Skip to content

Commit f7ad318

Browse files
YongjiXiemstsirkin
authored andcommitted
vhost: Fix the calculation in vhost_overflow()
This fixes the incorrect calculation for integer overflow when the last address of iova range is 0xffffffff. Fixes: ec33d03 ("vhost: detect 32 bit integer wrap around") Reported-by: Jason Wang <[email protected]> Signed-off-by: Xie Yongji <[email protected]> Acked-by: Jason Wang <[email protected]> Link: https://lore.kernel.org/r/[email protected] Signed-off-by: Michael S. Tsirkin <[email protected]>
1 parent 0e39829 commit f7ad318

File tree

1 file changed

+8
-2
lines changed

1 file changed

+8
-2
lines changed

drivers/vhost/vhost.c

Lines changed: 8 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -735,10 +735,16 @@ static bool log_access_ok(void __user *log_base, u64 addr, unsigned long sz)
735735
(sz + VHOST_PAGE_SIZE * 8 - 1) / VHOST_PAGE_SIZE / 8);
736736
}
737737

738+
/* Make sure 64 bit math will not overflow. */
738739
static bool vhost_overflow(u64 uaddr, u64 size)
739740
{
740-
/* Make sure 64 bit math will not overflow. */
741-
return uaddr > ULONG_MAX || size > ULONG_MAX || uaddr > ULONG_MAX - size;
741+
if (uaddr > ULONG_MAX || size > ULONG_MAX)
742+
return true;
743+
744+
if (!size)
745+
return false;
746+
747+
return uaddr > ULONG_MAX - size + 1;
742748
}
743749

744750
/* Caller should have vq mutex and device mutex. */

0 commit comments

Comments
 (0)