From nobody Mon Sep 28 22:29:16 2026 Received: from mail-wr1-f50.google.com (mail-wr1-f50.google.com [209.85.221.50]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 9BCC527442 for ; Sun, 16 Aug 2026 09:00:42 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.221.50 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786870844; cv=none; b=OISMs4KUIgAvZz5nmeedueqw5phfMldakTBx8ei11N2tdha4CgjvuWcKP3HjI77eiMQ4K+Vv2hO8t1eZzSR5dCDaWDuGXLB4waxKXZATdtMgHX6n6E55Od+HxNX6J0bUgshcZjZooVx09RaYsOjAvX8O+9EexZY+0EIvbUpZ7WQ= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786870844; c=relaxed/simple; bh=6T7GMCkGLOuSfaHhVTsEusliObvxag9Q/Qbw1CjZNeg=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=dKE2kJo/gWAkRSZ92N+vTByQl6yurcrUXRuPC4EWGPVg2e4bRJQu4MV/GYrwPI5gAzLGYKnm2DnobJI8ipJV1zt+jeiWAKL4EesmL/C/VKTv5FvG0BMKO/sQi8zsNcdz/4rEbkIFV4WrbOkmzVqZiBB6sAb02+B5SC3ABFSmAnY= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=esCZ2Fxk; arc=none smtp.client-ip=209.85.221.50 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="esCZ2Fxk" Received: by mail-wr1-f50.google.com with SMTP id ffacd0b85a97d-476a130c138so2539097f8f.0 for ; Sun, 16 Aug 2026 02:00:42 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1786870841; x=1787475641; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=TB5hLITgaLSvnkEZ2ABO7VyYwwjhkPuh1sGrI3sQjr4=; b=esCZ2FxkxMAdRy+o8iOCfI4AswWnHWutK5R2q7oAZxQ3ixw4OMsCSVKlaa59n4ogJs lgKdcdDAMOFhPmpwTGAdXH0nhtQIOdAfZzwsypuYL+OuG1CFdGwaUbwnwLURodh5YPN3 UozwjNkb/YVhNeT8YsH8o1S+vHI2+R3fRifNWdccZBAbIqObt9m/sKtLuxvkzAXX6zWM ztLysI23yNgsS7g1Put4ityWpEuvNxfh32joEdJYAAEDC8rilm4IWgwziT7lEd9RKogQ xfESjQKjc9fT00mcaK7OnDmOG0EKFsI5WdL2uysBrpLZGX3n9xZbNFGeVktUZmyP87ND VKcw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786870841; x=1787475641; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=TB5hLITgaLSvnkEZ2ABO7VyYwwjhkPuh1sGrI3sQjr4=; b=OCLv9xcYFsv2bVFxnTCEo2+rmuoDzxe3+WEzEamVf4eFWG73CFx+DqBl6vdT4efbkI 8Q5gJ1uwzFixTY3RbdYVhNj9JukAEd7q8bNoyk9UzlkEfuumE5o73NSZBo+iIrH2Cxwa O0ffI3/p8YBqPm8SY3wqu1H1ymT/hqTBax7b9zWOh6qcewZUyXVD3N4kehXuj31UKCQx 3xc/cDtvDajTBfSKmh4brCbieHaUvt6C7xZt+UebNz0+/D/ENHUgPVOpVhtNxrOHZcRh NncV2yAu8Tka1LSoqcq1xyCg0mqgOOs7lvsNWG0tOHS1t7UGqZCgSSWqbUbGjn2DQPE9 HoEA== X-Forwarded-Encrypted: i=1; AHgh+RqtSSdHxFog05d77DLRQU1sl7wkvMxaJIsdJMC6YSfEuna/KpH974i5wJ4+Dc4U2XLVlBeIlOJdWZqCjXw=@vger.kernel.org X-Gm-Message-State: AOJu0YwGU0KPXgN/Y9j1sIblQ/GgyFWWlb8C/A0YIs280cYvigWuum5b mIRfMu8GcrH+Rw8GrNk3na9CGWf6ZKSQFQGcx+szndsIZdLsn48XP9wut2GdaNGvOrM= X-Gm-Gg: AR+sD13D+13/xj3KhFmk7FVxi7M1+f1D7VxkNDMz9ljQA0dDqbezqmTVuy9uCvchDji H6iBMJGZ2XIA7vvDVSaCzslU8pDHrMdaJ42upyva+AgQf2o9DWuGBw1xXJIzBwqfbXIFWf31eeY e3NRuBN6ygZfngstJai8bKQ1YBC8d+qt5Jj5WLS1fL/+Ov7VKlJndjUq4Yz+v2kkmMTwcflE4ri qSEoD67Gm8mu3AZU98kvheT/nInPGLVPb0o+/uXz5TyTXNlc8i8Dgt9zhSYjppHUGxab98+mva5 