From nobody Fri Sep 25 19:19:17 2026 Received: from mail-pl1-f178.google.com (mail-pl1-f178.google.com [209.85.214.178]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id CF45B52D2C8 for ; Wed, 9 Sep 2026 10:49:09 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.214.178 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788950951; cv=none; b=X34aHeMfocmEBWvR4tLtgl7B5nHg8x11tBRpRtpPZQ8NLYmS1snJpKC0vfSB3d5znPAnNrzCjdA+ZNm+6WWeshjzQ+3iQCjzdmDj84fyub8ljGFQNC4Qo5rSc2CXufBLwFhwP5LS6RTFh4vi03TGyxlfwiSjGBNCPURvH3Q76MY= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788950951; c=relaxed/simple; bh=EqVQzSbQ8FxQSn7HL+wfusLM5qWOzg38zdmSWfOhHUA=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=tWFhnT8N37I3PecsXTGP9pd0K4Iaxz8ohTpfFRAN1P+h1fqHIOl2+UoVYrYV9OVY49qx8hac6JyAaE8MnjXGXT6mpnfkoa3v5LmPmBq1VhPfty3q4pcebh57tYuZg/1xk2iGjMdoSW+acSsXqE2luu1/1mCTSvQBjkR4FQlXCeA= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=Ml/UEum8; arc=none smtp.client-ip=209.85.214.178 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="Ml/UEum8" Received: by mail-pl1-f178.google.com with SMTP id d9443c01a7336-2d944747d41so62253225ad.0 for ; Wed, 09 Sep 2026 03:49:09 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1788950949; x=1789555749; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=6H9r9Y1iiMNm6s2u3z5FmxhhAAJmyha2D2o8ORi1TPw=; b=Ml/UEum8R4ZKXjkdby6fhTbE+sMmeCfFWIaNITnU1zG9lRW3hGVawkvNLgk4StC89i wTxXroAocW7J4f//U3XZtN0i3um9HzKp2g0GQVas1ibQfftjCihliPckttmcV6ddEeiG QOQZLVuAyLifXyK2264AWk2ZX+jF7Z6jbq59QYa0jkLfKdgqe96N8PQ75Uock2s6l7Wy fSs2QTpt8DooACv7/O0zbC0KWur4yIDNrEyJ7meh5UbCdt68MHe9VfXsnKm9sZAEVcXO wksv92EBwBvbrDplLGDKNJTzwh2X0YbaoO5NjJJqku5C/S+Qrbl2F1jbnj/6j3u3S1pn cdGQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788950949; x=1789555749; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=6H9r9Y1iiMNm6s2u3z5FmxhhAAJmyha2D2o8ORi1TPw=; b=V1xNgrc6ZZplPw3VIt/BoMpq/Xwzydo9gGj79GPJzlZobTcf+dFlVNieXr3rkVvtEI c433zhmM6lsJZ4rjA8YsDUotGdhykdswUwAyHaurk7E4titWrD27mZTdJLHVnfD/eOL2 +ArovKmFz5L9VhE4dYezU/0cBM3n0mRwLYaHYfry3als+frl/F1ep99g6rOepKA+C8VE Pf1LClCMKn29GzyP18nG3tARWNEnvLAu2ChcpPkyEh8jcYLsa63Eq5fREg42QDeMQRSg d6G+hxrWUZYRmp7jitYlZvryv0oKObietSaULoCvn2tJBwyxYOfcBPh0R9e6Hm9G4A1N FTsg== X-Forwarded-Encrypted: i=1; AKwUvBxRZyw+xlYn/Qn7NwU2pxyZ2zypaDcOInGIn9NNF5jQxdw6a+c7TSNl679PB6e1WG1XKq5SCB6/JDJcV6c=@vger.kernel.org X-Gm-Message-State: AFuF++mhEIZ2iBi17qUH5j2kpk383bzDtpz+EKFel9d9wwd4XOKr9RrV ZmS/KRb+J5eUyaVowBKAQOr1fQmXed0tD5eD2jnZsyCjr0nx/VC9mOOB X-Gm-Gg: AYBFou2MLZ96PClZxh2lrtr24OF449U4558Vq9ZLVwvko5qZ1X7N+uAaXIRm83dlvHf UjW70v1nzaSKRpVmKFt9KTTD2ZryDXQphy0iCmMglJV5CX+ooxNWc4+/ma0hLcs/h6Spb+vksgY GL9a+lhzCgGxr8y1a/47gUSK7DM0deAy+XT+UQsTVlO4j6nWtPZM0SOfGJAfpQsXfl84sJOm3r7 GaI6QV0AsfD3xUGIlX4Ttm7DwvdkcjrS23myuhCXUD1ayOteQK5GfQG6S+PYA50gjC51h2j/1fT HFc5OVU5pdD4laCk/YLP0+5Nu70PwqJNsIsrtM62rb3rpxAlN0uGuo39E0lho9b7q/ui1CwYYk9 MD+ruks4AiaeFT7gYpEHXi9n/LtYB7ESfqhcF+CA3Uu60nnwYO+DvB8j/A989hdx0qgZVgqCHSY /wlQk0DK5nq67hDxVCxKlmTimUG4V/jNOKwKkRhFQPHTxAHs0Mu2NF1z0pdR6Bt6ChOzpVzfIif 3JO+iBiiGymLkI+LGC0FiUT X-Received: by 2002:a17:90b:3fd0:b0:398:d6e6:4671 with SMTP id 98e67ed59e1d1-39b262981a2mr49484550a91.25.1788950948959; Wed, 09 Sep 2026 03:49:08 -0700 (PDT) Received: from LAPTOP-450UDG4J ([223.185.135.143]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-3396e7e477csm12026723eec.29.2026.09.09.03.49.05 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 09 Sep 2026 03:49:08 -0700 (PDT) From: Yogesh Gaur To: Ian Abbott , H Hartley Sweeten Cc: Greg Kroah-Hartman , linux-kernel@vger.kernel.org, Yogesh Gaur , syzbot+690d666eb12fca6e1e61@syzkaller.appspotmail.com Subject: [PATCH 1/6] comedi: comedi_parport: validate the IRQ supplied by userspace Date: Wed, 9 Sep 2026 16:18:42 +0530 Message-ID: <20260909104848.1763-2-yogeshgaur.83@gmail.com> X-Mailer: git-send-email 2.55.0.windows.5 In-Reply-To: <20260909104848.1763-1-yogeshgaur.83@gmail.com> References: <20260909104848.1763-1-yogeshgaur.83@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" comedi boards are configured through the COMEDI_DEVCONFIG ioctl, so it->options[1] is a number chosen by userspace. comedi_parport passes it to request_irq() without checking it first, which lets an interrupt owned by another irqdomain -- a PCI device's IO-APIC GSI, for instance -- be claimed for this board. When the owner of that interrupt is later released the descriptor is freed while this driver's handler is still installed on it. A parallel port asserts a legacy ISA interrupt, so the ISA