소스 검색

block: check for proper length of iov entries earlier in blk_rq_map_user_iov()

commit 9284bcf checks for proper length of iov entries in
blk_rq_map_user_iov(). But if the map is unaligned, kernel
will break out the loop without checking for the proper length.
So we need to check the proper length before the unalign check.

Signed-off-by: Xiaotian Feng <dfeng@redhat.com>
Cc: stable@kernel.org
Signed-off-by: Jens Axboe <jaxboe@fusionio.com>
Xiaotian Feng 15 년 전
부모
커밋
5478755616
1개의 변경된 파일3개의 추가작업 그리고 2개의 파일을 삭제
  1. 3 2
      block/blk-map.c

+ 3 - 2
block/blk-map.c

@@ -201,12 +201,13 @@ int blk_rq_map_user_iov(struct request_queue *q, struct request *rq,
 	for (i = 0; i < iov_count; i++) {
 	for (i = 0; i < iov_count; i++) {
 		unsigned long uaddr = (unsigned long)iov[i].iov_base;
 		unsigned long uaddr = (unsigned long)iov[i].iov_base;
 
 
+		if (!iov[i].iov_len)
+			return -EINVAL;
+
 		if (uaddr & queue_dma_alignment(q)) {
 		if (uaddr & queue_dma_alignment(q)) {
 			unaligned = 1;
 			unaligned = 1;
 			break;
 			break;
 		}
 		}
-		if (!iov[i].iov_len)
-			return -EINVAL;
 	}
 	}
 
 
 	if (unaligned || (q->dma_pad_mask & len) || map_data)
 	if (unaligned || (q->dma_pad_mask & len) || map_data)