Re: [PATCH v3 1/2] mm/gup_test: prevent overflow in GUP batch calculation

From: Kiryl Shutsemau

Date: Tue Sep 01 2026 - 06:35:31 EST


On Tue, Sep 01, 2026 at 02:04:51PM +0530, Sarthak Sharma wrote:
> __gup_test_ioctl() calculates the end of a GUP batch using:
>
> next = addr + nr * PAGE_SIZE;
>
> If nr is too large, it can cause the next to overflow and wrap around.
> If it wraps, the next > end check is bypassed and a large value
> of nr is passed to the gup call, even though the pages array was
> allocated according to gup->size. This can lead to out of bounds writes.
>
> Compare nr with the number of pages remaining before performing
> the multiplication. Clamp it to remaining range so that next does
> not overflow or exceed end.
>
> Fixes: 64c349f4ae78 ("mm: add infrastructure for get_user_pages_fast() benchmarking")
> Signed-off-by: Sarthak Sharma <sarthak.sharma@xxxxxxx>
> ---
> mm/gup_test.c | 5 +++--
> 1 file changed, 3 insertions(+), 2 deletions(-)
>
> diff --git a/mm/gup_test.c b/mm/gup_test.c
> index 44c1cdfb9c37..910cbef709b4 100644
> --- a/mm/gup_test.c
> +++ b/mm/gup_test.c
> @@ -139,10 +139,11 @@ static int __gup_test_ioctl(unsigned int cmd,
> if (nr != gup->nr_pages_per_call)
> break;
>
> - next = addr + nr * PAGE_SIZE;
> - if (next > end) {
> + if (nr > (end - addr) / PAGE_SIZE) {
> next = end;
> nr = (next - addr) / PAGE_SIZE;
> + } else {
> + next = addr + nr * PAGE_SIZE;
> }
>
> switch (cmd) {

What about this:

nr = min(nr, (end - addr) / PAGE_SIZE);
next = addr + nr * PAGE_SIZE;

Seems to be easier to follow, no?

--
Kiryl Shutsemau / Kirill A. Shutemov