[PATCH v2] riscv: hwprobe: Avoid uninitialized read in hwprobe_get_cpus()

Mark Harris posted 1 patch 1 week, 4 days ago
arch/riscv/kernel/sys_hwprobe.c | 1 +
1 file changed, 1 insertion(+)
[PATCH v2] riscv: hwprobe: Avoid uninitialized read in hwprobe_get_cpus()
Posted by Mark Harris 1 week, 4 days ago
When cpusetsize < cpumask_size(), hwprobe_get_cpus() did not fully
initialize its copy of the cpu mask, which could cause non-deterministic
results from the riscv_hwprobe syscall on a system with more than 8 CPUs
when the supplied cpu mask is empty.  Address this by fully initializing
the cpu mask.

Fixes: e178bf146e4b ("RISC-V: hwprobe: Introduce which-cpus flag")
Signed-off-by: Mark Harris <mark.hsj@gmail.com>
Reviewed-by: Nam Cao <namcao@linutronix.de>
Reviewed-by: Michael Ellerman <mpe@kernel.org>
---
v2: Add Fixes: and Reviewed-by: tags

 arch/riscv/kernel/sys_hwprobe.c | 1 +
 1 file changed, 1 insertion(+)

diff --git a/arch/riscv/kernel/sys_hwprobe.c b/arch/riscv/kernel/sys_hwprobe.c
index 1659d31fd288..caf6762427c8 100644
--- a/arch/riscv/kernel/sys_hwprobe.c
+++ b/arch/riscv/kernel/sys_hwprobe.c
@@ -450,6 +450,7 @@ static int hwprobe_get_cpus(struct riscv_hwprobe __user *pairs,
 	if (cpusetsize > cpumask_size())
 		cpusetsize = cpumask_size();
 
+	cpumask_clear(&cpus);
 	ret = copy_from_user(&cpus, cpus_user, cpusetsize);
 	if (ret)
 		return -EFAULT;
-- 
2.55.0
Re: [PATCH v2] riscv: hwprobe: Avoid uninitialized read in hwprobe_get_cpus()
Posted by Paul Walmsley 1 week, 3 days ago
On Mon, 13 Jul 2026, Mark Harris wrote:

> When cpusetsize < cpumask_size(), hwprobe_get_cpus() did not fully
> initialize its copy of the cpu mask, which could cause non-deterministic
> results from the riscv_hwprobe syscall on a system with more than 8 CPUs
> when the supplied cpu mask is empty.  Address this by fully initializing
> the cpu mask.
> 
> Fixes: e178bf146e4b ("RISC-V: hwprobe: Introduce which-cpus flag")
> Signed-off-by: Mark Harris <mark.hsj@gmail.com>
> Reviewed-by: Nam Cao <namcao@linutronix.de>
> Reviewed-by: Michael Ellerman <mpe@kernel.org>

Thanks, queued for v7.2-rc.


- Paul