Re: [PATCH 6/7] x86/fpu: Pre-fault only required size of xstate buffer
From: Borislav Petkov
Date: Wed Sep 23 2026 - 19:59:03 EST
On Wed, Sep 16, 2026 at 11:23:09PM +0000, Andrei Vagin wrote:
> The kernel previously used the default task FPU state size (user_size)
> to fault in the user buffer when restoring FPU registers from a signal
> frame. This can lead to attempting to fault in memory past the end of
> the actual frame if the frame was smaller than the default size.
>
> Introduce consistency checks to calculate the actual required size for
> the features enabled in the xfeatures mask, ensure that the provided
> xstate_size is sufficient, and shrink it to the actual required size.
> Use this validated size to fault in the user buffer.
>
> Keep the strict check that the provided xstate_size does not exceed the
> default user_size for now.
>
> Reviewed-by: Alexander Mikhalitsyn <alexander@xxxxxxxxxxxxx>
> Reviewed-by: Chang S. Bae <chang.seok.bae@xxxxxxxxx>
> Signed-off-by: Andrei Vagin <avagin@xxxxxxxxxx>
> ---
> arch/x86/kernel/fpu/signal.c | 38 +++++++++++++++++++++++++++---------
> arch/x86/kernel/fpu/xstate.h | 2 ++
> 2 files changed, 31 insertions(+), 9 deletions(-)
>
> diff --git a/arch/x86/kernel/fpu/signal.c b/arch/x86/kernel/fpu/signal.c
> index 050e58691964..1c4d83f3c44b 100644
> --- a/arch/x86/kernel/fpu/signal.c
> +++ b/arch/x86/kernel/fpu/signal.c
> @@ -29,7 +29,8 @@ static inline bool check_xstate_in_sigframe(struct fxregs_state __user *buf_fx,
> {
> int min_xstate_size = sizeof(struct fxregs_state) +
> sizeof(struct xstate_header);
> - void __user *fpstate = buf_fx;
> + struct fpstate *fpstate = x86_task_fpu(current)->fpstate;
> + void __user *buf = buf_fx;
> unsigned int magic2;
Reverse fir tree ordering pls:
struct fpstate *fpstate = x86_task_fpu(current)->fpstate;
int min_xstate_size = sizeof(struct fxregs_state) +
sizeof(struct xstate_header);
void __user *buf = buf_fx;
unsigned int magic2;
--
Regards/Gruss,
Boris.
https://people.kernel.org/tglx/notes-about-netiquette