range is the right bound; it is also sufficient, because mp_chip_data->isa_irq is set only by alloc_isa_irq_from_domain() and mp_unmap_irq() returns early when it is set. syzbot hit this one: remove_proc_entry: removing non-empty directory 'irq/20', leaking at least= 'comedi_parport' WARNING: fs/proc/generic.c:747 at remove_proc_entry+0x4e7/0x610 fs/proc/ge= neric.c:747 Call Trace: unregister_irq_proc+0x206/0x2a0 kernel/irq/proc.c:406 free_desc+0x89/0x330 kernel/irq/irqdesc.c:482 irq_free_descs+0x84/0xc0 kernel/irq/irqdesc.c:865 irq_domain_free_irqs+0x46a/0x5c0 kernel/irq/irqdomain.c:1917 mp_unmap_irq+0xf8/0x130 arch/x86/kernel/apic/io_apic.c:1061 acpi_unregister_gsi_ioapic+0x40/0x60 arch/x86/kernel/acpi/boot.c:722 acpi_pci_irq_disable+0x275/0x360 drivers/acpi/pci_irq.c:517 pci_disable_device+0x130/0x270 drivers/pci/pci.c:2206 pci_device_remove+0xb2/0x1d0 drivers/pci/pci-driver.c:512 device_release_driver_internal+0x44e/0x620 drivers/base/dd.c:1372 unbind_store+0xf8/0x110 drivers/base/bus.c:244 The leaked /proc entry the warning names is the mild part. mp_chip_data->count tracks GSI mappings rather than request_irq() users, and __setup_irq() takes no reference on the descriptor, so the irq_desc is freed with the comedi irqaction still attached to it. Bound the value before requesting it, as das16m1.c already does. An out-of-range value is ignored rather than rejected, so the board still attaches without interrupt support, exactly as it does today when request_irq() fails. Fixes: 241ab6ad7108 ("Staging: comedi: add comedi_parport driver") Reported-by: syzbot+690d666eb12fca6e1e61@syzkaller.appspotmail.com Closes: https://syzkaller.appspot.com/bug?extid=3D690d666eb12fca6e1e61 Assisted-by: LLM Signed-off-by: Yogesh Gaur --- drivers/comedi/drivers/comedi_parport.c | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/drivers/comedi/drivers/comedi_parport.c b/drivers/comedi/drive= rs/comedi_parport.c index 57ee3f9dfba2..94284ff157ac 100644 --- a/drivers/comedi/drivers/comedi_parport.c +++ b/drivers/comedi/drivers/comedi_parport.c @@ -243,7 +243,8 @@ static int parport_attach(struct comedi_device *dev, outb(0, dev->iobase + PARPORT_DATA_REG); outb(0, dev->iobase + PARPORT_CTRL_REG); =20 - if (it->options[1]) { + /* only ISA interrupts are valid on a parallel port */ + if (it->options[1] >=3D 1 && it->options[1] <=3D 15) { ret =3D request_irq(it->options[1], parport_interrupt, 0, dev->board_name, dev); if (ret =3D=3D 0) --=20 2.55.0.windows.5 From nobody Fri Sep 25 19:19:17 2026 Received: from mail-pf1-f180.google.com (mail-pf1-f180.google.com [209.85.210.180]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 5FB1C52FE5A for ; Wed, 9 Sep 2026 10:49:13 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.210.180 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788950954; cv=none; b=LzuvMjxNNbPS7tilbOwmO/zV6Fwnk9ifXJvZ1B222nri/6J2cBNqxqgm8pLgr3JkiGE3hcpQ8fhUdb0XobmhqJm0ICwM5vajAhJqsMbeHYUfNi/ZKCJeUVUT4wp3+0bzy2rnz5G/8s1xtSmRabVuE2EwP5zuMF2/3xKehak+FlY= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788950954; c=relaxed/simple; bh=lKLLoJOB3QCdcp8M6zQjLq9DEXilfjW0g7Vx6AzYsYY=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=h/WCk1k21dL4YwM0K4EBgqXDm0AQUEpqrxfskEaTxrc4ndJcKhilKlLwtq3b8p39VoLl8j7XZY5AFwvu34PQN19ed5/Q0idhGZsVJDuc6IqCPC0qkXNobADL/d3/nbdYLb8PMUztYssoFVuG3LeQpf4/aLTKIF1FCF+KUXpyO5k= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=EgAUY16i; arc=none smtp.client-ip=209.85.210.180 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="EgAUY16i" Received: by mail-pf1-f180.google.com with SMTP id d2e1a72fcca58-853c07a76adso5478067b3a.0 for ; Wed, 09 Sep 2026 03:49:13 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1788950952; x=1789555752; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=AuhItF3DHuGBcrjd2vsxrXT95gQ2Gc/hDHGyg4+Yc5w=; b=EgAUY16iU7PHU+H6Yl0y9baFLpDk5HukogpI2jP/2y+Nm41JoYZhhwDF1NGWpvRCsL o+30hKjRsUjNwY/IgJylBvaNyHixLLKzuHQZIZPiLhImp6VxIopJ3Oa4TlDn8qyQaOqW UUU3LH3VypW7he/vZ0okbNF+9litV7X1QV6qUZFfJ0WZ4kOzeSx0N/pK5hNIp7/QQkCT PDppsJnPdOSjcM/L6C7LhEiM6sAw7DCNEk+D2HWcD+APl4tyYBQ+//gKMmxjQcDXrPzx YTrzcYvLdBx8OfsTuyYSX8kbfAwBGxkiJLUKv3HfUML3K3kJE656srPtqNjpFRZ/E6TL 6V2A== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788950952; x=1789555752; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=AuhItF3DHuGBcrjd2vsxrXT95gQ2Gc/hDHGyg4+Yc5w=; b=G1Ib99KCjnop1emHK8eC/mp0JLLN3/2azQLTl9+XJiOtN54aWUE//qnz6ntAumq42c +YXMSSNa9V1pUi/2ba1WkrOjx9pkgcvVMuZHb7IPrd0GuDj+nxDcguNGiAEu+x4DJO1o