| From 5f5a3e85d2941a050f0f6bc01b06b05e9f376695 Mon Sep 17 00:00:00 2001 |
| From: Sasha Levin <sashal@kernel.org> |
| Date: Wed, 23 Jun 2021 14:01:35 +0200 |
| Subject: x86/fpu: Limit xstate copy size in xstateregs_set() |
| |
| From: Thomas Gleixner <tglx@linutronix.de> |
| |
| [ Upstream commit 07d6688b22e09be465652cf2da0da6bf86154df6 ] |
| |
| If the count argument is larger than the xstate size, this will happily |
| copy beyond the end of xstate. |
| |
| Fixes: 91c3dba7dbc1 ("x86/fpu/xstate: Fix PTRACE frames for XSAVES") |
| Signed-off-by: Thomas Gleixner <tglx@linutronix.de> |
| Signed-off-by: Borislav Petkov <bp@suse.de> |
| Reviewed-by: Andy Lutomirski <luto@kernel.org> |
| Reviewed-by: Borislav Petkov <bp@suse.de> |
| Link: https://lkml.kernel.org/r/20210623121452.120741557@linutronix.de |
| Signed-off-by: Sasha Levin <sashal@kernel.org> |
| --- |
| arch/x86/kernel/fpu/regset.c | 2 +- |
| 1 file changed, 1 insertion(+), 1 deletion(-) |
| |
| diff --git a/arch/x86/kernel/fpu/regset.c b/arch/x86/kernel/fpu/regset.c |
| index c413756ba89f..6bb874441de8 100644 |
| --- a/arch/x86/kernel/fpu/regset.c |
| +++ b/arch/x86/kernel/fpu/regset.c |
| @@ -117,7 +117,7 @@ int xstateregs_set(struct task_struct *target, const struct user_regset *regset, |
| /* |
| * A whole standard-format XSAVE buffer is needed: |
| */ |
| - if ((pos != 0) || (count < fpu_user_xstate_size)) |
| + if (pos != 0 || count != fpu_user_xstate_size) |
| return -EFAULT; |
| |
| xsave = &fpu->state.xsave; |
| -- |
| 2.30.2 |
| |