[PATCH] crypto: nx - validate 'ignore' before subtracting in decompress
From: Aldo Ariel Panzardo
Date: Fri Sep 25 2026 - 14:01:29 EST
The decompress() function subtracts the header-supplied `ignore` value
(a u16 from the compressed stream) from `dlen` (the number of bytes
produced by the decompressor) without checking that ignore <= dlen.
If a caller decompresses a crafted buffer where `hdr->ignore` exceeds
the actual decompressed length, the subtraction wraps around to a
near-UINT_MAX value. The subsequent memcpy() then copies gigabytes of
data past the destination buffer, causing an out-of-bounds kernel write.
Add a bounds check before the subtraction and return -EINVAL if the
value is inconsistent.
Cc: stable@xxxxxxxxxxxxxxx
Signed-off-by: Aldo Ariel Panzardo <qwe.aldo@xxxxxxxxx>
---
drivers/crypto/nx/nx-842.c | 3 +++
1 file changed, 3 insertions(+)
--- a/drivers/crypto/nx/nx-842.c
+++ b/drivers/crypto/nx/nx-842.c
@@ -421,6 +421,8 @@
slen -= spadding;
+ if (ignore > dlen)
+ return -EINVAL;
dlen -= ignore;
if (ignore)
pr_debug("ignoring last %x bytes\n", ignore);
--
2.43.0