OxKN7eFneJV4f50ZKNEEPwJMVCfKKWfysILEr5w9MWr6C79g1Q87PDLCnHen+PFNvL85 pn0wGkPL1I5w5UwNbvbb9Jv2RsaGaKR/whhHCQZ6eOZs5dcwYmejqnh3JYCrATT0yVfV AEufDU7zvLinVCeY0cLAKdlu4yZKb86Kj+i23APXlogEW3ibbWv7uAnFXnRSgVl49pmn dv8Q== X-Forwarded-Encrypted: i=1; AKwUvBzYun0eeB8FpJOZYSq+L8EBCFvC+Lp/OCH39lyIvWpRBXBRLmwHLIkNRHPKb23dY/4TaW2ZBSztxRrif88=@vger.kernel.org X-Gm-Message-State: AFuF++mQFQB5Xx9T0fTGCRVtyBz+MhSnRbdrb+p95D5hpLsEz6bJzext 55XO7Ba5g5rgJ6ZsGhZRT/Op9O8ZXT9IgFW2+nOviS3Y/JLzhrCnmIzr X-Gm-Gg: AYBFou2yKeNfcCcl5BNT2LmSZ6c9Zfaw5zpaMTimTNLsaqU2TtGIyuN8ZXwEzUdz+ut WJJadrcHNJpzbcUnmgn+MrW5XTTkh9E6Y8yrqJxc9ZdUNmdY9lStIAOwZN0Y0oaxryOQOrK5v9s M0AbPvdeHTDP/sqH+Qb52gF/gvhaD9UD6my9/jnP3i4zex8mG05j1+1Nh+gWJQAlK28d0k0Xfkz 1wXeGaP9Ri2hX/DCz8kK7/W9DDi/mqTJnOy9Ts4NVRAEuO92H1b+VNrUpTX8plybwmITMzS1NGV +3d/7zuULFg7rijQP5jDr/np0fx9j7XxS7gFyLolOtvwBCsVl7YRyLkRsDQXYsL8vdzApWAsqy2 sdkbDCSznse273RYkhLh6wjt4E53DDrvOa3xQ9ohScaNVQ1ieusSniFVZWSmCE9WGfQp6SdJW3v SANOP8MVOD9GondrX/eBbBWDvzM+3DJa7OWj+Vr81EnavMYUZndWMTe/bPRSpY7vK8IwKtzL3NQ 9Un7PUFWCBn/fyUJXUiPnS8 X-Received: by 2002:a05:6a20:9d93:b0:3d3:ae40:51e8 with SMTP id adf61e73a8af0-3da3a104d63mr51608904637.28.1788950952391; Wed, 09 Sep 2026 03:49:12 -0700 (PDT) Received: from LAPTOP-450UDG4J ([223.185.135.143]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-3396e7e477csm12026723eec.29.2026.09.09.03.49.09 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 09 Sep 2026 03:49:11 -0700 (PDT) From: Yogesh Gaur To: Ian Abbott , H Hartley Sweeten Cc: Greg Kroah-Hartman , linux-kernel@vger.kernel.org, Yogesh Gaur Subject: [PATCH 2/6] comedi: ni_atmio16d: validate the IRQ supplied by userspace Date: Wed, 9 Sep 2026 16:18:43 +0530 Message-ID: <20260909104848.1763-3-yogeshgaur.83@gmail.com> X-Mailer: git-send-email 2.55.0.windows.5 In-Reply-To: <20260909104848.1763-1-yogeshgaur.83@gmail.com> References: <20260909104848.1763-1-yogeshgaur.83@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" comedi boards are configured through the COMEDI_DEVCONFIG ioctl, so it->options[1] is a number chosen by userspace. ni_atmio16d passes it to request_irq() without checking it first, which lets an interrupt owned by another irqdomain -- a PCI device's IO-APIC GSI, for instance -- be claimed for this board. When the owner of that interrupt is later released the descriptor is freed while this driver's handler is still installed on it. The driver already documents which interrupts the board can assert -- "0 =3D=3D no irq; or 3,4,5,6,7,9,10,11,12,14,15" -- so use exactly that set rather than the whole ISA range. Bound the value before requesting it, as das16m1.c already does. An out-of-range value is ignored rather than rejected, so the board still attaches without interrupt support, exactly as it does today when request_irq() fails. Fixes: 2323b276308a ("Staging: comedi: add ni_at_atmio16d driver") Assisted-by: LLM Signed-off-by: Yogesh Gaur Reported-by: syzbot+690d666eb12fca6e1e61@syzkaller.appspotmail.com --- drivers/comedi/drivers/ni_atmio16d.c | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/drivers/comedi/drivers/ni_atmio16d.c b/drivers/comedi/drivers/= ni_atmio16d.c index 6765cdc276ca..87fed16b112c 100644 --- a/drivers/comedi/drivers/ni_atmio16d.c +++ b/drivers/comedi/drivers/ni_atmio16d.c @@ -593,7 +593,9 @@ static int atmio16d_attach(struct comedi_device *dev, /* reset the atmio16d hardware */ reset_atmio16d(dev); =20 - if (it->options[1]) { + /* only irqs 3, 4, 5, 6, 7, 9, 10, 11, 12, 14, and 15 are valid */ + if (it->options[1] >=3D 3 && it->options[1] <=3D 15 && + (1 << it->options[1]) & 0xdef8) { ret =3D request_irq(it->options[1], atmio16d_interrupt, 0, dev->board_name, dev); if (ret =3D=3D 0) --=20 2.55.0.windows.5 From nobody Fri Sep 25 19:19:17 2026 Received: from mail-pj1-f54.google.com (mail-pj1-f54.google.com [209.85.216.54]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 5E9E552ED45 for ; Wed, 9 Sep 2026 10:49:16 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.216.54 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788950958; cv=none; b=HO6MmgxwGTAWOHLCM1oRdLaR5avZhC3f2kGyD3TgRFUZOcoEHU72IK5eUkU8wXsrtaI5Em4RSlH12VVUNJtDfHQrLO6L8xomSACA8zzlD+JhioUegwY+JYDnLkNQSIZoPGqIkOjLZnYJbqPwhnCKhNfSADrmwTmUqf2G7IdtPpM= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788950958; c=relaxed/simple; bh=SYw2gi1AC5nhm0xVe0022TZZZ0W6MNIpykFOc8BW2kU=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=iQhLOoaJbrPfcQE30of8H+KtFzxHbhuPj3B8C3HgzbsoO9jTZUSO4rSGZ8+ygDFbtDTkOmzS4CnOxETvrCGkIy+KnmJId6ITz7tc8SIcC7Q6XBgbz2B9bxtQGxtdDkK80CAbayfOqJkBiq/q+59PovLG447rvM0w9yjKwNxNtm4= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=qKownFEi; arc=none