Skip to content

staging: vc04_services: fix pointer arithmetic in create_pagelist - #7593

Open
nolasoft wants to merge 1 commit into
raspberrypi:rpi-6.18.yfrom
nolasoft:rpi-6.18.y
Open

staging: vc04_services: fix pointer arithmetic in create_pagelist#7593
nolasoft wants to merge 1 commit into
raspberrypi:rpi-6.18.yfrom
nolasoft:rpi-6.18.y

Conversation

@nolasoft

@nolasoft nolasoft commented Sep 2, 2026

Copy link
Copy Markdown

Summary

Fix a pointer-arithmetic bug in the vmalloc handling path of create_pagelist().

Problem

In drivers/staging/vc04_services/interface/vchiq_arm/vchiq_core.c:

struct page *pg =
    vmalloc_to_page(((unsigned int *)bulk->offset +
                     (actual_pages * PAGE_SIZE)));

Adding an integer to an unsigned int * multiplies the offset by sizeof(unsigned int) (4). Consequently the address becomes:bulk->offset + (actual_pages * PAGE_SIZE * 4)instead of the intended:bulk->offset + (actual_pages * PAGE_SIZE)Only the first page is correct; later pages are wrong. This can lead to
incorrect DMA mappings, data corruption, or NULL page pointers.

In the vmalloc path of create_pagelist(), the address passed to
vmalloc_to_page() was computed as:

    (unsigned int *)bulk->offset + (actual_pages * PAGE_SIZE)

Because pointer arithmetic on unsigned int * scales by sizeof(unsigned int),
this advances by 4 * PAGE_SIZE bytes instead of PAGE_SIZE. As a result,
only the first page is correct; subsequent pages point to the wrong
addresses.

Cast through char * (or void *) so the offset is applied in bytes.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant