Commit 78004e9a87f2 for kernel

commit 78004e9a87f240df03e2f73120d291763c32e0a7
Author: Ali Ahmet Memis <ali@iusegentoo.com>
Date:   Fri Aug 21 01:45:27 2026 +0000

    openrisc: fix arbitrary kernel memory access via or1k_atomic syscall

    sys_or1k_atomic() (syscall 244 in the "or1k" ABI) takes two user
    pointers, v1 and v2, and swaps the words they point to in hand-written
    assembly.

        l.lwz   r29,0(r4)
        l.lwz   r27,0(r5)
        l.sw    0(r4),r27
        l.sw    0(r5),r29

    The pointers are not checked with access_ok(). The four memory
    accesses also have no exception table entries.

    A caller passes a kernel address as either pointer, and the syscall
    reads from and writes to it directly.

    This gives an unprivileged process a kernel read/write primitive. It
    overwrites kernel data such as the sys_call_table, gaining code
    execution in kernel context.

    Check both pointers before entering the critical section. Add fixups
    for the four memory accesses so faults on valid but unmapped user
    addresses return -EFAULT.

    [shorne@gmail.com: fix comment style]
    Fixes: 9d02a4283e9c ("OpenRISC: Boot code")
    Cc: stable@vger.kernel.org
    Signed-off-by: Ali Ahmet Memis <ali@iusegentoo.com>
    Signed-off-by: Stafford Horne <shorne@gmail.com>

diff --git a/arch/openrisc/kernel/entry.S b/arch/openrisc/kernel/entry.S
index c7e90b09645e..18e68680471e 100644
--- a/arch/openrisc/kernel/entry.S
+++ b/arch/openrisc/kernel/entry.S
@@ -1223,15 +1223,50 @@ _no_syscall_trace:
  *
  */

+/* Keep this literal; hi()/lo() can't use the UL-suffixed TASK_SIZE. */
+#define OR1K_ATOMIC_ADDR_LIMIT	0x7ffffffc
+
 ENTRY(sys_or1k_atomic)
 	/* FIXME: This ignores r3 and always does an XCHG */
+
+	/* Check both user pointers before accessing them. */
+	l.movhi	r13,hi(OR1K_ATOMIC_ADDR_LIMIT)
+	l.ori	r13,r13,lo(OR1K_ATOMIC_ADDR_LIMIT)
+	l.sfgtu	r4,r13
+	l.bf	9f
+	 l.nop
+	l.sfgtu	r5,r13
+	l.bf	9f
+	 l.nop
+
 	DISABLE_INTERRUPTS(r17,r19)
-	l.lwz	r29,0(r4)
-	l.lwz	r27,0(r5)
-	l.sw	0(r4),r27
-	l.sw	0(r5),r29
+10:	l.lwz	r29,0(r4)
+11:	l.lwz	r27,0(r5)
+12:	l.sw	0(r4),r27
+13:	l.sw	0(r5),r29
 	ENABLE_INTERRUPTS(r17)
 	l.jr	r9
 	 l.or	r11,r0,r0

+	/*
+	 * Either pointer was outside user space, or turned out to be
+	 * unmapped/inaccessible when we actually touched it.
+	 */
+9:	l.jr	r9
+	 l.addi	r11,r0,-EFAULT
+
+	.section .fixup, "ax"
+14:
+	ENABLE_INTERRUPTS(r17)
+	l.j	9b
+	 l.nop
+	.previous
+
+	.section __ex_table, "a"
+	.long	10b, 14b
+	.long	11b, 14b
+	.long	12b, 14b
+	.long	13b, 14b
+	.previous
+
 /* ============================================================[ EOF ]=== */