mirror of
https://github.com/torvalds/linux.git
synced 2026-08-06 23:43:54 +02:00
In gsi_trans_pool_init_dma(), the total size of a pool of memory
used for DMA transactions is calculated. However the calculation is
done incorrectly.
For 4KB pages, this total size is currently always more than one
page, and as a result, the calculation produces a positive (though
incorrect) total size. The code still works in this case; we just
end up with fewer DMA pool entries than we intended.
Bjorn Andersson tested booting a kernel with 16KB pages, and hit a
null pointer derereference in sg_alloc_append_table_from_pages(),
descending from gsi_trans_pool_init_dma(). The cause of this was
that a 16KB total size was going to be allocated, and with 16KB
pages the order of that allocation is 0. The total_size calculation
yielded 0, which eventually led to the crash.
Correcting the total_size calculation fixes the problem.
Reported-by: Bjorn Andersson <quic_bjorande@quicinc.com>
Tested-by: Bjorn Andersson <quic_bjorande@quicinc.com>
Fixes:
|
||
|---|---|---|
| .. | ||
| data | ||
| reg | ||
| gsi_private.h | ||
| gsi_reg.c | ||
| gsi_reg.h | ||
| gsi_trans.c | ||
| gsi_trans.h | ||
| gsi.c | ||
| gsi.h | ||
| ipa_cmd.c | ||
| ipa_cmd.h | ||
| ipa_data.h | ||
| ipa_endpoint.c | ||
| ipa_endpoint.h | ||
| ipa_gsi.c | ||
| ipa_gsi.h | ||
| ipa_interrupt.c | ||
| ipa_interrupt.h | ||
| ipa_main.c | ||
| ipa_mem.c | ||
| ipa_mem.h | ||
| ipa_modem.c | ||
| ipa_modem.h | ||
| ipa_power.c | ||
| ipa_power.h | ||
| ipa_qmi_msg.c | ||
| ipa_qmi_msg.h | ||
| ipa_qmi.c | ||
| ipa_qmi.h | ||
| ipa_reg.c | ||
| ipa_reg.h | ||
| ipa_resource.c | ||
| ipa_resource.h | ||
| ipa_smp2p.c | ||
| ipa_smp2p.h | ||
| ipa_sysfs.c | ||
| ipa_sysfs.h | ||
| ipa_table.c | ||
| ipa_table.h | ||
| ipa_uc.c | ||
| ipa_uc.h | ||
| ipa_version.h | ||
| ipa.h | ||
| Kconfig | ||
| Makefile | ||
| reg.h | ||