From nobody Sat Apr 18 12:54:50 2026 Received: from mail-yx1-f53.google.com (mail-yx1-f53.google.com [74.125.224.53]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 7601821D3F5 for ; Sat, 28 Feb 2026 00:22:16 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=74.125.224.53 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1772238137; cv=none; b=jhMieHtBjzYNZ3MP3Gc04Jnr5KuDji1orQDhatgVBDfKEZ0/LjvpdR0pWrGdKAVva/dbv+3/ran9Ya+1LKmg7OXjLJLj9yN+Bm8LzRvvNrER0/1qX3SLO6W0rtdHeAWjE6p/CkZauNdqOGMrmu5595TyITpEUoSnqN7zulIM9ms= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1772238137; c=relaxed/simple; bh=gIRJm3ifrZpLiko1TwJL+2iwGqf0M2LzHGs9/VcTBKs=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=qNV4PSBatt0GDABka9yuHJmTlGqhsHHF0eleyEXSuMamJcJZVsPxpwXYoGKlDhQ0QBDnUPrpfopGTizrjkyD4rZoi4vBAa3JeNIJpP9QcPjYCjs6abNYeRuqeKqcHYoMN62hL992dREtJopACYoLuJi18oosVQY/B/+4YRxnU0U= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=fail (p=none dis=none) header.from=sung-woo.kim; spf=pass smtp.mailfrom=gmail.com; arc=none smtp.client-ip=74.125.224.53 Authentication-Results: smtp.subspace.kernel.org; dmarc=fail (p=none dis=none) header.from=sung-woo.kim Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Received: by mail-yx1-f53.google.com with SMTP id 956f58d0204a3-64c9f7576d4so1943642d50.0 for ; Fri, 27 Feb 2026 16:22:16 -0800 (PST) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1772238135; x=1772842935; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to; bh=jxBYsfIl1dQDj7E0Mud0kfpYkTy2bn5OOdrQxDSmBiY=; b=OlOeDawdw4gvauMABBC0VgLNC70wvjqLjbv3U+5kwsLQHQgFjuB68te6b7j2z2jpK2 iF79GCVoc5PMxNXtz3V80zgNQ9aIo2xorG55Eujo53YotVFarzrvTj9g5dodfFWL1FES KeEDB3XOC58qJ4VjVq4eFNFc+vhg0fl3YLbCX2dWrft8WVQ2COccnxVPJ7y6sLuSqShl yrBkXwAyt4TDA7aGvQAB2kcL0V+kQVYOmBHao+pDVIw1pHbj8gxxpcj4EoKvyrokhplL 0Xt7e03Fg290O8iX9mRMc85LUpUhe0wGQpxKlbfDPDU1kb2EqR7t/qtZilVC2gLy++Rf XsDg== X-Forwarded-Encrypted: i=1; AJvYcCUq5qLjW1FNtSNlnRanW6dfILPsgs0JGlTFIy4jVEj9QeBvKWSvQcJf3UxXTkpCF8kOEbnlOg9ILMUmBHE=@vger.kernel.org X-Gm-Message-State: AOJu0Yz1t57OfG9q69ubOzS0GPA5DqykG0SUonO/OQYbHcPF3n9eOMaR 6LpbRcyjhEUKzlcFAHAARq5I3frGPFnsur4A3AxPZRk34ZjJaTVikavZ X-Gm-Gg: ATEYQzwrglYHIwd9sEWdrvznzBrPhXnksC46XrW9TNoNzSQlJFj/cRi6Hd3KyfQ67v1 YzvKe6svGO9K0scY/v7Nyb/MHvtX9D8YvXa07Wv3DRDs3BliW+DSiDa1vgZw531f8xUHa9r6rCe pPImEUH+CXJx+V7DG03BnRfM0KySF4eDD9hDH4FAR6vQU3Fx2G8d0Q40+bIH4KisgmmMl5luA8U YxJBXOfajQ+iA1gR6bb/rCbNZBtc+A+j3L+ITSfX5z7z/BjShPR7l0L4lw0Nvt8UC1pMnFCGuZB s0kPFDNOUXbxhcG2CNsiChqlvkoQvuCHAgs7GrQ3rA9wq4wXRl1Nqu9bAmanAVofHPa3QuKBQvr uY6gr5BcPKMkQRJsKhLOczWmQZN8w2ZzH6oISTklQxYpZToxvkj2ZvmP6oQDMf/78K/86Nv8nRi z9QAJ8x4rbqQ== X-Received: by 2002:a53:c9d2:0:b0:64c:9ee6:1ff5 with SMTP id 956f58d0204a3-64cc22fdd04mr3351893d50.65.1772238135399; Fri, 27 Feb 2026 16:22:15 -0800 (PST) Received: from tofu.. ([128.210.0.165]) by smtp.googlemail.com with ESMTPSA id 956f58d0204a3-64cb75ae57esm2872687d50.9.2026.02.27.16.22.14 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 27 Feb 2026 16:22:14 -0800 (PST) From: Sungwoo Kim To: Keith Busch , Jens Axboe , Christoph Hellwig , Sagi Grimberg , Chaitanya Kulkarni , Mike Christie , "Martin K. Petersen" , Hannes Reinecke Cc: Sungwoo Kim , Chao Shi , Weidong Zhu , Dave Tian , linux-nvme@lists.infradead.org, linux-kernel@vger.kernel.org Subject: [PATCH v2] nvme: fix memory allocation in nvme_pr_read_keys() Date: Fri, 27 Feb 2026 19:19:28 -0500 Message-ID: <20260228001927.382810-3-iam@sung-woo.kim> X-Mailer: git-send-email 2.47.3 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" nvme_pr_read_keys() takes num_keys from userspace and uses it to calculate the allocation size for rse via struct_size(). The upper limit is PR_KEYS_MAX (64K). A malicious or buggy userspace can pass a large num_keys value that results in a 4MB allocation attempt at most, causing a warning in the page allocator when the order