[PATCH 1/3] dmaengine: dw-axi-dmac: Bound the cyclic LLP search to the descriptor

From: Roland Dreier via B4 Relay

Date: Mon Oct 05 2026 - 21:03:36 EST


From: Roland Dreier <rolanddreier@xxxxxxxxxx>

For a cyclic transfer, axi_chan_block_xfer_complete() looks for the
LLI whose address matches CH_LLP by walking the descriptor's hw_desc
array, but it bounds the walk with chan->descs_allocated. That counts
the LLIs of every descriptor allocated on the channel, not just this
one. If CH_LLP matches none of the descriptor's LLIs (should never
happen, but...) while another descriptor is allocated, the loop reads
past the end of the array.

Bound the walk with the descriptor's nr_hw_descs, as in the
already-queued patch "dmaengine: dw-axi-dmac: Fix LLI dump
out-of-bounds access".

Assisted-by: LLM
Signed-off-by: Roland Dreier <rolanddreier@xxxxxxxxxx>
---
drivers/dma/dw-axi-dmac/dw-axi-dmac-platform.c | 3 +--
1 file changed, 1 insertion(+), 2 deletions(-)

diff --git a/drivers/dma/dw-axi-dmac/dw-axi-dmac-platform.c b/drivers/dma/dw-axi-dmac/dw-axi-dmac-platform.c
index eebed2474210..813d17a278e7 100644
--- a/drivers/dma/dw-axi-dmac/dw-axi-dmac-platform.c
+++ b/drivers/dma/dw-axi-dmac/dw-axi-dmac-platform.c
@@ -1095,7 +1095,6 @@ static noinline void axi_chan_handle_err(struct axi_dma_chan *chan, u32 status)

static void axi_chan_block_xfer_complete(struct axi_dma_chan *chan)
{
- int count = atomic_read(&chan->descs_allocated);
struct axi_dma_hw_desc *hw_desc;
struct axi_dma_desc *desc;
struct virt_dma_desc *vd;
@@ -1122,7 +1121,7 @@ static void axi_chan_block_xfer_complete(struct axi_dma_chan *chan)
desc = vd_to_axi_desc(vd);
if (desc) {
llp = lo_hi_readq(chan->chan_regs + CH_LLP);
- for (i = 0; i < count; i++) {
+ for (i = 0; i < desc->nr_hw_descs; i++) {
hw_desc = &desc->hw_desc[i];
if (hw_desc->llp == llp) {
axi_chan_irq_clear(chan, hw_desc->lli->status_lo);

--
2.54.0