Re: [PATCH] crypto: acomp: allocate async request context when cloning

From: Herbert Xu

Date: Tue Aug 25 2026 - 20:35:01 EST


On Sat, Aug 15, 2026 at 10:09:18AM +0000, Jérémy Jean wrote:
> ACOMP_REQUEST_ON_STACK() reserves only enough storage for the
> synchronous fallback. When an async implementation is selected, callers
> clone that stack request before retrying, but acomp_request_clone()
> currently copies only the stack-sized object. The clone therefore has no
> storage for the async provider request context, and providers such as QAT
> write past the allocation through acomp_request_ctx(). KASAN does report
> a slab OOB write.
>
> Allocate a zeroed clone large enough for the runtime acomp request size,
> copy only the bytes present in the source object, and preserve the
> existing fallback-on-allocation-failure behavior. Use the runtime reqsize
> because an implementation may adjust it during tfm initialization.
>
> Assisted-by: Codex:gpt-5
> Signed-off-by: Jérémy Jean <Jeremy.Jean@xxxxxxxxxxxxxxxxx>
> ---
> crypto/acompress.c | 16 +++++++++++++---
> 1 file changed, 13 insertions(+), 3 deletions(-)

Patch applied. Thanks.
--
Email: Herbert Xu <herbert@xxxxxxxxxxxxxxxxxxx>
Home Page: http://gondor.apana.org.au/~herbert/
PGP Key: http://gondor.apana.org.au/~herbert/pubkey.txt