mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH] dm mirror: fix integer overflow in create_dirty_log()
@ 2026-03-01 13:10 Junrui Luo
  2026-03-02 17:40 ` Benjamin Marzinski
  2026-04-05  6:48 ` Junrui Luo
  0 siblings, 2 replies; 3+ messages in thread
From: Junrui Luo @ 2026-03-01 13:10 UTC (permalink / raw)
  To: Alasdair Kergon, Mike Snitzer, Mikulas Patocka, Benjamin Marzinski
  Cc: dm-devel, linux-kernel, Yuhao Jiang, Junrui Luo

The argument count calculation in create_dirty_log() performs
`*args_used = 2 + param_count` before validating against argc. When a
user provides a param_count close to UINT_MAX via the device mapper
table string, this unsigned addition wraps around to a small value,
causing the subsequent `argc < *args_used` check to be bypassed.

The overflowed param_count is then passed as argc to dm_dirty_log_create(),
where it can cause out-of-bounds reads on the argv array.

Fix by comparing param_count against argc - 2 before performing the
addition, following the same pattern used by parse_features() in the
same file. Since argc >= 2 is already guaranteed, the subtraction is
safe.

Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Reported-by: Yuhao Jiang <danisjiang@gmail.com>
Signed-off-by: Junrui Luo <moonafterrain@outlook.com>
---
 drivers/md/dm-raid1.c | 6 +++---
 1 file changed, 3 insertions(+), 3 deletions(-)

diff --git a/drivers/md/dm-raid1.c b/drivers/md/dm-raid1.c
index 80a5c4127707..de5c00704e69 100644
--- a/drivers/md/dm-raid1.c
+++ b/drivers/md/dm-raid1.c
@@ -993,13 +993,13 @@ static struct dm_dirty_log *create_dirty_log(struct dm_target *ti,
 		return NULL;
 	}
 
-	*args_used = 2 + param_count;
-
-	if (argc < *args_used) {
+	if (param_count > argc - 2) {
 		ti->error = "Insufficient mirror log arguments";
 		return NULL;
 	}
 
+	*args_used = 2 + param_count;
+
 	dl = dm_dirty_log_create(argv[0], ti, mirror_flush, param_count,
 				 argv + 2);
 	if (!dl) {

---
base-commit: 4d349ee5c7782f8b27f6cb550f112c5e26fff38d
change-id: 20260301-fixes-5b596967096c

Best regards,
-- 
Junrui Luo <moonafterrain@outlook.com>


^ permalink raw reply	[flat|nested] 3+ messages in thread

* Re: [PATCH] dm mirror: fix integer overflow in create_dirty_log()
  2026-03-01 13:10 [PATCH] dm mirror: fix integer overflow in create_dirty_log() Junrui Luo
@ 2026-03-02 17:40 ` Benjamin Marzinski
  2026-04-05  6:48 ` Junrui Luo
  1 sibling, 0 replies; 3+ messages in thread
From: Benjamin Marzinski @ 2026-03-02 17:40 UTC (permalink / raw)
  To: Junrui Luo
  Cc: Alasdair Kergon, Mike Snitzer, Mikulas Patocka, dm-devel,
	linux-kernel, Yuhao Jiang

On Sun, Mar 01, 2026 at 09:10:58PM +0800, Junrui Luo wrote:
> The argument count calculation in create_dirty_log() performs
> `*args_used = 2 + param_count` before validating against argc. When a
> user provides a param_count close to UINT_MAX via the device mapper
> table string, this unsigned addition wraps around to a small value,
> causing the subsequent `argc < *args_used` check to be bypassed.
> 
> The overflowed param_count is then passed as argc to dm_dirty_log_create(),
> where it can cause out-of-bounds reads on the argv array.
> 
> Fix by comparing param_count against argc - 2 before performing the
> addition, following the same pattern used by parse_features() in the
> same file. Since argc >= 2 is already guaranteed, the subtraction is
> safe.
> 
> Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
> Reported-by: Yuhao Jiang <danisjiang@gmail.com>
> Signed-off-by: Junrui Luo <moonafterrain@outlook.com>

Reviewed-by: Benjamin Marzinski <bmarzins@redhat.com>


^ permalink raw reply	[flat|nested] 3+ messages in thread

* Re: [PATCH] dm mirror: fix integer overflow in create_dirty_log()
  2026-03-01 13:10 [PATCH] dm mirror: fix integer overflow in create_dirty_log() Junrui Luo
  2026-03-02 17:40 ` Benjamin Marzinski
@ 2026-04-05  6:48 ` Junrui Luo
  1 sibling, 0 replies; 3+ messages in thread
From: Junrui Luo @ 2026-04-05  6:48 UTC (permalink / raw)
  To: Alasdair Kergon, Mike Snitzer, Mikulas Patocka, Benjamin Marzinski
  Cc: dm-devel, linux-kernel, Yuhao Jiang

Hi,

Gentle ping on this patch. It has Benjamin's Reviewed-by but hasn't
been picked up yet. Could this be queued for the next merge window?

Thanks,
Junrui Luo

^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2026-04-05  6:48 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-03-01 13:10 [PATCH] dm mirror: fix integer overflow in create_dirty_log() Junrui Luo
2026-03-02 17:40 ` Benjamin Marzinski
2026-04-05  6:48 ` Junrui Luo

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

Powered by JetHome