diff options
| author | Jens Axboe | 2026-01-21 11:48:56 -0700 |
|---|---|---|
| committer | Sasha Levin | 2026-03-04 07:19:24 -0500 |
| commit | f130001251fbded9c47504923072f5f6a5c2f022 (patch) | |
| tree | c868f9faa8a047fc543354b1c02fbc80b508ecfa /io_uring | |
| parent | 7d99cbe717c1b15a66559215df32312d8cf7e525 (diff) | |
io_uring/sync: validate passed in offset
[ Upstream commit 649dd18f559891bdafc5532d737c7dfb56060a6d ]
Check if the passed in offset is negative once cast to sync->off. This
ensures that -EINVAL is returned for that case, like it would be for
sync_file_range(2).
Fixes: c992fe2925d7 ("io_uring: add fsync support")
Signed-off-by: Jens Axboe <axboe@kernel.dk>
Signed-off-by: Sasha Levin <sashal@kernel.org>
Diffstat (limited to 'io_uring')
| -rw-r--r-- | io_uring/sync.c | 2 |
1 files changed, 2 insertions, 0 deletions
diff --git a/io_uring/sync.c b/io_uring/sync.c index 64e87ea2b8fb..59f951a4b524 100644 --- a/io_uring/sync.c +++ b/io_uring/sync.c @@ -61,6 +61,8 @@ int io_fsync_prep(struct io_kiocb *req, const struct io_uring_sqe *sqe) return -EINVAL; sync->off = READ_ONCE(sqe->off); + if (sync->off < 0) + return -EINVAL; sync->len = READ_ONCE(sqe->len); return 0; } |