smtp.client-ip=209.85.216.54 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="qKownFEi" Received: by mail-pj1-f54.google.com with SMTP id 98e67ed59e1d1-39682983a0fso6257875a91.3 for ; Wed, 09 Sep 2026 03:49:16 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1788950955; x=1789555755; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=PxKqn4CGn3MwPhUs31ivMcK4nmJ/9HPbLbrdPHhsR0U=; b=qKownFEiAfwIJMAOeD9aPS+01IEksv0zdvL2xC1yYoewEgeOc66MjYbJCEIp9LLypi WupJBKUkPOsZCY/8u4WfKZt6LnzmNMKBEXbjYEZstddj46MZ74rmFuikOjNBRgEm6gIu nENnP7gL5HsRIh4tJv5hgDBh883M9CH5yY2olGGWtucxtX9cmRN3QoajD46eurKR6bKe 2S8m+ie0G066NNbaCTGXsFPtIqD+1PIoj9Q1cl1nNCsg5Whdd4gZWkuDUv0cvMT0X39k Id9hZHFGqko/HqEa/nsOgf0TegNEQmNbkEdOEZZ6DA7gp7wfwItmG2syjcQ8cQC/jZgb lc3A== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788950955; x=1789555755; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=PxKqn4CGn3MwPhUs31ivMcK4nmJ/9HPbLbrdPHhsR0U=; b=iaMuAmlxo8OIQbaoWXBhKbWlTuCRqnFvANtl5kFjRWVAruo8hzxwcASJQm3+787fmn 3dQ9rCPN9UxH8KdXUMpPXL1UUDCV1camKOQLNuHCVoqQoK+PyhExPqIxVL6hESF1UtLW 2VvkhXqdOp/lHDKNDZvKoHcKCtNAXX42hdlsPDtKAE8Is22kPwYg+TbuBo3bYl+inhcx i2j5Ci/CMFuSZibBPnWHQ+fztbIoloE5ipCuBj/753B5SMr4aqGE22eVgKtcJc7JcP/X C5RN0PQpjD5NE/tSlMy1iNqIVu+ynv7UCU+wDIMLXQcofDJYumeGTCJoj1MEiPwLYpHf RTaA== X-Forwarded-Encrypted: i=1; AKwUvBxEs0BabPAfJ1sKyNR5GoVw7qU0UCRv9BUR41YGIpGXotU7jKwrDBDOdg1uSpfvgUMEvtWZtHfW6jvPnHI=@vger.kernel.org X-Gm-Message-State: AFuF++nGkCd5lLBDYm62Yr4WS0HruVa2yNfmR94lDQzvEAqr57EcdTln z07sOXAV2odsxZBZMFSRxqL+At1JklFtniVLbz+hm//y7jqDq8JBGICc X-Gm-Gg: AYBFou0DjkSGuQA+gJ9HwFXilbZEya5AnOxjlj53dF9lGpnF7jUIkKEsZdviayco3Al AnykwSGuXKEGqqYdOxadn+NnEV7psAleqpxyl1UjOOfRQXpge8ODdT3hJmlp60NejZjYEBhR9qJ 5zXIJ1KwjV7VZJ6IsgIU8r+q1lEQJpWxvVbSqfkCV5UVRBmNKnc+3Knya3xfhF8a+mcGx3dOgqu 8fRCDJeWEuSj40rwE9Hds5RWb2AukC7C5Z/PWcOfdRGpTXDKhUx+GkwEfmgzK7uS72Sisii2XWK pGP35RkK282AtoG8WjCeVbnzfJi/bv26d6ZBpwYx7yXFG2SYATq6MZPDR/961opjyj0UQ7w1Dih DSWafKksBjKHTjukI2XJyZLabB09x5i3Ez0AUT2/LLhQRxX92i1TtgFe6QFU73HWyc3fHWg1rLD afc/B1lY2FMMyi2bbOegHDY1hxROkUiHE0JVpOYOn7aEQBK8dCecivQQKwBUJN/nIQYJ//YUQZk 8/fEuECNJuCZbur3IX3rQLV X-Received: by 2002:a17:90b:5844:b0:38f:5869:387b with SMTP id 98e67ed59e1d1-39b26101c20mr51690204a91.9.1788950955356; Wed, 09 Sep 2026 03:49:15 -0700 (PDT) Received: from LAPTOP-450UDG4J ([223.185.135.143]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-3396e7e477csm12026723eec.29.2026.09.09.03.49.12 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 09 Sep 2026 03:49:15 -0700 (PDT) From: Yogesh Gaur To: Ian Abbott , H Hartley Sweeten Cc: Greg Kroah-Hartman , linux-kernel@vger.kernel.org, Yogesh Gaur Subject: [PATCH 3/6] comedi: dt2814: validate the IRQ supplied by userspace Date: Wed, 9 Sep 2026 16:18:44 +0530 Message-ID: <20260909104848.1763-4-yogeshgaur.83@gmail.com> X-Mailer: git-send-email 2.55.0.windows.5 In-Reply-To: <20260909104848.1763-1-yogeshgaur.83@gmail.com> References: <20260909104848.1763-1-yogeshgaur.83@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" comedi boards are configured through the COMEDI_DEVCONFIG ioctl, so it->options[1] is a number chosen by userspace. dt2814 passes it to request_irq() without checking it first, which lets an interrupt owned by another irqdomain -- a PCI device's IO-APIC GSI, for instance -- be claimed for this board. When the owner of that interrupt is later released the descriptor is freed while this driver's handler is still installed on it. Every interrupt this board can assert is a legacy ISA one, so the ISA range is the right bound; it is also sufficient, because mp_chip_data->isa_irq is set only by alloc_isa_irq_from_domain() and mp_unmap_irq() returns early when it is set. Bound the value before requesting it, as das16m1.c already does. An out-of-range value is ignored rather than rejected, so the board still attaches without interrupt support, exactly as it does today when request_irq() fails. Fixes: a211ea977a41 ("Staging: comedi: add dt2814 driver") Assisted-by: LLM Signed-off-by: Yogesh Gaur Reported-by: syzbot+690d666eb12fca6e1e61@syzkaller.appspotmail.com --- drivers/comedi/drivers/dt2814.c | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/drivers/comedi/drivers/dt2814.c b/drivers/comedi/drivers/dt281= 4.c index caec16482afb..63b7f17691ff 100644 --- a/drivers/comedi/drivers/dt2814.c +++ b/drivers/comedi/drivers/dt2814.c @@ -316,7 +316,8 @@ static int dt2814_attach(struct