exceeds MAX_PAGE_ORDER. To fix this, use kvzalloc() instead of kzalloc(). This bug has the same reasoning and fix with the patch below: https://lore.kernel.org/linux-block/20251212013510.3576091-1-kartikey406@gm= ail.com/ Warning log: WARNING: mm/page_alloc.c:5216 at __alloc_frozen_pages_noprof+0x5aa/0x2300 m= m/page_alloc.c:5216, CPU#1: syz-executor117/272 Modules linked in: CPU: 1 UID: 0 PID: 272 Comm: syz-executor117 Not tainted 6.19.0 #1 PREEMPT(= voluntary) Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.3-0-ga= 6ed6b701f0a-prebuilt.qemu.org 04/01/2014 RIP: 0010:__alloc_frozen_pages_noprof+0x5aa/0x2300 mm/page_alloc.c:5216 Code: ff 83 bd a8 fe ff ff 0a 0f 86 69 fb ff ff 0f b6 1d f9 f9 c4 04 80 fb = 01 0f 87 3b 76 30 ff 83 e3 01 75 09 c6 05 e4 f9 c4 04 01 <0f> 0b 48 c7 85 7= 0 fe ff ff 00 00 00 00 e9 8f fd ff ff 31 c0 e9 0d RSP: 0018:ffffc90000fcf450 EFLAGS: 00010246 RAX: 0000000000000000 RBX: 0000000000000000 RCX: 1ffff920001f9ea0 RDX: 0000000000000000 RSI: 000000000000000b RDI: 0000000000040dc0 RBP: ffffc90000fcf648 R08: ffff88800b6c3380 R09: 0000000000000001 R10: ffffc90000fcf840 R11: ffff88807ffad280 R12: 0000000000000000 R13: 0000000000040dc0 R14: 0000000000000001 R15: ffffc90000fcf620 FS: 0000555565db33c0(0000) GS:ffff8880be26c000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 000000002000000c CR3: 0000000003b72000 CR4: 00000000000006f0 Call Trace: alloc_pages_mpol+0x236/0x4d0 mm/mempolicy.c:2486 alloc_frozen_pages_noprof+0x149/0x180 mm/mempolicy.c:2557 ___kmalloc_large_node+0x10c/0x140 mm/slub.c:5598 __kmalloc_large_node_noprof+0x25/0xc0 mm/slub.c:5629 __do_kmalloc_node mm/slub.c:5645 [inline] __kmalloc_noprof+0x483/0x6f0 mm/slub.c:5669 kmalloc_noprof include/linux/slab.h:961 [inline] kzalloc_noprof include/linux/slab.h:1094 [inline] nvme_pr_read_keys+0x8f/0x4c0 drivers/nvme/host/pr.c:245 blkdev_pr_read_keys block/ioctl.c:456 [inline] blkdev_common_ioctl+0x1b71/0x29b0 block/ioctl.c:730 blkdev_ioctl+0x299/0x700 block/ioctl.c:786 vfs_ioctl fs/ioctl.c:51 [inline] __do_sys_ioctl fs/ioctl.c:597 [inline] __se_sys_ioctl fs/ioctl.c:583 [inline] __x64_sys_ioctl+0x1bf/0x220 fs/ioctl.c:583 x64_sys_call+0x1280/0x21b0 mnt/fuzznvme_1/fuzznvme/linux-build/v6.19/./arc= h/x86/include/generated/asm/syscalls_64.h:17 do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline] do_syscall_64+0x71/0x330 arch/x86/entry/syscall_64.c:94 entry_SYSCALL_64_after_hwframe+0x76/0x7e RIP: 0033:0x7fb893d3108d Code: 28 c3 e8 46 1e 00 00 66 0f 1f 44 00 00 f3 0f 1e fa 48 89 f8 48 89 f7 = 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff f= f 73 01 c3 48 c7 c1 b8 ff ff ff f7 d8 64 89 01 48 RSP: 002b:00007ffff61f2f38 EFLAGS: 00000246 ORIG_RAX: 0000000000000010 RAX: ffffffffffffffda RBX: 00007ffff61f3138 RCX: 00007fb893d3108d RDX: 0000000020000040 RSI: 00000000c01070ce RDI: 0000000000000003 RBP: 0000000000000001 R08: 0000000000000000 R09: 00007ffff61f3138 R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000001 R13: 00007ffff61f3128 R14: 00007fb893dae530 R15: 0000000000000001 Fixes: 5fd96a4e15de (nvme: Add pr_ops read_keys support) Acked-by: Chao Shi Acked-by: Weidong Zhu Acked-by: Dave Tian Signed-off-by: Sungwoo Kim Reviewed-by: Christoph Hellwig Reviewed-by: Hannes Reinecke --- v2: add missing kvfree drivers/nvme/host/pr.c | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/drivers/nvme/host/pr.c b/drivers/nvme/host/pr.c index ad2ecc2f49a97..fe7dbe2648158 100644 --- a/drivers/nvme/host/pr.c +++ b/drivers/nvme/host/pr.c @@ -242,7 +242,7 @@ static int nvme_pr_read_keys(struct block_device *bdev, if (rse_len > U32_MAX) return -EINVAL; =20 - rse =3D kzalloc(rse_len, GFP_KERNEL); + rse =3D kvzalloc(rse_len, GFP_KERNEL); if (!rse) return -ENOMEM; =20 @@ -267,7 +267,7 @@ static int nvme_pr_read_keys(struct block_device *bdev, } =20 free_rse: - kfree(rse); + kvfree(rse); return ret; } =20 --=20 2.47.3