<feed xmlns='http://www.w3.org/2005/Atom'>
<title>kernel/git/stable/linux-stable.git/drivers/tty/vt/selection.c, branch master</title>
<subtitle>Unnamed repository; edit this file 'description' to name the repository.</subtitle>
<id>http://git-test.landau.one/pub/scm/linux/kernel/git/stable/linux-stable.git/atom/drivers/tty/vt/selection.c?h=master</id>
<link rel='self' href='http://git-test.landau.one/pub/scm/linux/kernel/git/stable/linux-stable.git/atom/drivers/tty/vt/selection.c?h=master'/>
<link rel='alternate' type='text/html' href='http://git-test.landau.one/pub/scm/linux/kernel/git/stable/linux-stable.git/'/>
<updated>2026-10-01T09:15:46Z</updated>
<entry>
<title>vt: selection: Fix unsigned underflow and slab-out-of-bounds read in paste_selection()</title>
<updated>2026-10-01T09:15:46Z</updated>
<author>
<name>Hui Peng</name>
<email>benquike@gmail.com</email>
</author>
<published>2026-09-19T11:00:41Z</published>
<link rel='alternate' type='text/html' href='http://git-test.landau.one/pub/scm/linux/kernel/git/stable/linux-stable.git/commit/?id=39495ef5d6f8019e62d65807f217a7ca8232727a'/>
<id>urn:sha1:39495ef5d6f8019e62d65807f217a7ca8232727a</id>
<content type='text'>
In paste_selection(), the loop copies min_t(unsigned int,
vc_sel.buf_len - pasted,tty-&gt;receive_room) bytes per iteration into
tty_ldisc_receive_buf() and increments pasted += count.

Because the selection mutex (vc_sel.lock) is dropped inside the loop
Whenever the line discipline buffer fills up and paste_selection()
sleeps on tty-&gt;write_wait, a concurrent TIOCLINUX (TIOCL_SETSEL) ioctl
can replace vc_sel.buffer with a shorter selection and reduce
vc_sel.buf_len below pasted.

When paste_selection() resumes, vc_sel.buf_len - pasted underflows as an
unsigned integer to a large positive value, causing
tty_ldisc_receive_buf(ld, vc_sel.buffer + pasted, NULL, count) to read
up to 4094 bytes out-of-bounds past the newly allocated vc_sel.buffer.

Fix this by terminating the loop when pasted &gt;= vc_sel.buf_len.

Kernel stack trace (Linux 7.3.0-rc3):
 ==================================================================
 BUG: KASAN: slab-out-of-bounds in n_tty_receive_buf_common+0xa01/0x1650
 Read of size 4094 at addr ffff888101c58010 by task kworker/u17:1/65
 Workqueue: events_unbound flush_to_ldisc
 Call Trace:
  &lt;TASK&gt;
  dump_stack_lvl+0x70/0xa0
  print_report+0x153/0x4c6
  kasan_report+0xf1/0x120
  kasan_check_range+0x11c/0x200
  __asan_memcpy+0x29/0x70
  n_tty_receive_buf_common+0xa01/0x1650
  tty_ldisc_receive_buf+0x66/0x110
  tty_port_default_receive_buf+0x6b/0xb0
  flush_to_ldisc+0x1b4/0x410
  process_one_work+0x6ff/0x1110
  worker_thread+0x4a8/0xb70
  kthread+0x307/0x3e0
  ret_from_fork+0x3ed/0x680
  &lt;/TASK&gt;
 ==================================================================

Fixes: e8c75a30a23c ("vt: selection, push sel_lock up")
Cc: stable &lt;stable@kernel.org&gt;
Assisted-by: LLM
Signed-off-by: Hui Peng &lt;benquike@gmail.com&gt;
Link: https://patch.msgid.link/20260919110041.3763078-1-benquike@gmail.com
Signed-off-by: Greg Kroah-Hartman &lt;gregkh@linuxfoundation.org&gt;
</content>
</entry>
<entry>
<title>tty: serial: mpc52xx_uart: move static declarations up.</title>
<updated>2026-10-01T09:04:53Z</updated>
<author>
<name>Rosen Penev</name>
<email>rosenp@gmail.com</email>
</author>
<published>2026-09-27T20:35:01Z</published>
<link rel='alternate' type='text/html' href='http://git-test.landau.one/pub/scm/linux/kernel/git/stable/linux-stable.git/commit/?id=8167c1f071426706c233e93ecfd13aba7d5c06c8'/>
<id>urn:sha1:8167c1f071426706c233e93ecfd13aba7d5c06c8</id>
<content type='text'>
Avoid a compilation error so that they're not used before being
declared.

Fixes: 4d105880666a ("tty: serial: mpc52xx_uart: add bounds check for psc_num array index")
Reported-by: kernel test robot &lt;lkp@intel.com&gt;
Closes: https://lore.kernel.org/oe-kbuild-all/202609260356.tJWbd1WU-lkp@intel.com/
Signed-off-by: Rosen Penev &lt;rosenp@gmail.com&gt;
Link: https://patch.msgid.link/20260927203501.14105-1-rosenp@gmail.com
Signed-off-by: Greg Kroah-Hartman &lt;gregkh@linuxfoundation.org&gt;
</content>
</entry>
</feed>
