Notification keys are checked against an inclusive maximum, but optee_notif_init() passes that maximum to bitmap_zalloc() as the number of bits. The bitmap is therefore one bit short. When the maximum key is a multiple of BITS_PER_LONG, accessing that key reads or writes beyond the allocated bitmap. Word rounding masks the problem.
Allocate max_key + 1 bits so that the highest valid key has storage.
Fixes: 787c80cc7b22 ("optee: separate notification functions") Signed-off-by: Amirreza Zarrabi amirreza.zarrabi@oss.qualcomm.com --- drivers/tee/optee/notif.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/tee/optee/notif.c b/drivers/tee/optee/notif.c index 68014222d7be..2bf5ce397233 100644 --- a/drivers/tee/optee/notif.c +++ b/drivers/tee/optee/notif.c @@ -114,7 +114,7 @@ int optee_notif_init(struct optee *optee, u_int max_key) { spin_lock_init(&optee->notif.lock); INIT_LIST_HEAD(&optee->notif.db); - optee->notif.bitmap = bitmap_zalloc(max_key, GFP_KERNEL); + optee->notif.bitmap = bitmap_zalloc(max_key + 1, GFP_KERNEL); if (!optee->notif.bitmap) return -ENOMEM;
--- base-commit: becb95e45ef0dda9ffb35156d909d3da7a2789c3 change-id: 20261009-fix-tee-max-keys-50f2db87b4e5
Best regards,