Zdo+D8UptDaOWNB+xeiGnuytt3zqv+/Oddrj5JJMB/c9jmti7bBpWDbdSDWxnsdRp7JnNYqc/3C lF69fM3Ba2/ZBG9nIyeeODJnvVSccRZX5SL127RRbO6QuYMAEg92TOgv0XqAhvZUeP2cp+NapYh IyqQnDO7Ik9uTEvwu6LHEYoz821MujVskhW2jeg0gaVPwF64pc9MObROqP X-Received: by 2002:adf:f392:0:b0:46e:1815:6a83 with SMTP id ffacd0b85a97d-4816078c790mr19677263f8f.29.1786870840761; Sun, 16 Aug 2026 02:00:40 -0700 (PDT) Received: from zen ([37.203.152.61]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-4815f2b13c3sm18665907f8f.19.2026.08.16.02.00.38 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 16 Aug 2026 02:00:39 -0700 (PDT) From: Kiarash Azarnia To: rppt@kernel.org, pasha.tatashin@soleen.com, pratyush@kernel.org Cc: graf@amazon.com, kexec@lists.infradead.org, linux-mm@kvack.org, linux-kernel@vger.kernel.org, stable@vger.kernel.org Subject: [PATCH] kho: fix signed shift UB in kho_preserved_memory_reserve() Date: Sun, 16 Aug 2026 12:30:37 +0330 Message-ID: <20260816090038.3117276-1-kiarash.azarnia@gmail.com> X-Mailer: git-send-email 2.53.0 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" kho_preserved_memory_reserve() computes the size of a preserved reservation as: sz =3D 1 << (order + PAGE_SHIFT); `1` is a signed int, so the shift is signed-int arithmetic. For order 19 (a 2 GiB region) it produces 1 << 31, which is unrepresentable in int and is undefined behavior; in practice it yields 0x80000000, sign-extended on the assignment to the u64 sz. For order >=3D 20 the shift count exceeds the width of int, which is also undefined. The return value of memblock_reserve() is ignored and memblock_cap_size() clamps the bogus size, so the kernel silently reserves the wrong amount of memory for the preserved region. kho_alloc_preserve() caps order at MAX_PAGE_ORDER and cannot reach order 19, but a boot-time reserve_mem=3D region of at least 2 GiB drives kho_preserve_pages() to compute order 19, and kho_preserve_pages() is EXPORT_SYMBOL_GPL(), so the path is reachable. Cast the shift operand to u64 so the arithmetic is done in 64 bits: sz =3D (u64)1 << (order + PAGE_SHIFT); Fixes: 3f2ad90060f6 ("kho: adopt radix tree for preserved memory tracking") Cc: stable@vger.kernel.org Signed-off-by: Kiarash Azarnia --- kernel/liveupdate/kexec_handover.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/kernel/liveupdate/kexec_handover.c b/kernel/liveupdate/kexec_h= andover.c index 175c08a6e41e..c79f48bd64ac 100644 --- a/kernel/liveupdate/kexec_handover.c +++ b/kernel/liveupdate/kexec_handover.c @@ -501,7 +501,7 @@ static int __init kho_preserved_memory_reserve(phys_add= r_t phys, struct page *page; u64 sz; =20 - sz =3D 1 << (order + PAGE_SHIFT); + sz =3D (u64)1 << (order + PAGE_SHIFT); page =3D kho_get_preserved_page(phys, order); =20 /* Reserve the memory preserved in KHO in memblock */ --=20 2.53.0