From nobody Tue Sep 29 02:34:31 2026 Received: from mailgw.kylinos.cn (mailgw.kylinos.cn [124.126.103.232]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 9F9572D0292; Thu, 13 Aug 2026 02:48:22 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=124.126.103.232 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786589306; cv=none; b=XWuOLWNmBvXPgJZi8671rEjr9KyN8Xu8BKPo9BqNF/xUgRDp9q/u6dxoRfZ73uzXcXzmf5Abkg1Jke/lkMPPEcoY95MhhScV2TWhNe0gkvpaqOyxXWLZRYloSKPb+KJJZYw9PY1AZpOv8scVOWhND744pmla7iJqumFNSAB9IG0= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786589306; c=relaxed/simple; bh=F6d+tOUJ99Rld8kBlFOo0jGMvA8ksoK7W0n2Xsz21RA=; h=From:To:Cc:Subject:Date:Message-Id:MIME-Version:Content-Type; b=VQ+2hv3jHikiLFumJlCrtHH75rbtZVHdf7gRVmzV+AdbLWPTed1aLXrZ/zrpd/yKy8PSbdXf8cQdLdWINAk9bHxwu9hTO6VaxAXPe/tNtO5gg/sbxVO+dgV/3WWIbnx7PZuNX5N/fGeXC3qHkizD2sEioBNX2Iwn3FUtbUPyu6A= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=kylinos.cn; spf=pass smtp.mailfrom=kylinos.cn; arc=none smtp.client-ip=124.126.103.232 Authentication-Results: smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=kylinos.cn Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=kylinos.cn X-UUID: 6f0a086a96c111f1aa26b74ffac11d73-20260813 X-CID-P-RULE: Release_Ham X-CID-O-INFO: VERSION:1.3.12,REQID:3ee9cb89-8f7e-4e34-8529-8b33a01c0c99,IP:0,U RL:0,TC:0,Content:-25,EDM:0,RT:0,SF:0,FILE:0,BULK:0,RULE:Release_Ham,ACTIO N:release,TS:-25 X-CID-META: VersionHash:e7bac3a,CLOUDID:fca12f24adbe9056790d6ab9c1a22647,BulkI D:nil,BulkQuantity:0,Recheck:0,SF:102|136|850|865|898,TC:nil,Content:0|15| 50,EDM:-3|-100,IP:nil,URL:99|1,File:nil,RT:nil,Bulk:nil,QS:nil,BEC:nil,COL :0,OSI:0,OSA:0,AV:0,LES:1,SPR:NO,DKR:0,DKP:0,BRR:0,BRE:0,ARC:0 X-CID-BVR: 2,SSN|SDN X-CID-BAS: 2,SSN|SDN,0,_ X-CID-FACTOR: TF_CID_SPAM_ULS,TF_CID_SPAM_SNR X-CID-RHF: D41D8CD98F00B204E9800998ECF8427E X-UUID: 6f0a086a96c111f1aa26b74ffac11d73-20260813 X-User: xiaopei01@kylinos.cn Received: from localhost.localdomain [(10.44.16.150)] by mailgw.kylinos.cn (envelope-from ) (Generic MTA with TLSv1.3 TLS_AES_256_GCM_SHA384 256/256) with ESMTP id 1912808178; Thu, 13 Aug 2026 10:48:16 +0800 From: Pei Xiao To: joern@lazybastard.org, miquel.raynal@bootlin.com, richard@nod.at, vigneshr@ti.com, linux-mtd@lists.infradead.org, linux-kernel@vger.kernel.org Cc: Pei Xiao , syzbot+b320a4d5f65a61dbbf89@syzkaller.appspotmail.com, =?UTF-8?q?J=C3=B6rn=20Engel?= , stable@vger.kernel.org Subject: [PATCH v3] mtd: block2mtd: Fix divide error when erase_size is zero Date: Thu, 13 Aug 2026 10:48:12 +0800 Message-Id: <25ec7ba58facdf29b42ca43dcf11cd98e2089a5f.1786589041.git.xiaopei01@kylinos.cn> X-Mailer: git-send-email 2.25.1 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable The erase size is parsed from the "block2mtd" module parameter and can be set to zero. add_device() then evaluates if (size % erase_size) with a zero divisor, which triggers a divide error: divide error: 0000 [#1] PREEMPT SMP PTI RIP: 0010:add_device drivers/mtd/devices/block2mtd.c:296 [inline] RIP: 0010:block2mtd_setup2+0x592/0xda0 drivers/mtd/devices/block2mtd.c:459 Call Trace: block2mtd_setup+0x27/0xe0 drivers/mtd/devices/block2mtd.c:476 param_attr_store+0x214/0x310 kernel/params.c:589 module_attr_store+0x65/0x90 kernel/params.c:904 kernfs_fop_write_iter+0x3a4/0x540 fs/kernfs/file.c:345 ... Reject a zero erase size before performing the modulo operation so the existing "erasesize must be a divisor of device size" error path reports the invalid argument and frees the device. Fixes: ea6d833a3fdd ("mtd: block2mtd: check device size") Reported-by: syzbot+b320a4d5f65a61dbbf89@syzkaller.appspotmail.com Closes: https://lore.kernel.org/lkml/6a7b58ba.ac361c09.22ff0a.0045.GAE@goog= le.com/ Suggested-by: J=C3=B6rn Engel Cc: stable@vger.kernel.org Signed-off-by: Pei Xiao --- changes in v3: 1.remove (long) cast due to build errors in 32bit config systems 2.changes git log about (long) cast changlogs in v2: 1.Add Suggested-by tag 2.remove unnecessary (long) cast from the size --- drivers/mtd/devices/block2mtd.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/drivers/mtd/devices/block2mtd.c b/drivers/mtd/devices/block2mt= d.c index 03e80b2c4f5a..349fa07be314 100644 --- a/drivers/mtd/devices/block2mtd.c +++ b/drivers/mtd/devices/block2mtd.c @@ -293,7 +293,7 @@ static struct block2mtd_dev *add_device(char *devname, = int erase_size, } =20 size =3D bdev_nr_bytes(bdev); - if ((long)size % erase_size) { + if (!erase_size || (long)size % erase_size) { pr_err("erasesize must be a divisor of device size\n"); goto err_free_block2mtd; } --=20 2.25.1