diff options
| author | Pengpeng Hou <pengpeng@iscas.ac.cn> | 2026-07-10 15:26:04 -0700 |
|---|---|---|
| committer | Vineet Gupta <vgupta@kernel.org> | 2026-07-10 15:26:04 -0700 |
| commit | 460511c11f0d67e62c6526b191b205eafc8033b2 (patch) | |
| tree | eec3a6fb1e57dec1363cc48789d10949d843f4ef /arch/arc | |
| parent | 8cdeaa50eae8dad34885515f62559ee83e7e8dda (diff) | |
arc: validate DT CPU map strings before parsing them
arc_get_cpu_map() fetches the possible-cpus or present-cpus property
from the flat DT and immediately passes the raw pointer to
cpulist_parse(). That parser expects a NUL-terminated text buffer, but
this path does not prove that the DT property is terminated within its
declared bounds.
Reject unterminated CPU-map properties before handing them to
cpulist_parse().
Changes since v1:
- fold the NUL-termination check into the initial lookup test, as
suggested by Vineet Gupta
Signed-off-by: Pengpeng Hou <pengpeng@iscas.ac.cn>
Signed-off-by: Vineet Gupta <vgupta@kernel.org>
Diffstat (limited to 'arch/arc')
| -rw-r--r-- | arch/arc/kernel/smp.c | 6 |
1 files changed, 4 insertions, 2 deletions
diff --git a/arch/arc/kernel/smp.c b/arch/arc/kernel/smp.c index b2f2c59279a6..2d99dffed0ce 100644 --- a/arch/arc/kernel/smp.c +++ b/arch/arc/kernel/smp.c @@ -22,6 +22,7 @@ #include <linux/irqdomain.h> #include <linux/export.h> #include <linux/of_fdt.h> +#include <linux/string.h> #include <asm/mach_desc.h> #include <asm/setup.h> @@ -43,9 +44,10 @@ static int __init arc_get_cpu_map(const char *name, struct cpumask *cpumask) { unsigned long dt_root = of_get_flat_dt_root(); const char *buf; + int len; - buf = of_get_flat_dt_prop(dt_root, name, NULL); - if (!buf) + buf = of_get_flat_dt_prop(dt_root, name, &len); + if (!buf || !memchr(buf, '\0', len)) return -EINVAL; if (cpulist_parse(buf, cpumask)) |
