crypto/acompress.c | 16 +++++++++++++--- 1 file changed, 13 insertions(+), 3 deletions(-)
ACOMP_REQUEST_ON_STACK() reserves only enough storage for the
synchronous fallback. When an async implementation is selected, callers
clone that stack request before retrying, but acomp_request_clone()
currently copies only the stack-sized object. The clone therefore has no
storage for the async provider request context, and providers such as QAT
write past the allocation through acomp_request_ctx(). KASAN does report
a slab OOB write.
Allocate a zeroed clone large enough for the runtime acomp request size,
copy only the bytes present in the source object, and preserve the
existing fallback-on-allocation-failure behavior. Use the runtime reqsize
because an implementation may adjust it during tfm initialization.
Assisted-by: Codex:gpt-5
Signed-off-by: Jérémy Jean <Jeremy.Jean@oss.cyber.gouv.fr>
---
crypto/acompress.c | 16 +++++++++++++---
1 file changed, 13 insertions(+), 3 deletions(-)
diff --git a/crypto/acompress.c b/crypto/acompress.c
index 032de704eb2c..4de1a2ad577f 100644
--- a/crypto/acompress.c
+++ b/crypto/acompress.c
@@ -559,12 +559,22 @@ EXPORT_SYMBOL_GPL(acomp_walk_virt);
struct acomp_req *acomp_request_clone(struct acomp_req *req,
size_t total, gfp_t gfp)
{
+ struct crypto_tfm *tfm = req->base.tfm;
struct acomp_req *nreq;
+ size_t len;
- nreq = container_of(crypto_request_clone(&req->base, total, gfp),
- struct acomp_req, base);
- if (nreq == req)
+ len = sizeof(*req) +
+ crypto_acomp_reqsize(crypto_acomp_reqtfm(req));
+ len = ALIGN(len, CRYPTO_MINALIGN);
+
+ nreq = kzalloc(len, gfp);
+ if (!nreq) {
+ req->base.tfm = tfm->fb;
return req;
+ }
+
+ memcpy(nreq, req, sizeof(*req));
+ nreq->base.flags &= ~CRYPTO_TFM_REQ_ON_STACK;
if (req->src == &req->chain.ssg)
nreq->src = &nreq->chain.ssg;
--
2.47.3
On Sat, Aug 15, 2026 at 10:09:18AM +0000, Jérémy Jean wrote: > ACOMP_REQUEST_ON_STACK() reserves only enough storage for the > synchronous fallback. When an async implementation is selected, callers > clone that stack request before retrying, but acomp_request_clone() > currently copies only the stack-sized object. The clone therefore has no > storage for the async provider request context, and providers such as QAT > write past the allocation through acomp_request_ctx(). KASAN does report > a slab OOB write. > > Allocate a zeroed clone large enough for the runtime acomp request size, > copy only the bytes present in the source object, and preserve the > existing fallback-on-allocation-failure behavior. Use the runtime reqsize > because an implementation may adjust it during tfm initialization. > > Assisted-by: Codex:gpt-5 > Signed-off-by: Jérémy Jean <Jeremy.Jean@oss.cyber.gouv.fr> > --- > crypto/acompress.c | 16 +++++++++++++--- > 1 file changed, 13 insertions(+), 3 deletions(-) Patch applied. Thanks. -- Email: Herbert Xu <herbert@gondor.apana.org.au> Home Page: http://gondor.apana.org.au/~herbert/ PGP Key: http://gondor.apana.org.au/~herbert/pubkey.txt
© 2016 - 2026 Red Hat, Inc.