From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-wm1-f46.google.com (mail-wm1-f46.google.com [209.85.128.46]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id A3F7233B6C4 for ; Sun, 8 Mar 2026 20:06:16 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.128.46 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1773000378; cv=none; b=Sdxh0UnAP/PDJpWChAt5JL1MRXQX2wI4waxoP4MakiTIKLjn2qqNAjhGFv/07/j3mKaHoV2NB5fSra38gGwJJz19EOzCsBToR/X2YuRmnZx0c4GK3CJU45PLSdkUEB4Gkn6pBIEz8xat9TqNDn3ojWOq+TZO907FNVU4bqSAPRA= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1773000378; c=relaxed/simple; bh=VLGA807kQ0+1zZTtjS+ezzJzFlj2ZJSs5cESofm4viM=; h=Date:From:To:Cc:Message-ID:In-Reply-To:References:Subject: MIME-Version:Content-Type; b=gdKFpupLflPBAKu53k/gp8p+GDtWqyCOjKQY+OYOCTpkpjzw4RHXOo7YdVAOKKhtOt+S5EHNosnk9wMV+qq78Bwc0kXkuqM2fQQoGSiLrhB4IKU2+2zDDH2PDoBZBbRWmXqw93MBj0H/FAhIC/Yc8sD9ql1PI8kosliVRlebzgg= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=YKwyTh1y; arc=none smtp.client-ip=209.85.128.46 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="YKwyTh1y" Received: by mail-wm1-f46.google.com with SMTP id 5b1f17b1804b1-48336a6e932so71297875e9.3 for ; Sun, 08 Mar 2026 13:06:16 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20230601; t=1773000375; x=1773605175; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:subject:references :in-reply-to:message-id:cc:to:from:date:from:to:cc:subject:date :message-id:reply-to; bh=VLGA807kQ0+1zZTtjS+ezzJzFlj2ZJSs5cESofm4viM=; b=YKwyTh1y4wMkNvUwV/T6HNalMtnOgoB913kiUMlzirPCqBjwNqVP1kBVxaZzsbh6Ky t7csH2D5NUpkjQI3DIH5vYBsXJVqtaHwkBbdGF4n/PzBGDJfKe8UT7eCUqebqm/TC5pF YGz1zmlqmCPrHWV3JffPpR4Q6GQtA0XQbQIQZanDRqPxHOOnmcyf9gBhMBQJCJ8tojCV wkv8xYZOCwFC0uvop4zINmUk8wlIMSd9BF/i7VnHbd3DXt4C+j4C7HrzM3JMfNXMPd+i +WqGr1HvJJu6XqSMGAQMVWYS8beAJMxqPYfyRTq/2598h6XSPwne82VA1YEto7YtNPSA gmZw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1773000375; x=1773605175; h=content-transfer-encoding:mime-version:subject:references :in-reply-to:message-id:cc:to:from:date:x-gm-gg:x-gm-message-state :from:to:cc:subject:date:message-id:reply-to; bh=VLGA807kQ0+1zZTtjS+ezzJzFlj2ZJSs5cESofm4viM=; b=GaDrgcKh837PXPPwpfpaZxJNMv4Z6YXSbgcQL+jJFhZJRpqSfovUmDeyW105hcl4Iy +gkpbFJLoVroSO+XisqpzkcE9sdKH/c4aa4Sket59ng3SFduaN9fTq9Z25livTT92ekR z8LIYQba4br0bUp3/C6w4bOQvgPAwtRnwhPKZBdhexxxhUfaj5cSEcWXLVmjL7O67iiz npRUwpQqQoJ2JaL6ZLbGdEHydbkwAD33x/eio6aEFeuojTgy8uWKYFHIQGzar5KmInSq wCbq713ee0DjjnmW9nNLlLm4uW0/6jdaVkqPfLcwhesbbyyVDCOYJtC4GQ/DDT4y/FCx XxUQ== X-Gm-Message-State: AOJu0Yy0VBaAYbr4s+LYANkWIvAsLkvqvKS1MLfgNF0FU1NbuqYfAbEY aZqH3BbBKLeO9nRFK7HqprGhsZ2FAbjVaPgFcomPz+gH5WoBR5U5hAJN X-Gm-Gg: ATEYQzxzEgWAWosD0dyi9PWJyddFo3OfCw5AFk0PvmG88XS+HFNZRipQrvSIPEyoolg JM6UsomZCTbe8h0QZ6hdrFOuO1Fpibt0qICuMuSQXe3/xAmtIr0QBO9DIWfjKDrZwXbYZTtzZTU OW8ebHErLwLt19GP+S2w+X9g3C3YQKu8WTfokwxA8dP3mf7E50BqmnI1x2wVFbY4VUSKxqFEbad b/M0Rr3qenV4+6kZizyogfiRNrzB21HjaCUf0j4bCO0DB4+7FH8WQLmfFlRxCo1dbSBT9mb6mgu wyD86DOkwEvsiA9R2B2RzzdxKKRTRmQZk+L+5NU/eM7DMTZOygua7vorfXFJ409gtYiKkJQ+Kc/ KUaQXv0YNlifb1WnQvTMLF04yRB2xR6+D4W0441CDu6Wv99fqEbxRbNncRXV0zgOGKl6TotUe/x LVN6s8KGhH6dcIKNm2 X-Received: by 2002:a05:600c:3d90:b0:482:f564:d613 with SMTP id 