Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.bugs.dist > #1309910

Bug#1148364: riscv64: strnlen() returns a truncated length for very large count, breaking ACPI name resolution (AE_AML_NAME_NOT_FOUND flood at boot)

From Aurelien Jarno <aurel32@debian.org>
Newsgroups linux.debian.bugs.dist, linux.debian.kernel
Subject Bug#1148364: riscv64: strnlen() returns a truncated length for very large count, breaking ACPI name resolution (AE_AML_NAME_NOT_FOUND flood at boot)
Date 2026-09-19 12:00 +0200
Message-ID <NF01s-wmw-9@gated-at.bofh.it> (permalink)
References <NEZ5n-vQv-1@gated-at.bofh.it> <NEZ5n-vQv-1@gated-at.bofh.it>
Organization linux.* mail to news gateway

Cross-posted to 2 groups.

Show all headers | View raw


control: forwarded -1 https://lore.kernel.org/all/20260915152656708z04s4oSYY2BGj34F36RZa@zte.com.cn/
control: forcemerge -1 1148365

Hi,

On 2026-09-19 16:49, Lufei Zheng wrote:
> Package: linux-image-7.1.13+deb14-riscv64
> Version: 7.1.13-1
> Severity: important
> Tags: upstream
> X-Debbugs-Cc: debian-riscv@lists.debian.org
> 
> Dear maintainers,
> 
> arch/riscv/lib/strnlen.S has an integer-overflow bug: for a very large `count` (in practice `(size_t)-1`) the address computation `s + count` wraps around 2^64, the loop bound becomes smaller than the start address, and strnlen() returns a length derived only from the first machine word(typically 8).  The same wrap exists in the byte-loop fallback.

The issue has been reported upstream with a patch [1], but it is still 
under review. If you can test it and send a Tested-by: that would help 
the patch to get accepted faster.

It will get added to the debian kernel once it get fixed upstream.

Regards
Aurelien

[1] https://lore.kernel.org/all/20260915152656708z04s4oSYY2BGj34F36RZa@zte.com.cn/

-- 
Aurelien Jarno                          GPG: 4096R/1DDD8C9B
aurelien@aurel32.net                     http://aurel32.net

Back to linux.debian.bugs.dist | Previous | Next — Next in thread | Find similar | Unroll thread


Thread

Bug#1148364: riscv64: strnlen() returns a truncated length for very large count, breaking ACPI name resolution (AE_AML_NAME_NOT_FOUND flood at boot) Aurelien Jarno <aurel32@debian.org> - 2026-09-19 12:00 +0200
  Bug#1148364: riscv64: strnlen() returns a truncated length for very large count, breaking ACPI name resolution (AE_AML_NAME_NOT_FOUND flood at boot) Troy Mitchell <me@troy-y.org> - 2026-09-22 08:30 +0200

csiph-web