diff options
| author | Jens Axboe | 2025-04-07 07:51:23 -0600 |
|---|---|---|
| committer | Greg Kroah-Hartman | 2025-04-25 10:45:26 +0200 |
| commit | 35c4a652d8335d6cc3306284ab36f4f2ad031d5f (patch) | |
| tree | fb56dc309b01d511cd24352ac70e4550a95690c9 /io_uring | |
| parent | 21b0c54546d605acb8149b07c67b0e624b4e9e92 (diff) | |
io_uring/kbuf: reject zero sized provided buffers
commit cf960726eb65e8d0bfecbcce6cf95f47b1ffa6cc upstream.
This isn't fixing a real issue, but there's also zero point in going
through group and buffer setup, when the buffers are going to be
rejected once attempted to get used.
Cc: stable@vger.kernel.org
Reported-by: syzbot+58928048fd1416f1457c@syzkaller.appspotmail.com
Signed-off-by: Jens Axboe <axboe@kernel.dk>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Diffstat (limited to 'io_uring')
| -rw-r--r-- | io_uring/kbuf.c | 2 |
1 files changed, 2 insertions, 0 deletions
diff --git a/io_uring/kbuf.c b/io_uring/kbuf.c index 0d9b8a8b42c2..8c6611fe4f46 100644 --- a/io_uring/kbuf.c +++ b/io_uring/kbuf.c @@ -321,6 +321,8 @@ int io_provide_buffers_prep(struct io_kiocb *req, const struct io_uring_sqe *sqe p->nbufs = tmp; p->addr = READ_ONCE(sqe->addr); p->len = READ_ONCE(sqe->len); + if (!p->len) + return -EINVAL; if (check_mul_overflow((unsigned long)p->len, (unsigned long)p->nbufs, &size)) |
