Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.bugs.dist > #1309910
| From | Aurelien Jarno <aurel32@debian.org> |
|---|---|
| Newsgroups | linux.debian.bugs.dist, linux.debian.kernel |
| Subject | Bug#1148364: riscv64: strnlen() returns a truncated length for very large count, breaking ACPI name resolution (AE_AML_NAME_NOT_FOUND flood at boot) |
| Date | 2026-09-19 12:00 +0200 |
| Message-ID | <NF01s-wmw-9@gated-at.bofh.it> (permalink) |
| References | <NEZ5n-vQv-1@gated-at.bofh.it> <NEZ5n-vQv-1@gated-at.bofh.it> |
| Organization | linux.* mail to news gateway |
Cross-posted to 2 groups.
control: forwarded -1 https://lore.kernel.org/all/20260915152656708z04s4oSYY2BGj34F36RZa@zte.com.cn/ control: forcemerge -1 1148365 Hi, On 2026-09-19 16:49, Lufei Zheng wrote: > Package: linux-image-7.1.13+deb14-riscv64 > Version: 7.1.13-1 > Severity: important > Tags: upstream > X-Debbugs-Cc: debian-riscv@lists.debian.org > > Dear maintainers, > > arch/riscv/lib/strnlen.S has an integer-overflow bug: for a very large `count` (in practice `(size_t)-1`) the address computation `s + count` wraps around 2^64, the loop bound becomes smaller than the start address, and strnlen() returns a length derived only from the first machine word(typically 8). The same wrap exists in the byte-loop fallback. The issue has been reported upstream with a patch [1], but it is still under review. If you can test it and send a Tested-by: that would help the patch to get accepted faster. It will get added to the debian kernel once it get fixed upstream. Regards Aurelien [1] https://lore.kernel.org/all/20260915152656708z04s4oSYY2BGj34F36RZa@zte.com.cn/ -- Aurelien Jarno GPG: 4096R/1DDD8C9B aurelien@aurel32.net http://aurel32.net
Back to linux.debian.bugs.dist | Previous | Next — Next in thread | Find similar | Unroll thread
Bug#1148364: riscv64: strnlen() returns a truncated length for very large count, breaking ACPI name resolution (AE_AML_NAME_NOT_FOUND flood at boot) Aurelien Jarno <aurel32@debian.org> - 2026-09-19 12:00 +0200 Bug#1148364: riscv64: strnlen() returns a truncated length for very large count, breaking ACPI name resolution (AE_AML_NAME_NOT_FOUND flood at boot) Troy Mitchell <me@troy-y.org> - 2026-09-22 08:30 +0200
csiph-web