From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-wr1-f50.google.com (mail-wr1-f50.google.com [209.85.221.50]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id BD8FB3A9015 for ; Sun, 8 Mar 2026 20:15:23 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.221.50 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1773000928; cv=none; b=LAN8kNpWlA1fhiHmK8rVCmEmfLOBDgida2yBHVQdzxq90gRc28jBXsOlBLH2kKow/Lf4iNoZ4WTq7E9Em5JN0QVj9P86wruJAQsYbzV1vS8j6eb2b3vAd2scT0FMa4oU8qDvw95Pw7u2sMhJ9WJbegjeCI49WyfpM+TOFGCnz2A= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1773000928; c=relaxed/simple; bh=Gb5bjb2QoBMFPKfaBcTmOt30O6QdxbIHSAJ5mnu3P08=; h=Date:From:To:Cc:Message-ID:In-Reply-To:References:Subject: MIME-Version:Content-Type; b=QDUn7JePkM8zibkPnJlh6oBJmGpDA6M5pz4e8uOubYsqi4gKkYyTYmmyDygdVkly3TScSXJH34EC35M447sQiEDh+vHEHPPqJjYNV6LDjvk41p6/lZYzJIVZjpuvGBdzKKy72w2m0AQqw0d//vDebisnh8kH3mIecjlNNkFX5uQ= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=JMHUl2Sx; arc=none smtp.client-ip=209.85.221.50 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="JMHUl2Sx" Received: by mail-wr1-f50.google.com with SMTP id ffacd0b85a97d-439b78b638eso8038552f8f.2 for ; Sun, 08 Mar 2026 13:15:23 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20230601; t=1773000922; x=1773605722; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:subject:references :in-reply-to:message-id:cc:to:from:date:from:to:cc:subject:date :message-id:reply-to; bh=Gb5bjb2QoBMFPKfaBcTmOt30O6QdxbIHSAJ5mnu3P08=; b=JMHUl2SxjPL5loydXdkFslS17bn7o5AiIGZmacOU3h906FGdm1157O/6ZujKdkICIS qwO+QbPgF8mdNTU3sBfLm8XiHT8KG6lofoG4gf1+z205OaJJBn+HH9gyX2t1W2xdPvf4 N69QerGwow2eFDJ95QKeiKuA5pPeuEBtQX7QCqNz3Z0tXXu/RT2RusxX2l0HPsV/Uqp9 MLTeiMarTunpBDH0zxieZ8b9TRQCfxsBLOWGcAE/JGtquNwbGakW8hhXmkcOYvqmXHIW 35ABf5NgDFCqaIl94b4cjJV55TzQTKRYwZr2rWZ9FMwEJrk9GehJ9LhfHkZK9KgLkpdd Ab1A== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1773000922; x=1773605722; h=content-transfer-encoding:mime-version:subject:references :in-reply-to:message-id:cc:to:from:date:x-gm-gg:x-gm-message-state :from:to:cc:subject:date:message-id:reply-to; bh=Gb5bjb2QoBMFPKfaBcTmOt30O6QdxbIHSAJ5mnu3P08=; b=m1A3m7GFPy+j8rbhwYHkvmg9cOQYw5THSPDIcAMpkzsuapK2SM/MUmUuK5wO/bekqH gkfV1V1ublozI2tEI9HV/N5EvDF8nvIRotyFypCPebDl3UMp687qMcogJTsKoWINFr9z uq9YUQ7zbFGFE6WeLZATGO1PuVIswP1GbQ7xdn2h1qJx8yAWGsDrDs3j7zp8MQHPwOym aDumda0RdwsTBVQbEiWLJAVWFJwIWfcMoGYRwykXvEWr0r6UsZ13t56h9Le4tH6PFVwF 1tiQsqHkMeGoYn2rDInsShNvwgmGZYkotaE0u8riZssmtBBJAmEXkrkrpARxLgZCI1xB KZ/w== X-Gm-Message-State: AOJu0YxjeEZP8MDOjPEhdwpMhHnsQY4dfkigtXGo8sPwBoOJbJ4CFgIy 8U41+B9c5en1r37vNDGAYOJ/L+TdPU5tQNLlEaq4/MqejP+HB3/4KsHiG0QLhzOVHqI87g== X-Gm-Gg: ATEYQzx88EZNlSsbnhgz+I/Ccb2wTLoWf/Wl4FteFtEviAc9rgwWlU5hc/xhLPEwQzv q3nrpAinZpCEcMc/PLPWL0pe5gYrkaU3XInAX2WNL2aWSHgMxj5tks7c4/kjosmc2IEhHslFM3P F5TWpEv++rYI3Ct5jii8yhaPgB9FTel2ogaVdAonbPtEqfC22XiQJq29Uq0mwzc3O63YLAr5Y8A +waz83BKquhU1HByBuIgyJVlbNn4++vWvdgPodPEjbSF9FOylYihZNwtq67QrbxoKaK5zj+zGPa vatUrhzXQUtUT9y0iMb9aRa6IGRoPNPG42eR7b+7uLoQhZY3MWZQfSwGiTKUkU3EvZXaDOreguH LBeGH12WEOOEI8Ly4ahsPeHnjnBqQdYKPSxuQRJBIgnVsCGu5LhNmxCMiXQHedg0w9v4qPOSSGx Nw9L5lW4ljVC2Y2heG X-Received: by 2002:a05:6000:2481:b0:439:b486:ba71 with SMTP id ffacd0b85a97d-439da8a72dbmr17014327f8f.56.1773000921772; Sun, 08 Mar 2026 13:15:21 -0700 (PDT) Received: from [127.0.0.1] ([86.1.69.5]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-439dad8d973sm19542501f8f.3.2026.03.08.13.15.21 (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Sun, 08 Mar 2026 13:15:21 -0700 (PDT) Date: Sun, 8 Mar 2026 20:15:16 +0000 From: Josh Law To: Andrew Morton Cc: linux-kernel@vger.kernel.org, Josh Law Message-ID: In-Reply-To: References: <20260308181054.2884026-1-objecting@objecting.org> <20260308125519.dc842722209726977a8e14cc@linux-foundation.org> Subject: Re: [PATCH v2 1/2] lib/ts_bm: fix integer overflow in pattern length calculation Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: quoted-printable X-Correlation-ID: 8 Mar 2026 20:06:15 Josh Law : > 8 Mar 2026 19:55:20 Andrew Morton : > >> On Sun,=C2=A0 8 Mar 2026 18:10:53 +0000 Josh Law = wrote: >> >>> From: Josh Law >>> >>> The ts_bm algorithm computes the required allocation size by >>> multiplying the pattern length by the size of an integer. If the >>> pattern length is sufficiently large, this can overflow the 32-bit >>> unsigned int before it is widened to size_t. This could result in an >>> undersized allocation and a subsequent heap buffer overflow when >>> copying the pattern. >>> >>> Fix this by explicitly checking that the length does not exceed >>> the maximum safe threshold before calculating the buffer sizes. >>> >>> ... >>> >>> --- a/lib/ts_bm.c >>> +++ b/lib/ts_bm.c >>> @@ -166,6 +166,9 @@ static struct ts_config *bm_init(const void *patter= n, unsigned int len, >>> =C2=A0=C2=A0=C2=A0 unsigned int prefix_tbl_len =3D len * sizeof(unsigne= d int); >>> =C2=A0=C2=A0=C2=A0 size_t priv_size =3D sizeof(*bm) + len + prefix_tbl_= len; >> >> The above description is referring to this expression? >> >> I think the uints will be promoted to size_t before the addition occurs? >> >> If you're referring to the prefix_tbl_len initialization then yes, >> overflow could happen. >> >>> +=C2=A0=C2=A0 if (unlikely(len =3D=3D 0 || len > (UINT_MAX - sizeof(*bm= )) / (sizeof(unsigned int) + 1))) >>> +=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0 return ERR_PTR(-EINVAL); >> >> Seems odd to perform these (uncommented!) checks after having performed >> the problematic operations.=C2=A0 Something like: >> >> =C2=A0=C2=A0=C2=A0 unsigned int prefix_tbl_len; >> =C2=A0=C2=A0=C2=A0 size_t priv_size; >> >> =C2=A0=C2=A0=C2=A0 /* Explanatory comment goes here */ >> =C2=A0=C2=A0=C2=A0 /* Can this actually happen? */ >> =C2=A0=C2=A0=C2=A0 if (unlikely(len =3D=3D 0)) >> =C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0 return ERR_PTR(-EINVAL); >> >> =C2=A0=C2=A0=C2=A0 /* Explanatory comment goes here */ >> =C2=A0=C2=A0=C2=A0 if (unlikely(len > (UINT_MAX - sizeof(*bm)) / (sizeof= (unsigned int) + 1)) >> =C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0 return ERR_PTR(-EINVAL); >> >> =C2=A0=C2=A0=C2=A0 prefix_tbl_len =3D len * sizeof(unsigned int); >> =C2=A0=C2=A0=C2=A0 priv_size =3D sizeof(*bm) + len + prefix_tbl_len; >> >> >> Also, please check the various helpers in overflow.h. > > Yeah, I'm fixing that now, I also submitted a couple other patches you ma= y want to have a look at > > > V/R > > > Josh law Oh and also, sorry for bugging, but I have=C2=A0 a maintainers patch I sent= , and another one you need to look at, V/R Josh law