diff options
| author | Li RongQing <lirongqing@baidu.com> | 2026-07-21 17:34:10 +0800 |
|---|---|---|
| committer | Will Deacon <will@kernel.org> | 2026-07-21 11:34:51 +0000 |
| commit | 754f8efe45f87e3a9c6871b645b2f9d46d1b407b (patch) | |
| tree | cf2ddd51eb5ae5a4f3b62f9c28303d02de56f93f | |
| parent | fb80117fddb5b477218dc99bb53911b72c3847f8 (diff) | |
| download | linux-754f8efe45f87e3a9c6871b645b2f9d46d1b407b.tar.gz linux-754f8efe45f87e3a9c6871b645b2f9d46d1b407b.tar.bz2 linux-754f8efe45f87e3a9c6871b645b2f9d46d1b407b.zip | |
iommu/intel: Fix out-of-bounds memset in dmar_latency_disable()
dmar_latency_disable() intends to zero out only the single
latency_statistic entry for the given type, but the memset size was
computed as sizeof(*lstat) * DMAR_LATENCY_NUM, which clears the entire
array starting from &lstat[type].
When type > 0, this writes beyond the end of the allocated array,
corrupting adjacent memory.
Fix by using sizeof(*lstat) to clear only the target entry.
Fixes: 55ee5e67a59a ("iommu/vt-d: Add common code for dmar latency performance monitors")
Signed-off-by: Li RongQing <lirongqing@baidu.com>
Signed-off-by: Will Deacon <will@kernel.org>
| -rw-r--r-- | drivers/iommu/intel/perf.c | 2 |
1 files changed, 1 insertions, 1 deletions
diff --git a/drivers/iommu/intel/perf.c b/drivers/iommu/intel/perf.c index 02168f2f20a4..bec98dcbb9ec 100644 --- a/drivers/iommu/intel/perf.c +++ b/drivers/iommu/intel/perf.c @@ -63,7 +63,7 @@ void dmar_latency_disable(struct intel_iommu *iommu, enum latency_type type) return; spin_lock_irqsave(&latency_lock, flags); - memset(&lstat[type], 0, sizeof(*lstat) * DMAR_LATENCY_NUM); + memset(&lstat[type], 0, sizeof(*lstat)); spin_unlock_irqrestore(&latency_lock, flags); } |