[PATCH] s390/extable: Fix mvcos instruction decoding
From: Heiko Carstens
Date: Fri Oct 02 2026 - 06:40:06 EST
If either the b1 or b2 field of the mvcos instruction is zero, register
zero is not used for address computation; zero is used instead, according
to the architecture. ex_handler_ua_mvcos() incorrectly uses the real
contents of register zero. Fix this.
This shouldn't be a problem for any generated code, since the compiler
would only generate such code if it is possible to prove at compile time
that either the source or destination address is within the first 4kb of
the designated address space. Such code should not exist (also confirmed
by an allyesconfig build and decoding all ~7000 mvcos instructions).
Fixes: c488f5187a24 ("s390/uaccess: Shorten raw_copy_from_user() / raw_copy_to_user() inline assemblies")
Cc: stable@xxxxxxxxxxxxxxx
Signed-off-by: Heiko Carstens <hca@xxxxxxxxxxxxx>
---
arch/s390/mm/extable.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/arch/s390/mm/extable.c b/arch/s390/mm/extable.c
index 7498e858c401..848855da9a70 100644
--- a/arch/s390/mm/extable.c
+++ b/arch/s390/mm/extable.c
@@ -106,9 +106,9 @@ static bool ex_handler_ua_mvcos(const struct exception_table_entry *ex,
regs->psw.addr = extable_fixup(ex);
insn = (struct insn_ssf *)regs->psw.addr;
if (from)
- uaddr = regs->gprs[insn->b2] + insn->d2;
+ uaddr = (insn->b2 ? regs->gprs[insn->b2] : 0) + insn->d2;
else
- uaddr = regs->gprs[insn->b1] + insn->d1;
+ uaddr = (insn->b1 ? regs->gprs[insn->b1] : 0) + insn->d1;
remainder = PAGE_SIZE - (uaddr & (PAGE_SIZE - 1));
if (regs->gprs[insn->r3] <= remainder)
remainder = 0;
--
2.53.0