diff options
author | Pavel Begunkov <asml.silence@gmail.com> | 2020-11-29 18:33:32 +0000 |
---|---|---|
committer | Jens Axboe <axboe@kernel.dk> | 2020-11-30 11:12:03 -0700 |
commit | 2d280bc8930ba9ed1705cfd548c6c8924949eaf1 (patch) | |
tree | ca26780dd333d3d3cd1193f38af32ed0a9ac0101 /fs/io_uring.c | |
parent | af60470347de6ac2b9f0cc3703975a543a3de075 (diff) | |
download | lwn-2d280bc8930ba9ed1705cfd548c6c8924949eaf1.tar.gz lwn-2d280bc8930ba9ed1705cfd548c6c8924949eaf1.zip |
io_uring: fix recvmsg setup with compat buf-select
__io_compat_recvmsg_copy_hdr() with REQ_F_BUFFER_SELECT reads out iov
len but never assigns it to iov/fast_iov, leaving sr->len with garbage.
Hopefully, following io_buffer_select() truncates it to the selected
buffer size, but the value is still may be under what was specified.
Cc: <stable@vger.kernel.org> # 5.7
Signed-off-by: Pavel Begunkov <asml.silence@gmail.com>
Signed-off-by: Jens Axboe <axboe@kernel.dk>
Diffstat (limited to 'fs/io_uring.c')
-rw-r--r-- | fs/io_uring.c | 3 |
1 files changed, 2 insertions, 1 deletions
diff --git a/fs/io_uring.c b/fs/io_uring.c index 1023f7b44cea..a2a7c65a77aa 100644 --- a/fs/io_uring.c +++ b/fs/io_uring.c @@ -4499,7 +4499,8 @@ static int __io_compat_recvmsg_copy_hdr(struct io_kiocb *req, return -EFAULT; if (clen < 0) return -EINVAL; - sr->len = iomsg->iov[0].iov_len; + sr->len = clen; + iomsg->iov[0].iov_len = clen; iomsg->iov = NULL; } else { ret = __import_iovec(READ, (struct iovec __user *)uiov, len, |