From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from cae.in-ulm.de (cae.in-ulm.de [217.10.14.231]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id E051C23B63E for ; Tue, 24 Mar 2026 19:40:00 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=217.10.14.231 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1774381203; cv=none; b=vF6pqH+jtPwzLajfydyUacKgprd+z8Pr79J33tvexR4Wt6MIAP2rhPNk7DCwWV6HPGLdXrPWRBA3tObkRc4qOej8bEmbkCvTvFRl43BJx9bQCVz4emMZOzrTOEsaab4Axaxu1otdGxk9QRBOs88RWxFQojqijOwXLRU+Z5ZJ/Fk= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1774381203; c=relaxed/simple; bh=YdwhenMDauEDkIWRY6yyc3+0VtSbzN1GOzU494pRgb8=; h=Date:From:To:Cc:Subject:Message-ID:References:MIME-Version: Content-Type:Content-Disposition:In-Reply-To; b=iCtCmRL6FWAV4De0aI60P2ibcfjCtnDC7tQ7mhuQ9p/AenkYwErg1V0ov67n1oE9+HgoX+nWfSDxNuwOSIfAgXP89ITbWbRhcUlwxmb4k5I9mI5p+HrmwfVoUiqV6Pevny8VOLkPvLEqEmarr6YICQlkECv6TOWgaoL8MR4EzZ4= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=c--e.de; spf=pass smtp.mailfrom=c--e.de; arc=none smtp.client-ip=217.10.14.231 Authentication-Results: smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=c--e.de Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=c--e.de Received: by cae.in-ulm.de (Postfix, from userid 1000) id 56A841400FB; Tue, 24 Mar 2026 20:39:58 +0100 (CET) Date: Tue, 24 Mar 2026 20:39:58 +0100 From: "Christian A. Ehrhardt" To: Andrew Morton Cc: linux-kernel@vger.kernel.org, David Howells , Kees Cook , Petr Mladek , David Gow Subject: Re: [PATCH RESEND 3/3] lib: Fix length calculation in extract_kvec_to_sg Message-ID: References: <20260323212350.807118-1-lk@c--e.de> <20260323212350.807118-4-lk@c--e.de> <20260324121224.c7efad04eafeead81aead946@linux-foundation.org> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <20260324121224.c7efad04eafeead81aead946@linux-foundation.org> Hi Andrew, On Tue, Mar 24, 2026 at 12:12:24PM -0700, Andrew Morton wrote: > On Mon, 23 Mar 2026 22:23:50 +0100 "Christian A. Ehrhardt" wrote: > > > When extracting from a kvec to a scatterlist, do not > > cross page boundaries. The required length is already > > calculated but not used as intended. > > > > The previous changes to the kunit_iov_iter.c demonstrate > > that the patch is necessary. > > Thanks. > > > Cc: David Howells > > Cc: Andrew Morton > > Cc: stable@vger.kernel.org # v6.5+ > > Could we please have a description of the userspace-visible impact? To > help others understand why we're proposing a backport, The function is used to construct a scatterlist. The result of the bug is that the scatterlist entries have a length that is too long. Results can vary but most likely this will result in silent data corruption. I don't have a use visible example of this, though. The bug was found while staring at code. > > --- a/lib/scatterlist.c > > +++ b/lib/scatterlist.c > > @@ -1249,7 +1249,7 @@ static ssize_t extract_kvec_to_sg(struct iov_iter *iter, > > else > > page = virt_to_page((void *)kaddr); > > > > - sg_set_page(sg, page, len, off); > > + sg_set_page(sg, page, seg, off); > > sgtable->nents++; > > sg++; > > sg_max--; > > I'm thinking the series should be split up - this patch for 7.0-rcX and > -stable, the kunit changes for 7.0-rcX. Or do you think we should > -stableize the kunit changes also? Only the actual fix is marked for backport to -stable but I consider that somewhat critical because it is in essence a memory error. > Or we put it all into 7.0-rcX and let the -stable patch trickle back > later on. After all, 018584697533 was a couple of years ago. It's hard > to decide on these things without that userspace-visible impact thing! Best regards, Christian