[PATCH] crypto: nx - validate 'ignore' before subtracting in decompress

From: Aldo Ariel Panzardo

Date: Fri Sep 25 2026 - 14:01:29 EST


The decompress() function subtracts the header-supplied `ignore` value
(a u16 from the compressed stream) from `dlen` (the number of bytes
produced by the decompressor) without checking that ignore <= dlen.

If a caller decompresses a crafted buffer where `hdr->ignore` exceeds
the actual decompressed length, the subtraction wraps around to a
near-UINT_MAX value. The subsequent memcpy() then copies gigabytes of
data past the destination buffer, causing an out-of-bounds kernel write.

Add a bounds check before the subtraction and return -EINVAL if the
value is inconsistent.

Cc: stable@xxxxxxxxxxxxxxx
Signed-off-by: Aldo Ariel Panzardo <qwe.aldo@xxxxxxxxx>
---
drivers/crypto/nx/nx-842.c | 3 +++
1 file changed, 3 insertions(+)

--- a/drivers/crypto/nx/nx-842.c
+++ b/drivers/crypto/nx/nx-842.c
@@ -421,6 +421,8 @@

slen -= spadding;

+ if (ignore > dlen)
+ return -EINVAL;
dlen -= ignore;
if (ignore)
pr_debug("ignoring last %x bytes\n", ignore);

--
2.43.0