Re: [PATCH] tee: shm: reject zero-sized allocations in tee_dyn_shm_alloc_helper()

From: Jens Wiklander

Date: Fri Oct 02 2026 - 08:45:49 EST


Hi,

On Thu, Oct 1, 2026 at 3:01 PM Sumit Garg <sumit.garg@xxxxxxxxxx> wrote:
>
> On Mon, 28 Sep 2026 at 17:31:13 +0300, Georgiy Osokin wrote:
> >tee_dyn_shm_alloc_helper() derives nr_pages from a caller-supplied size
> >and passes it to alloc_pages_exact() without checking it. For size == 0
> >nr_pages is 0, and alloc_pages_exact(0) calls get_order(0), which is
> >documented as undefined and returns BITS_PER_LONG - PAGE_SHIFT. The page
> >allocator then trips its order > MAX_PAGE_ORDER warning and fails the
> >allocation; on a panic_on_warn kernel that ends the boot.
> >
> >This can be triggered by TEE_IOC_SHM_ALLOC with struct
> >tee_ioctl_shm_alloc_data where size is 0.
> >
> >Reject a zero page count, as register_shm_helper() already does for the
> >register path.
> >
> >Fixes: cf4441503e20 ("tee: optee: Move pool_op helper functions")
> >Cc: stable@xxxxxxxxxxxxxxx
> >Cc: lvc-project@xxxxxxxxxxxxxxxx
> >Signed-off-by: Georgiy Osokin <g.osokin@xxxxxxxxxxxx>
> >---
> > drivers/tee/tee_shm.c | 4 ++++
> > 1 file changed, 4 insertions(+)
>
> Reviewed-by: Sumit Garg <sumit.garg@xxxxxxxxxxxxxxxx>

Looks good, I'm picking this up.

Thanks,
Jens