[PATCH v2] dmaengine: xilinx: dpdma: Reserve space for a string terminator

From: Jiale Yao

Date: Sat Oct 03 2026 - 06:01:10 EST


xilinx_dpdma_debugfs_write() copies size bytes from userspace and parses
them with strsep() and strcasecmp(). If the input has no NUL within that
range, the parser can read beyond the allocation.

Use memdup_user_nul() to copy the complete input and append a terminating
NUL.

Fixes: 1d220435cab3 ("dmaengine: xilinx: dpdma: Add debugfs support")
Signed-off-by: Jiale Yao <yaojiale02@xxxxxxx>

---

Changes in v2:
- Replace kzalloc() and strncpy_from_user() with memdup_user_nul(), as
suggested by Laurent.

diff --git a/drivers/dma/xilinx/xilinx_dpdma.c b/drivers/dma/xilinx/xilinx_dpdma.c
index d9a3542c4531..219d25be6c3a 100644
--- a/drivers/dma/xilinx/xilinx_dpdma.c
+++ b/drivers/dma/xilinx/xilinx_dpdma.c
@@ -410,15 +410,11 @@ static ssize_t xilinx_dpdma_debugfs_write(struct file *f,
if (dpdma_debugfs.testcase != DPDMA_TC_NONE)
return -EBUSY;

- kern_buff = kzalloc(size, GFP_KERNEL);
- if (!kern_buff)
- return -ENOMEM;
+ kern_buff = memdup_user_nul(buf, size);
+ if (IS_ERR(kern_buff))
+ return PTR_ERR(kern_buff);
kern_buff_start = kern_buff;

- ret = strncpy_from_user(kern_buff, buf, size);
- if (ret < 0)
- goto done;
-
/* Read the testcase name from a user request. */
testcase = strsep(&kern_buff, " ");

--
2.34.1