comedi_device *dev, str= uct comedi_devconfig *it) return -EIO; } =20 - if (it->options[1]) { + /* only ISA interrupts are valid on this board */ + if (it->options[1] >=3D 1 && it->options[1] <=3D 15) { ret =3D request_irq(it->options[1], dt2814_interrupt, 0, dev->board_name, dev); if (ret =3D=3D 0) --=20 2.55.0.windows.5 From nobody Fri Sep 25 19:19:17 2026 Received: from mail-pj1-f44.google.com (mail-pj1-f44.google.com [209.85.216.44]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 76FDB530E17 for ; Wed, 9 Sep 2026 10:49:19 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.216.44 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788950961; cv=none; b=Fe2vNxesbCj5yAU4gml/weNokGXGI3FSLgiPDszovD6I59k/TS8N2iSGK9PhKM/V8Qy68vJC2Zh1Y2tpGZR4aZd/3lrhXcjULmcGdrDLnEA+SsZzAqDW7BQInuiNsM+Vex896AzhvLwKItdwS1sYyziTOw28einVp2CrK+JiZ2c= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788950961; c=relaxed/simple; bh=HhUiwpApPp1PvQ5DB2B/c6qqcPMEq2cFKx+kv1MDJtk=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=VG+3YtGH2nWcNPE1sqMLmMduhB18si6sTvaRu/ulDpVreeAsKOB7+3b0t+byS5UAjO3GHnZI36QtJH+3c+HDKgAAWq2WLnMbAGGZvostXxShFJ86BHjV8slKJIpthOWsJuDYFcEOf1Jx4Mv6gkcOseKAH4YCzgZBy/gg0UdFr/g= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=gjR1Mlc5; arc=none smtp.client-ip=209.85.216.44 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="gjR1Mlc5" Received: by mail-pj1-f44.google.com with SMTP id 98e67ed59e1d1-381b831d535so8913394a91.0 for ; Wed, 09 Sep 2026 03:49:19 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1788950958; x=1789555758; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=NYYSg4n/Nh940SSb9t8+EI1dJmqGSAca/D+rn4rXdBU=; b=gjR1Mlc5dde6yCZ3V8Nkyl80zz4slF9VIpMOdtsSwx6qE1BDHGuyjkNDkI/wiAlBLe DtgK+PsConGvkl1dGjkSrHcmrjz4lLHgo/22cvvdx69H6hbf+LiS/IVF0JmyDzDqSpYn nXIovB+QUCTqNbX1pSo3LA+YNiC0yyVv3JJHvfzWpdYKSXbXi+RpgGAU2/TmbhCbzC68 LSRnKgXXTX0dgBpwoDwX0mtA0gNGxx/h7POhqXEufQEFO09fr3yVgVZUmcPKluQzO4fK 8g7wrpJXM2tSJW8RXEb/Lu+KQUHHz2EjYuEmyE7tr/e8ZCMkR5IZIg7KkxFPoG2esSxH SSLQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788950958; x=1789555758; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=NYYSg4n/Nh940SSb9t8+EI1dJmqGSAca/D+rn4rXdBU=; b=CYn5AnL8SZ0H7+ta8ybt37s8cWdl4SRbdHhYj2ltVVBI/tpRed38anNmDzflTgH+Bo 4txQsKyzATPODvJFH7PVoCY5zNIUWJbVaV/ZKH7mG4uffcasYjT4Wt8aVKbwzGXr+W5v jaew/PcOlLcSQQmf9dr8pOZQjL0PgwdqLmK0vPwvnbFkv2JYxAOkmdZlVNt3fGcmqylt S6nnqtrVULNGw5DnRbR3Pr8tLdC0cRrxlVcolTS39bsZIDFfz7eIwDqVfUxw6sFDqZwr 1mLfYAlHrCCe9Sg9KKy8X0ID+jO8fdKpCnkUtpVgNIhQ2s7MnOL3yPMF6U02PW02vN3a X0NQ== X-Forwarded-Encrypted: i=1; AKwUvByXOjyCXtgrVMIyTyX8uZ4BGGZf8ejcYy0urHJXU4XijJOLVg/lbDLNkQWhKPNgFgPGnyX57Zvww4dykxw=@vger.kernel.org X-Gm-Message-State: AFuF++m3GkWCMdAq60xFhkl6aPqCdNlLSoj1MjWGueAbjBG9tpf7NvNX WVHWRhmC6SzdeEBqquRNzgP5cdbt9c7ZH1XmdMncR20crMkHjxRJqyee X-Gm-Gg: AYBFou1WPItVPbzURD7pkrtW/HeT13eNwu2YV09G7uGTxtlvo68//w7ooQ+UH61lhwF DI3zQ6ogScOF0hBaS/JBFKOVFfN6uZrtgkGBS8Lx/Zk7y77gsuKHABnF1dDGXdhe4wf14t/rHFk QbWUcP+joMq3WjL/XqKywtxe0+blJzK1wtmv+Fe1hrNZ1BJttOG5dYAApuipTHNe9YgU7rQ/msX RP9TuxTBmpQhOOC9w/+NNMZdXBQBKsmAHGluvCACQFqpMM2xfrtNBBixKIRqNRL+CiFp/3jucGG ChQ/2gn5Z5mJawMsOjP/nblruAwuWnryQ3lKUDIzfR7Da1mYn/o4K04H74DpKxi45gJWXMLRBhM zp7LKinnG6hL6TemtS1a7/rdlgsobSmhnM792FRVTyS6Uv1kX+M2VUsE+fGXQa95RDG43YyZwrU wsxFEKXcHrTjeLQ1mvlYdIlM6z80YA9NzvtJuE61/KIbcdv8nZjGKbmKyE8A9VVQtwlh71SF2s6 JyOs3j54v1RrhEHtLRfqT3Yoadv1TGOQ38= X-Received: by 2002:a17:90b:5344:b0:38e:4f41:83df with SMTP id 98e67ed59e1d1-39b261e0f14mr51530680a91.15.1788950958316; Wed, 09 Sep 2026 03:49:18 -0700 (PDT) Received: from LAPTOP-450UDG4J ([223.185.135.143]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-3396e7e477csm12026723eec.29.2026.09.09.03.49.15 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 09 Sep 2026 03:49:17 -0700 (PDT) From: Yogesh Gaur To: Ian Abbott , H Hartley Sweeten Cc: Greg Kroah-Hartman , linux-kernel@vger.kernel.org, Yogesh Gaur Subject: [PATCH 4/6] comedi: dmm32at: validate the IRQ supplied by userspace Date: Wed, 9 Sep 2026 16:18:45 +0530 Message-ID: <20260909104848.1763-5-yogeshgaur.83@gmail.com> X-Mailer: git-send-email 2.55.0.windows.5 In-Reply-To: <20260909104848.1763-1-yogeshgaur.83@gmail.com> References: <20260909104848.1763-1-yogeshgaur.83@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" comedi boards are configured through the COMEDI_DEVCONFIG ioctl, so it->options[1] is a number chosen by userspace. dmm32at passes it to request_irq() without checking it first, which lets an interrupt owned by another irqdomain -- a PCI device's IO-APIC GSI, for instance -- be claimed for this board. When the owner of that interrupt is later released the descriptor is freed while this driver's handler is still installed on it. Every interrupt this board can assert is a legacy ISA one, so the ISA range is the right bound; it is also sufficient, because mp_chip_data->isa_irq is set only by alloc_isa_irq_from_domain() and mp_unmap_irq() returns early when it is set. Bound the value before requesting it, as das16m1.c already does. An out-of-range value is ignored rather than rejected, so the board still attaches without interrupt support, exactly as it does today when request_irq() fails. Fixes: 3c501880ac44 ("Staging: comedi: add dmm32at driver") Assisted-by: LLM Signed-off-by: Yogesh Gaur Reported-by: syzbot+690d666eb12fca6e1e61@syzkaller.appspotmail.com --- drivers/comedi/drivers/dmm32at.c | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/drivers/comedi/drivers/dmm32at.c b/drivers/comedi/drivers/dmm3= 2at.c index d1d9f75e168f..c6a6ba2899e6 100644 --- a/drivers/comedi/drivers/dmm32at.c +++ b/drivers/comedi/drivers/dmm32at.c @@ -600,7 +600,8 @@ static int dmm32at_attach(struct comedi_device *dev, return ret; } =20 - if (it->options[1]) { + /* only ISA interrupts are valid on this board */ + if (it->options[1] >=3D 1 && it->options[1] <=3D 15) { ret =3D request_irq(it->options[1], dmm32at_isr, 0, dev->board_name, dev); if (ret =3D=3D 0) --=20 2.55.0.windows.5 From nobody Fri Sep 25 19:19:17 2026 Received: from mail-pf1-f173.google.com (mail-pf1-f173.google.com [209.85.210.173]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 37C82533593 for ; Wed, 9 Sep 2026 10:49:22 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.210.173 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788950964; cv=none; b=rGTXEfDbFLK6wFWgcQehBtVefKNwPuqljSeCk2io5GH/VarRqPO8cM+8GVE3OaPTqvrPa7tjUL7tC8Xt+Hqui1CKsBBcLRBxO6a6irPxRoLaSxZnl3A9vtg+SCy5XmX1YH9I07LkV85UJWVjdKoFi8aXTMNemDV2/xYI6shpQ1g= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788950964; c=relaxed/simple; bh=CpjLaJJjD8vhLCsAVTtlUMrtov9by2/IVfsnz7WVKuE=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=ETUgfH+QUX1imDT8/ZuBS+zF/ElUkosMW9BhWDcDjMEteZIYdSuvPmFcT57CCkBV1shobg2v8ME3hztUi/1pN9sEw6U1xycG9vbP0LD1JQyfoiQvE3ra4oePjjWFqLQGQtSx9NH0GA4AA0T6TNxYKYapxyXNlqQPZfWmtJM1Ikk= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=USI14LO8; arc=none smtp.client-ip=209.85.210.173 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="USI14LO8" Received: by mail-pf1-f173.google.com with SMTP id d2e1a72fcca58-8520161fdb9so5713672b3a.3 for ; Wed, 09 Sep 2026 03:49:22 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1788950961; x=1789555761; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=c7NhZSXmEgRftQ8I2EcEI/sFWG4uZBvif+OlTpOSwU0=; b=USI14LO85HYD4h4yKdGROOAtgOYz7uMwD1GY+gwSPRTEV7RF3o5SaJKis2jYf6EUr1 DsdMQaYH2Kz+ZN7PZFbFrFP2TjI56Hvq6/X8yf8qmzJjZ9YhCuaFo49ke/QzSfUPCuok bxGgFJn7x+00W9yWhN3rMMIrAvCux/W4PAvL35v2mkVzFak2G96ub5QG3YhPQNU/N195 CaWfx+jLlPZ2k0as/N+Nr83eXgIGECpS9vHpHdFMZWnLaEk1r9tNoJVosM0+eph5//ZT wYiBMXlsBSJL+RszS+jGHL7Y2jYhijF3oUQ+nriRSKxZLw37dOgCVnr2We0pM5UmwyA4 r4sw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788950961; x=1789555761; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=c7NhZSXmEgRftQ8I2EcEI/sFWG4uZBvif+OlTpOSwU0=; b=XEu6ArchJBpgjHPrgNiaqQbtYD8PnsMdfZcyrVa8+xeBdQSaBrTEZzrfFczjRs+Vre sheIW4ulK969TlKynRvxspFSgBxIDBZ9yWofjNXSPgUIehNI1rVYB+74DH3eTjHjeITx WC0utYBO2BHa2ZA2kccMtXX8Y6EEsZxv/09mQGJwOkZ9ECM+mYQLT7WEGpPx2+3TPuwW QZ3Z/SVAwnQkGwilhfJgroigHIFwSo0UeX4g7OzpLRq0xOkVp21f+V9kjBgmW6liFQHl orw0LCvbXXyoaqc7QhKkazh1od174gUFJdOgKdbD8kMXZcJ7PfwXFTYs8mtH/HCFYF9E aLJA== X-Forwarded-Encrypted: i=1; AKwUvByA5vaETDTF1xbMpvDwQCYfAW6xXL/74oe1k04mJPw+2Rt2DeX/ZtH1QKCOaZCT2+qmSFp39kktROjlXnA=@vger.kernel.org X-Gm-Message-State: AFuF++k3ooF8ECp992vjUMAVbkZUGW1+xs3mWl8SX8JQe5CQn5FIgcWN wyn75o6+cp0lffqbDApVF7XBQF00KUW8zyeYPVclqrPIKk3h3BtEusx0 X-Gm-Gg: AYBFou3G6djnboTDRV2SWEZmNMd2/Sm+Le+BEgVQsKAiREbAbxYODSmsYozQ12olOj5 NvGqtO1EJTxPB19g7BjI2boSfjqN78DZQ4FgJ1pht1NWoTCZa50+Lbmd3jqtnUSW2UvZDWDrW2A xnG9DlaeZTDFrLPBIpMtAP9AXT7rcHW5XY+2qw/XlfPqIdNXTvxqoDI8G1FfmbJ5ktLm6NYrRkH UQcBA732+9rhZhMp8fztLgXBhepf7dx02fRu8oW8yXWpeZlM0rd2IULmiWg8P6dATBxlJL9Dgpk Km8UgQJwOEG11UrrCNFFbWdgUMSboQApMiaRvJTh9z/OIW6oT2E3vDMu7bctDXo4eN1mmPBtWwY /WFQRPqqSJKMPVd/EiZewpNc6DXGq1tPuVizn+Vxxq1kdq+fh8CZCHSdWzJAth+n14086dbJjqb ni5rnbLTjxgt0OOIQuiN1zm4TtaML+17UHGeVXsFjnPTmsb9vWkGwBxp/rDWwewzVxGUbNOD6JB 4qUd7acSJ8MqOsKx4KSLdRi