv/kernel/ptrace.c
@@ -230,6 +230,7 @@ static int riscv_vr_set(struct task_struct *target,
 		return -ENODATA;
 
 	/* Copy rest of the vstate except datap */
+	memset(&ptrace_vstate, 0, sizeof(ptrace_vstate));
 	ret = user_regset_copyin(&pos, &count, &kbuf, &ubuf, &ptrace_vstate, 0,
 				 sizeof(struct __riscv_v_regset_state));
 	if (unlikely(ret))
@@ -339,6 +340,7 @@ static int riscv_cfi_set(struct task_struct *target,
 
 	regs = task_pt_regs(target);
 
+	memset(&user_cfi, 0, sizeof(user_cfi));
 	ret = user_regset_copyin(&pos, &count, &kbuf, &ubuf, &user_cfi, 0, -1);
 	if (ret)
 		return ret;
-- 
2.34.1


No virus found
		Checked by Hillstone Network AntiVirus


^ permalink raw reply	[flat|nested] 2+ messages in thread

* Re: [PATCH] riscv: ptrace: Zero-initialize regset buffers before copyin
  2026-08-26 11:57 [PATCH] riscv: ptrace: Zero-initialize regset buffers before copyin Zongmin Zhou
@ 2026-10-07 16:46 ` Paul Walmsley
  0 siblings, 0 replies; 2+ messages in thread
From: Paul Walmsley @ 2026-10-07 16:46 UTC (permalink / raw)
  To: Zongmin Zhou
  Cc: oleg, pjw, palmer, aou, alex, andybnac, debug, linux-riscv,
	linux-kernel, Zongmin Zhou

On Wed, 26 Aug 2026, Zongmin Zhou wrote:

> From: Zongmin Zhou <zhouzongmin@kylinos.cn>
> 
> user_regset_copyin() only copies `count` bytes, so a PTRACE_SETREGSET
> request with a short iov_len leaves the rest of the stack buffer
> uninitialized. In riscv_vr_set() that garbage is validated and copied
> into the target's vstate, and in riscv_cfi_set() it can be stored as
> the target's shadow stack pointer. Zero both buffers, as the get path
> already does.
> 
> Fixes: 9300f0043974 ("RISC-V: Add ptrace support for vectors")
> Fixes: 2af7c9cf021c ("riscv/ptrace: expose riscv CFI status and state via ptrace and in core files")
> Signed-off-by: Zongmin Zhou <zhouzongmin@kylinos.cn>

Thanks, queued for v7.3-rc.


- Paul


^ permalink raw reply	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2026-10-07 16:46 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-08-26 11:57 [PATCH] riscv: ptrace: Zero-initialize regset buffers before copyin Zongmin Zhou
2026-10-07 16:46 ` Paul Walmsley

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®