Re: [PATCH] crypto: nx - validate 'ignore' before subtracting in decompress

From: Herbert Xu

Date: Fri Oct 02 2026 - 04:08:00 EST


On Fri, Sep 25, 2026 at 02:58:39PM -0300, Aldo Ariel Panzardo wrote:
> The decompress() function subtracts the header-supplied `ignore` value
> (a u16 from the compressed stream) from `dlen` (the number of bytes
> produced by the decompressor) without checking that ignore <= dlen.
>
> If a caller decompresses a crafted buffer where `hdr->ignore` exceeds
> the actual decompressed length, the subtraction wraps around to a
> near-UINT_MAX value. The subsequent memcpy() then copies gigabytes of
> data past the destination buffer, causing an out-of-bounds kernel write.
>
> Add a bounds check before the subtraction and return -EINVAL if the
> value is inconsistent.
>
> Cc: stable@xxxxxxxxxxxxxxx
> Signed-off-by: Aldo Ariel Panzardo <qwe.aldo@xxxxxxxxx>
> ---
> drivers/crypto/nx/nx-842.c | 3 +++
> 1 file changed, 3 insertions(+)

Thanks for the fix!

I think a bigger problem is that this hardware is accepting input
that cannot be processed by the software fallback since it has no
handling of NX842_CRYPTO_MAGIC.

The whole point of having the software implementation is to be able
to decompress the output of the hardware.

I'm not sure who is maintaining this currently. Vishal, do we
still need the 842 algorithm? Could we fix the software fallback
so that it can handle the same input as the hardware driver?

Cheers,
--
Email: Herbert Xu <herbert@xxxxxxxxxxxxxxxxxxx>
Home Page: http://gondor.apana.org.au/~herbert/
PGP Key: http://gondor.apana.org.au/~herbert/pubkey.txt