Re: [PATCH v2] dmaengine: xilinx: dpdma: Reserve space for a string terminator

From: Frank Li

Date: Sat Oct 03 2026 - 21:03:34 EST


On Sat, Oct 03, 2026 at 05:59:22PM +0800, Jiale Yao wrote:
> xilinx_dpdma_debugfs_write() copies size bytes from userspace and parses
> them with strsep() and strcasecmp(). If the input has no NUL within that
> range, the parser can read beyond the allocation.
>
> Use memdup_user_nul() to copy the complete input and append a terminating
> NUL.
>
> Fixes: 1d220435cab3 ("dmaengine: xilinx: dpdma: Add debugfs support")
> Signed-off-by: Jiale Yao <yaojiale02@xxxxxxx>
>
> ---

Reviewed-by: Frank Li <Frank.Li@xxxxxxx>

>
> Changes in v2:
> - Replace kzalloc() and strncpy_from_user() with memdup_user_nul(), as
> suggested by Laurent.
>
> diff --git a/drivers/dma/xilinx/xilinx_dpdma.c b/drivers/dma/xilinx/xilinx_dpdma.c
> index d9a3542c4531..219d25be6c3a 100644
> --- a/drivers/dma/xilinx/xilinx_dpdma.c
> +++ b/drivers/dma/xilinx/xilinx_dpdma.c
> @@ -410,15 +410,11 @@ static ssize_t xilinx_dpdma_debugfs_write(struct file *f,
> if (dpdma_debugfs.testcase != DPDMA_TC_NONE)
> return -EBUSY;
>
> - kern_buff = kzalloc(size, GFP_KERNEL);
> - if (!kern_buff)
> - return -ENOMEM;
> + kern_buff = memdup_user_nul(buf, size);
> + if (IS_ERR(kern_buff))
> + return PTR_ERR(kern_buff);
> kern_buff_start = kern_buff;
>
> - ret = strncpy_from_user(kern_buff, buf, size);
> - if (ret < 0)
> - goto done;
> -
> /* Read the testcase name from a user request. */
> testcase = strsep(&kern_buff, " ");
>
> --
> 2.34.1
>