From e62745dd1172e475c101de3f11e39bf192d35ae5 Mon Sep 17 00:00:00 2001 From: Wang Zihan Date: Sun, 3 May 2026 03:46:15 +0800 Subject: [PATCH] vt: add mode validation in vt_setactivate The vt_setactivate() function accepts any mode value without validation, while VT_SETMODE correctly rejects invalid values (only VT_AUTO and VT_PROCESS are valid). This allows users to set invalid mode values (e.g., 0xFF) which bypasses VT_PROCESS signal handling and causes undefined VT switching behavior. Fix this by adding the same validation as VT_SETMODE. Signed-off-by: Wang Zihan Link: https://patch.msgid.link/tencent_6A7DAE2E1288663D23AACBE2950D6E535007@qq.com Signed-off-by: Greg Kroah-Hartman --- drivers/tty/vt/vt_ioctl.c | 2 ++ 1 file changed, 2 insertions(+) diff --git a/drivers/tty/vt/vt_ioctl.c b/drivers/tty/vt/vt_ioctl.c index 28993a3d0acb..b8787283a0fa 100644 --- a/drivers/tty/vt/vt_ioctl.c +++ b/drivers/tty/vt/vt_ioctl.c @@ -596,6 +596,8 @@ static int vt_setactivate(struct vt_setactivate __user *sa) return -EFAULT; if (vsa.console == 0 || vsa.console > MAX_NR_CONSOLES) return -ENXIO; + if (vsa.mode.mode != VT_AUTO && vsa.mode.mode != VT_PROCESS) + return -EINVAL; vsa.console--; vsa.console = array_index_nospec(vsa.console, MAX_NR_CONSOLES);