[PATCH 1/2] riscv: cfi: Bounds check restore token before swap

From: Samuel Holland

Date: Wed Oct 07 2026 - 11:57:59 EST


Currently the user-provided shadow stack restore token is not checked
before being used as the address in ssamoswap.d. While an invalid
restore token will be caught and raise SIGSEGV, this happens after
writing 4 bytes of zeroes anywhere in the address space. Check that the
restore token is at least a valid user address before the swap to ensure
we do not scribble over kernel memory.

Fixes: 66c9c713de59 ("riscv/signal: save and restore the shadow stack on a signal")
Signed-off-by: Samuel Holland <samuel.holland@xxxxxxxxxx>
---

arch/riscv/kernel/usercfi.c | 5 ++++-
1 file changed, 4 insertions(+), 1 deletion(-)

diff --git a/arch/riscv/kernel/usercfi.c b/arch/riscv/kernel/usercfi.c
index dec0ba5eff5ea..23c4d6d9d8cbc 100644
--- a/arch/riscv/kernel/usercfi.c
+++ b/arch/riscv/kernel/usercfi.c
@@ -206,10 +206,13 @@ int save_user_shstk(struct task_struct *tsk, unsigned long *saved_shstk_ptr)
*/
int restore_user_shstk(struct task_struct *tsk, unsigned long shstk_ptr)
{
+ unsigned long __user *token_ptr = (unsigned long __user *)shstk_ptr;
unsigned long token = 0;

- token = amo_user_shstk((unsigned long __user *)shstk_ptr, 0);
+ if (!access_ok(token_ptr, sizeof(token)))
+ return -EFAULT;

+ token = amo_user_shstk(token_ptr, 0);
if (token == -1)
return -EFAULT;

--
2.52.0

base-commit: a90ee4305c4a5df72c11b31dacfdc76e00fcf78a
branch: up/cfi-fixes