[PATCH v3 1/2] mm/gup_test: prevent overflow in GUP batch calculation
From: Sarthak Sharma
Date: Tue Sep 01 2026 - 04:50:33 EST
__gup_test_ioctl() calculates the end of a GUP batch using:
next = addr + nr * PAGE_SIZE;
If nr is too large, it can cause the next to overflow and wrap around.
If it wraps, the next > end check is bypassed and a large value
of nr is passed to the gup call, even though the pages array was
allocated according to gup->size. This can lead to out of bounds writes.
Compare nr with the number of pages remaining before performing
the multiplication. Clamp it to remaining range so that next does
not overflow or exceed end.
Fixes: 64c349f4ae78 ("mm: add infrastructure for get_user_pages_fast() benchmarking")
Signed-off-by: Sarthak Sharma <sarthak.sharma@xxxxxxx>
---
mm/gup_test.c | 5 +++--
1 file changed, 3 insertions(+), 2 deletions(-)
diff --git a/mm/gup_test.c b/mm/gup_test.c
index 44c1cdfb9c37..910cbef709b4 100644
--- a/mm/gup_test.c
+++ b/mm/gup_test.c
@@ -139,10 +139,11 @@ static int __gup_test_ioctl(unsigned int cmd,
if (nr != gup->nr_pages_per_call)
break;
- next = addr + nr * PAGE_SIZE;
- if (next > end) {
+ if (nr > (end - addr) / PAGE_SIZE) {
next = end;
nr = (next - addr) / PAGE_SIZE;
+ } else {
+ next = addr + nr * PAGE_SIZE;
}
switch (cmd) {
--
2.53.0