[patch 07/12] powerpc: Fix size check for hugetlbfs
From: Greg KH <gregkh@suse.de>
Date: 2007-08-14 07:50:24
-stable review patch. If anyone has any objections, please let us know. ------------------ From: Benjamin Herrenschmidt <benh@kernel.crashing.org> My "slices" address space management code that was added in 2.6.22 implementation of get_unmapped_area() doesn't properly check that the size is a multiple of the requested page size. This allows userland to create VMAs that aren't a multiple of the huge page size with hugetlbfs (since hugetlbfs entirely relies on get_unmapped_area() to do that checking) which leads to a kernel BUG() when such areas are torn down. Signed-off-by: Benjamin Herrenschmidt <benh@kernel.crashing.org> Signed-off-by: Paul Mackerras <redacted> Signed-off-by: Greg Kroah-Hartman <gregkh@suse.de> --- arch/powerpc/mm/slice.c | 2 ++ 1 file changed, 2 insertions(+)
--- a/arch/powerpc/mm/slice.c
+++ b/arch/powerpc/mm/slice.c@@ -405,6 +405,8 @@ unsigned long slice_get_unmapped_area(un if (len > mm->task_size) return -ENOMEM; + if (len & ((1ul << pshift) - 1)) + return -EINVAL; if (fixed && (addr & ((1ul << pshift) - 1))) return -EINVAL; if (fixed && addr > (mm->task_size - len))
--