X-Received: by 2002:a05:6a21:3943:b0:3c4:1493:6822 with SMTP id adf61e73a8af0-3da3a0aa8cbmr57062584637.18.1788950961428; Wed, 09 Sep 2026 03:49:21 -0700 (PDT) Received: from LAPTOP-450UDG4J ([223.185.135.143]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-3396e7e477csm12026723eec.29.2026.09.09.03.49.18 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 09 Sep 2026 03:49:21 -0700 (PDT) From: Yogesh Gaur To: Ian Abbott , H Hartley Sweeten Cc: Greg Kroah-Hartman , linux-kernel@vger.kernel.org, Yogesh Gaur Subject: [PATCH 5/6] comedi: pcmmio: validate the IRQ supplied by userspace Date: Wed, 9 Sep 2026 16:18:46 +0530 Message-ID: <20260909104848.1763-6-yogeshgaur.83@gmail.com> X-Mailer: git-send-email 2.55.0.windows.5 In-Reply-To: <20260909104848.1763-1-yogeshgaur.83@gmail.com> References: <20260909104848.1763-1-yogeshgaur.83@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" comedi boards are configured through the COMEDI_DEVCONFIG ioctl, so it->options[1] is a number chosen by userspace. pcmmio passes it to request_irq() without checking it first, which lets an interrupt owned by another irqdomain -- a PCI device's IO-APIC GSI, for instance -- be claimed for this board. When the owner of that interrupt is later released the descriptor is freed while this driver's handler is still installed on it. The board's interrupt is routed in software rather than jumpered, and the driver notes that "any IRQ from 1-15 is OK", so the ISA range is exactly the right bound. Bound the value before requesting it, as das16m1.c already does. An out-of-range value is ignored rather than rejected, so the board still attaches without interrupt support, exactly as it does today when request_irq() fails. Fixes: 6baef150380d ("Staging: comedi: add pcmmio and pcmuio drivers") Assisted-by: LLM Signed-off-by: Yogesh Gaur Reported-by: syzbot+690d666eb12fca6e1e61@syzkaller.appspotmail.com --- drivers/comedi/drivers/pcmmio.c | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/drivers/comedi/drivers/pcmmio.c b/drivers/comedi/drivers/pcmmi= o.c index f42b7343b4e4..afe2bda91659 100644 --- a/drivers/comedi/drivers/pcmmio.c +++ b/drivers/comedi/drivers/pcmmio.c @@ -684,7 +684,8 @@ static int pcmmio_attach(struct comedi_device *dev, str= uct comedi_devconfig *it) =20 pcmmio_reset(dev); =20 - if (it->options[1]) { + /* the irq is configured in software, so any ISA irq is OK */ + if (it->options[1] >=3D 1 && it->options[1] <=3D 15) { ret =3D request_irq(it->options[1], interrupt_pcmmio, 0, dev->board_name, dev); if (ret =3D=3D 0) { --=20 2.55.0.windows.5 From nobody Fri Sep 25 19:19:17 2026 Received: from mail-pg1-f178.google.com (mail-pg1-f178.google.com [209.85.215.178]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id A4B935328C3 for ; Wed, 9 Sep 2026 10:49:25 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.215.178 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788950967; cv=none; b=ovmTdD+Z0m4SYiOLlafHPEvww08g4DxyRM59h0xmJ3EyCbS/5XI5UjLNJ1vInzq1sutrDICMe06VKdwtcwTjXaAFRKpeVLqtak9zHrNwUCq0DYzbHYMz68k0aPuQz+s7K62Eo1clzixdc14xTlXI151PW2vtOHqBVCKXBVcgz7Q= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788950967; c=relaxed/simple; bh=mGTbmang64JjYEa8MhL2eBgNDeYF7cnKrLMsVDldpqU=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=XV4USuhJlzNp0CecSQH2n9LdI/1FyqztjncVk+DDEh4cArCPEoRYJtbFSV8Nf3gjLvdtdvFTqAP4Ev5iLDBhOf74ri8CL2RC6Cqdi8FTlbzONLVEdJeAuzIvlAeSlKpNFqvmkqdxJBsBQ0//pVq52faiIxtv4vLet4Ub/jmXDlk= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=LIJqZ6IA; arc=none smtp.client-ip=209.85.215.178 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="LIJqZ6IA" Received: by mail-pg1-f178.google.com with SMTP id 41be03b00d2f7-cc48fe04342so2279646a12.0 for ; Wed, 09 Sep 2026 03:49:25 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1788950965; x=1789555765; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=wVde/0UXjeqgx2G6fnsoxLCBIhaGKDP8LoxgsoCSsBk=; b=LIJqZ6IAhPp9LipLxlPw6AhxQwbuubYcM4is3LdXMK5p+Eg86S2GwkF4BJCTKOwxNC 9ZnLVspTQ/nIjzjRHW+sbke8/OzD7UYlxDR7+vRLVtvdXOJqyozcUhDaOJzOMfwe0one 9xpjjyuLYmcElQcXJ3Ku+LMTp88pYcGn8xTpKcNpPtGXJi2TcbFbOtySX9hQhy9RHQA/ r9W4M+Bvs2XloNeWDqqeWnLRtm6wxYoMSN0xIpqQyZ24yc/HuE32IZQwmfFsaYX7n905 fRWtwfRGGD+GueSmhPQHJPvdF4MkqVP1h+ysexQkdH9HWlQsZM6fpBKsyW2SWi+Qnlut Gt/g== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788950965; x=1789555765; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=wVde/0UXjeqgx2G6fnsoxLCBIhaGKDP8LoxgsoCSsBk=; b=o4qEtCtt42be8XGDtGI9eMiNS+Sc/viwq9l47QLLgXD66tTqXCt/QRNJNIGVIRwrkw