5b1f17b1804b1-48526930529mr150176365e9.15.1773000374680; Sun, 08 Mar 2026 13:06:14 -0700 (PDT) Received: from [127.0.0.1] ([86.1.69.5]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-4853a59fc36sm84257855e9.9.2026.03.08.13.06.14 (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Sun, 08 Mar 2026 13:06:14 -0700 (PDT) Date: Sun, 8 Mar 2026 20:06:12 +0000 From: Josh Law To: Andrew Morton Cc: linux-kernel@vger.kernel.org, Josh Law Message-ID: In-Reply-To: <20260308125519.dc842722209726977a8e14cc@linux-foundation.org> References: <20260308181054.2884026-1-objecting@objecting.org> <20260308125519.dc842722209726977a8e14cc@linux-foundation.org> Subject: Re: [PATCH v2 1/2] lib/ts_bm: fix integer overflow in pattern length calculation Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: quoted-printable X-Correlation-ID: 8 Mar 2026 19:55:20 Andrew Morton : > On Sun,=C2=A0 8 Mar 2026 18:10:53 +0000 Josh Law = wrote: > >> From: Josh Law >> >> The ts_bm algorithm computes the required allocation size by >> multiplying the pattern length by the size of an integer. If the >> pattern length is sufficiently large, this can overflow the 32-bit >> unsigned int before it is widened to size_t. This could result in an >> undersized allocation and a subsequent heap buffer overflow when >> copying the pattern. >> >> Fix this by explicitly checking that the length does not exceed >> the maximum safe threshold before calculating the buffer sizes. >> >> ... >> >> --- a/lib/ts_bm.c >> +++ b/lib/ts_bm.c >> @@ -166,6 +166,9 @@ static struct ts_config *bm_init(const void *pattern= , unsigned int len, >> =C2=A0=C2=A0=C2=A0 unsigned int prefix_tbl_len =3D len * sizeof(unsigned= int); >> =C2=A0=C2=A0=C2=A0 size_t priv_size =3D sizeof(*bm) + len + prefix_tbl_l= en; > > The above description is referring to this expression? > > I think the uints will be promoted to size_t before the addition occurs? > > If you're referring to the prefix_tbl_len initialization then yes, > overflow could happen. > >> +=C2=A0=C2=A0 if (unlikely(len =3D=3D 0 || len > (UINT_MAX - sizeof(*bm)= ) / (sizeof(unsigned int) + 1))) >> +=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0 return ERR_PTR(-EINVAL); > > Seems odd to perform these (uncommented!) checks after having performed > the problematic operations.=C2=A0 Something like: > > =C2=A0=C2=A0=C2=A0 unsigned int prefix_tbl_len; > =C2=A0=C2=A0=C2=A0 size_t priv_size; > > =C2=A0=C2=A0=C2=A0 /* Explanatory comment goes here */ > =C2=A0=C2=A0=C2=A0 /* Can this actually happen? */ > =C2=A0=C2=A0=C2=A0 if (unlikely(len =3D=3D 0)) > =C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0 return ERR_PTR(-EINVAL); > > =C2=A0=C2=A0=C2=A0 /* Explanatory comment goes here */ > =C2=A0=C2=A0=C2=A0 if (unlikely(len > (UINT_MAX - sizeof(*bm)) / (sizeof(= unsigned int) + 1)) > =C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0 return ERR_PTR(-EINVAL); > > =C2=A0=C2=A0=C2=A0 prefix_tbl_len =3D len * sizeof(unsigned int); > =C2=A0=C2=A0=C2=A0 priv_size =3D sizeof(*bm) + len + prefix_tbl_len; > > > Also, please check the various helpers in overflow.h. Yeah, I'm fixing that now, I also submitted a couple other patches you may = want to have a look at V/R Josh law