From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-pf1-f179.google.com (mail-pf1-f179.google.com [209.85.210.179]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 1BD0238F25D for ; Wed, 8 Apr 2026 12:02:02 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.210.179 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1775649724; cv=none; b=WvfYviyPIcm3EFaRlS/LEGBNk+gZIz3QZvGyr3FeGvG32IX3A9RCdCA5WstyCE5ZahZMB7tdaFUJmHcUE5SUL+71NWpd/JqzKqp6J4Q7g/dCR/0wIglWPFydBIz0o93CMNiQUAqT2RfWlA5MWwP6IgDhm1u0NA4sk8gYMMgvMnU= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1775649724; c=relaxed/simple; bh=GdgHfu4NwRR5nHQPLhhd8u0gAQp21be2yqKo5lXv4k4=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=CP3jRFeREeSR4WPNs7Exs/eT/OGhFt+mWL46viYSU8H7OTtG/jxbNCnK5sQzJtE8kLTOxlaRSuLp29LPMuEzEjuDP3nAZVRDJIC394ou3i7l6rmAZY7F9P46noPC00Gn9EUKTuLlanV5czb0IXwz1keOQriWMqsqW2SUpTnv84E= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=R60ZS7am; arc=none smtp.client-ip=209.85.210.179 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="R60ZS7am" Received: by mail-pf1-f179.google.com with SMTP id d2e1a72fcca58-82418b0178cso2877991b3a.1 for ; Wed, 08 Apr 2026 05:02:02 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1775649722; x=1776254522; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to; bh=PHdUj5TFH9dKxJLMiJUsQpHQaLsjedD8VYK/u5ysz28=; b=R60ZS7am8ikHKkUZLgQN0PLWPN0ZIXCAC+Ie1WkwR2cz02qjJ0q+BfyguPkocZexf+ Zm88nyaqMrmvnpQid5vivRaiRV4JhAq7dP3OhvdlOraKEgqvHlHlXPsbCToKo5j+JSvh FhZ7J6JIEm4Zmco3BUT+EFA548+zI0A/9JU/EpUJQVQ1/OYj4a/1uY2Sjs2myh0+GCtS 0VA0ok19DwYDJVONEO2gIcJLM+6yut+WmIb5+BN3MDyfv2QBYmEOyuqZh9dp8yiKbZ4k dtjxiWZAsrlzq6xmo2gf1aKF49MSCZ6kDtqZMPwOq2rYYVGR/fLpaAnz0E4gIFKHBlLD KMLw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1775649722; x=1776254522; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to; bh=PHdUj5TFH9dKxJLMiJUsQpHQaLsjedD8VYK/u5ysz28=; b=EZUenZGaH7RDfC1BMnhRTFSls5GnbAOdNNmCzkFqo9pjYoEJGkEXVDTREpbbO06ukS erNgcS/g4G2KV2jVGQztONCWNAWEe2INpuQg7Vn9GRDIxDRZ3ieBMhi0o5vd2BvPMQTG uWZYTrqekBzN8SDo/DnDRP7Day+LTmffZGsJCz9lWx71zI4xCqAvCEsPxVUBVTwq/thC QDLb0t9PPrldlaDTBlYKARnN7M9GB3EOkrq/soeu+MkSpkaldWLXZZpmqi1ft7S6hK6Z wH0jBosgYxfg7TuxDe2AZ5gcs+w7KikEhVl5b+g3mfKcWVQtuu4FOYuXJK3oIWJna8l5 CDcg== X-Forwarded-Encrypted: i=1; AJvYcCXL/M25hRLTlHz7J1fbFId/q90/buSzYQb4LnqSNfL//nDLKKGsYoDPl+SPOnYdWEgwisqXe3U2jX4ZsHQ=@vger.kernel.org X-Gm-Message-State: AOJu0YwN9cipngjcqZ2OgK82zRUBwG24saaEOFjmxPBc4F9gtYMck1i8 PIvwKE4cNeaw/vjM1LTpmejKUsk9Cp8ydDc7Qne9p2RCbcy896BuPAqv X-Gm-Gg: AeBDietRGROESHxCJI/iL88/JBwa9x7Tas+gPA40bv2Zil3hXmmzhXEAlEGq1diiuUJ JEGGE7/jInBqHzVRPqusA/XUuzPBwT/6HvqcmFO+0nnfl6/JmqH86D4J536B0enYIWmF1QPOeS5 m4GCD9aQU3zcYMp0X3JBWD2t7rH1Fmszq8irOIqIpA/d0RHph9hTGkItdOgxM0WuwoYt2TOV5IZ SE52VxZx/Kcrsm/O3goBLSKwFt65F35O4+kD3LdehJomswQq95hBmlJfWs5f2BdSbjTv4bpbU/O m8cQ0NzYnui7yOrthiWas72hp96z92+/hq5xyewlJnXXoY3PZIvQN4wYAmHHLrspiuzD4pY+VCA 3fAYvcgbSjlDcqbXjGSa4iUrOTj0uVPgOmZ+KqZkSmavXvnu+DuTdB0/AQgss5Lrbui3Pdsit4w /qWhcFUGpZQSuebr0fp95irBjKQ6mqM/H4TIlxpnKiUyKB X-Received: by 2002:a05:6a00:4b50:b0:820:2f9b:fe31 with SMTP id d2e1a72fcca58-82d0db53786mr21789802b3a.30.1775649722177; Wed, 08 Apr 2026 05:02:02 -0700 (PDT) Received: from Mac.localdomain ([49.205.216.49]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-82cf9b3e169sm21209322b3a.18.2026.04.08.05.01.58 (version=TLS1_3 cipher=TLS_CHACHA20_POLY1305_SHA256 bits=256/256); Wed, 08 Apr 2026 05:02:01 -0700 (PDT) From: "Ritesh Harjani (IBM)" To: linuxppc-dev@lists.ozlabs.org, Haren Myneni Cc: Madhavan Srinivasan , Christophe Leroy , Venkat Rao Bagalkote , Nicholas Piggin , linux-kernel@vger.kernel.org, "Ritesh Harjani (IBM)" , stable@vger.kernel.org Subject: [RFC v2 02/10] pseries/papr-hvpipe: Prevent kernel stack memory leak to userspace Date: Wed, 8 Apr 2026 17:31:32 +0530 Message-ID: X-Mailer: git-send-email 2.50.1 In-Reply-To: References: Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit The hdr variable is allocated on the stack and only hdr.version and hdr.flags are initialized explicitly. Because the struct papr_hvpipe_hdr contains reserved padding bytes (reserved[3] and reserved2[40]), these could leak the uninitialized bytes to userspace after copy_to_user(). This patch fixes that by initializing the whole struct to 0. Cc: stable@vger.kernel.org Fixes: 814ef095f12c9 ("powerpc/pseries: Add papr-hvpipe char driver for HVPIPE interfaces") Signed-off-by: Ritesh Harjani (IBM) --- arch/powerpc/platforms/pseries/papr-hvpipe.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/arch/powerpc/platforms/pseries/papr-hvpipe.c b/arch/powerpc/platforms/pseries/papr-hvpipe.c index c41d45e1986d..3392874ebdf6 100644 --- a/arch/powerpc/platforms/pseries/papr-hvpipe.c +++ b/arch/powerpc/platforms/pseries/papr-hvpipe.c @@ -327,7 +327,7 @@ static ssize_t papr_hvpipe_handle_read(struct file *file, { struct hvpipe_source_info *src_info = file->private_data; - struct papr_hvpipe_hdr hdr; + struct papr_hvpipe_hdr hdr = {}; long ret; /* -- 2.39.5