iNiYPNIkprKcIaCrpl5W1XMuBHZgOSR7gfPmTO2JK6FkwjRF6SiqV1hpI+ZUFBJ4S4yr 3Hi90swO1KjgdeDbngQKniDi7TKwMX59pIlWyPFClDe126PMV8FbluZ1qQ8oKkp48qOR LU+OfXCzNXm9riHlpj19T0RQgPkHfb6Zeu9ur9J3dGUs7XuiqM3itgwj7UUs2zDIdXbY QLCa1XLG0po1BFR1ji+DVhnDioZ4kj/fSdlK3Ylmw91PrVRvqEfMToT1ajczdddG7XJz /JFg== X-Forwarded-Encrypted: i=1; AKwUvBw6AGNxRJe470llW9OEJfNjMemluzLajFF+YWMaIldMbDqdzTF84ORHULDoBm3uxy6QNn0PNrdxobH7qw8=@vger.kernel.org X-Gm-Message-State: AFuF++mFGVoNJ69zua64Y4OcOVhBoWT451HcLJI2vfiuCmg8zDD6m+Tu Guvo+wF9yqn1aiZXiMjJc2pYorxtFxO9UFzSmD23dTxS4jjw1o4hFwEu X-Gm-Gg: AYBFou3OBMn4QOrbvZJNRJna2TDjM5WdKH0BCXRQpQMW3tTTQZLLyfAYX56QxUt+UkV 6cgAJcWJRtXt0+WrtcfLShZ7r4C0XIC9Gzz5JFic2sx17K9DcntJNt/l27zoL476kF52UM3Xlrt icNa0SiMaPxamTHRe+8kEX9zFJSVbh/FVwEebmOvDqFDX3dr/s5PW/Le8449X+jD4sODhDGd8+4 KHd2OLoCnCd3+xH5YZx6Lg4ij6YC+7NpG4n7OzWkyt9ztFDRz6SYsFu8CVYxtXhrjf3osbzWevO eL1hQs/yTb/w/2sn6EMp2WZ/coVU8yngyxYeM+abvuMIzgMpJSSFqtLl3cbXB2yB0kyGemOTanX 7uHYmQni+DD9SGXytZuT5kiHZI98oPsfJhChUq4oh3TP9glbhNQMMANQzp78WqWCYWiKiA38hVc tfO3cXKPrA7cfDpxtGO6D/4wEMClLeA6A4O2gRRFavx/PRMccBS/kblCky4dQEmK62yCLIp0Tf+ JIo+O61oZEQlnbdnIRx2Ofq X-Received: by 2002:a05:6a21:114c:b0:3d1:e510:9052 with SMTP id adf61e73a8af0-3da39ee2689mr53748910637.7.1788950964701; Wed, 09 Sep 2026 03:49:24 -0700 (PDT) Received: from LAPTOP-450UDG4J ([223.185.135.143]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-3396e7e477csm12026723eec.29.2026.09.09.03.49.21 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 09 Sep 2026 03:49:24 -0700 (PDT) From: Yogesh Gaur To: Ian Abbott , H Hartley Sweeten Cc: Greg Kroah-Hartman , linux-kernel@vger.kernel.org, Yogesh Gaur Subject: [PATCH 6/6] comedi: pcmuio: validate the IRQs supplied by userspace Date: Wed, 9 Sep 2026 16:18:47 +0530 Message-ID: <20260909104848.1763-7-yogeshgaur.83@gmail.com> X-Mailer: git-send-email 2.55.0.windows.5 In-Reply-To: <20260909104848.1763-1-yogeshgaur.83@gmail.com> References: <20260909104848.1763-1-yogeshgaur.83@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" comedi boards are configured through the COMEDI_DEVCONFIG ioctl, so it->options[1] is a number chosen by userspace. pcmuio passes it to request_irq() without checking it first, which lets an interrupt owned by another irqdomain -- a PCI device's IO-APIC GSI, for instance -- be claimed for this board. When the owner of that interrupt is later released the descriptor is freed while this driver's handler is still installed on it. Every interrupt this board can assert is a legacy ISA one, so the ISA range is the right bound; it is also sufficient, because mp_chip_data->isa_irq is set only by alloc_isa_irq_from_domain() and mp_unmap_irq() returns early when it is set. Bound the value before requesting it, as das16m1.c already does. An out-of-range value is ignored rather than rejected, so the board still attaches without interrupt support, exactly as it does today when request_irq() fails. This board takes two interrupts, one per ASIC, so options[1] and options[2] both need the check. The existing options[2] =3D=3D dev->irq case is left alone: it covers both ASICs sharing one interrupt and neither having one, and by then options[1] has already been validated. Fixes: 6baef150380d ("Staging: comedi: add pcmmio and pcmuio drivers") Assisted-by: LLM Signed-off-by: Yogesh Gaur Reported-by: syzbot+690d666eb12fca6e1e61@syzkaller.appspotmail.com --- drivers/comedi/drivers/pcmuio.c | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) diff --git a/drivers/comedi/drivers/pcmuio.c b/drivers/comedi/drivers/pcmui= o.c index d9995cbeecb6..da80bca0bb55 100644 --- a/drivers/comedi/drivers/pcmuio.c +++ b/drivers/comedi/drivers/pcmuio.c @@ -546,7 +546,8 @@ static int pcmuio_attach(struct comedi_device *dev, str= uct comedi_devconfig *it) =20 pcmuio_reset(dev); =20 - if (it->options[1]) { + /* only ISA interrupts are valid on this board */ + if (it->options[1] >=3D 1 && it->options[1] <=3D 15) { /* request the irq for the 1st asic */ ret =3D request_irq(it->options[1], pcmuio_interrupt, 0, dev->board_name, dev); @@ -558,7 +559,7 @@ static int pcmuio_attach(struct comedi_device *dev, str= uct comedi_devconfig *it) if (it->options[2] =3D=3D dev->irq) { /* the same irq (or none) is used by both asics */ devpriv->irq2 =3D it->options[2]; - } else if (it->options[2]) { + } else if (it->options[2] >=3D 1 && it->options[2] <=3D 15) { /* request the irq for the 2nd asic */ ret =3D request_irq(it->options[2], pcmuio_interrupt, 0, dev->board_name, dev); --=20 2.55.0.windows.5