[PATCH] mm/hmm/test: Reject overflowing page counts
From: Dan Carpenter
Date: Tue Sep 15 2026 - 14:23:52 EST
The number of pages comes directly from userspace. Shifting a value
larger than ULONG_MAX >> PAGE_SHIFT discards its high bits before the
existing end-address check. A request for a huge number of pages can
therefore be accepted and processed as a much smaller request.
Reject page counts that cannot be represented as a byte size before
performing the shift.
So far as ChatGPT and I can tell this doesn't cause an issue in
practice but preventing this integer overflow is the correct thing to
do.
Fixes: b2ef9f5a5cb3 ("mm/hmm/test: add selftest driver for HMM")
Assisted-by: ChatGPT:gpt-5
Signed-off-by: Dan Carpenter <error27@xxxxxxxxx>
---
lib/test_hmm.c | 2 ++
1 file changed, 2 insertions(+)
diff --git a/lib/test_hmm.c b/lib/test_hmm.c
index 6911daa9f854..b409c42bfe6f 100644
--- a/lib/test_hmm.c
+++ b/lib/test_hmm.c
@@ -1624,6 +1624,8 @@ static long dmirror_fops_unlocked_ioctl(struct file *filp,
if (cmd.addr & ~PAGE_MASK)
return -EINVAL;
+ if (cmd.npages > ULONG_MAX >> PAGE_SHIFT)
+ return -EINVAL;
if (cmd.addr >= (cmd.addr + (cmd.npages << PAGE_SHIFT)))
return -EINVAL;
--
2.53.0