summaryrefslogtreecommitdiffstats
path: root/lib/dynamic_queue_limits.c
diff options
context:
space:
mode:
authorHui Peng <benquike@gmail.com>2026-09-19 11:00:41 +0000
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>2026-10-01 11:15:46 +0200
commit39495ef5d6f8019e62d65807f217a7ca8232727a (patch)
tree4e18a1d371957dff072c9f415c03dc63bc59d561 /lib/dynamic_queue_limits.c
parent0928ed9bd7946baee911efa401088697836e3b1e (diff)
downloadlinux-stable-39495ef5d6f8019e62d65807f217a7ca8232727a.tar.gz
linux-stable-39495ef5d6f8019e62d65807f217a7ca8232727a.zip
vt: selection: Fix unsigned underflow and slab-out-of-bounds read in paste_selection()
In paste_selection(), the loop copies min_t(unsigned int, vc_sel.buf_len - pasted,tty->receive_room) bytes per iteration into tty_ldisc_receive_buf() and increments pasted += count. Because the selection mutex (vc_sel.lock) is dropped inside the loop Whenever the line discipline buffer fills up and paste_selection() sleeps on tty->write_wait, a concurrent TIOCLINUX (TIOCL_SETSEL) ioctl can replace vc_sel.buffer with a shorter selection and reduce vc_sel.buf_len below pasted. When paste_selection() resumes, vc_sel.buf_len - pasted underflows as an unsigned integer to a large positive value, causing tty_ldisc_receive_buf(ld, vc_sel.buffer + pasted, NULL, count) to read up to 4094 bytes out-of-bounds past the newly allocated vc_sel.buffer. Fix this by terminating the loop when pasted >= vc_sel.buf_len. Kernel stack trace (Linux 7.3.0-rc3): ================================================================== BUG: KASAN: slab-out-of-bounds in n_tty_receive_buf_common+0xa01/0x1650 Read of size 4094 at addr ffff888101c58010 by task kworker/u17:1/65 Workqueue: events_unbound flush_to_ldisc Call Trace: <TASK> dump_stack_lvl+0x70/0xa0 print_report+0x153/0x4c6 kasan_report+0xf1/0x120 kasan_check_range+0x11c/0x200 __asan_memcpy+0x29/0x70 n_tty_receive_buf_common+0xa01/0x1650 tty_ldisc_receive_buf+0x66/0x110 tty_port_default_receive_buf+0x6b/0xb0 flush_to_ldisc+0x1b4/0x410 process_one_work+0x6ff/0x1110 worker_thread+0x4a8/0xb70 kthread+0x307/0x3e0 ret_from_fork+0x3ed/0x680 </TASK> ================================================================== Fixes: e8c75a30a23c ("vt: selection, push sel_lock up") Cc: stable <stable@kernel.org> Assisted-by: LLM Signed-off-by: Hui Peng <benquike@gmail.com> Link: https://patch.msgid.link/20260919110041.3763078-1-benquike@gmail.com Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Diffstat (limited to 'lib/dynamic_queue_limits.c')
0 files changed, 0 insertions, 0 deletions