__gup_test_ioctl() accepts the number of pages per call from userspace. Its
batch end calculation can overflow and wrap around, bypassing the existing
check. This can cause GUP to write beyond the allocated pages array. This
issue was reported by Sashiko.
Also, gup->size is calculated from address difference instead of the actual
pages pinned. This can report partial pages pinned as covering the whole
requested range.
Prevent overflow by clamping each batch before calculating next and
report the actual bytes pinned.
Changes in v3:
- Add a new patch to prevent overflow in GUP batch calculation
Changes in v2:
- Fix a typo in the commit message
Previous versions:
v2: https://lore.kernel.org/all/20260831101304.162867-1-sarthak.sharma@arm.com/
v1: https://lore.kernel.org/all/20260831064808.77768-1-sarthak.sharma@arm.com/
Sarthak Sharma (2):
mm/gup_test: prevent overflow in GUP batch calculation
mm/gup_test: report actual pinned bytes
mm/gup_test.c | 7 ++++---
1 file changed, 4 insertions(+), 3 deletions(-)
--
2.53.0