From 5253aee00a4383cb0482d5e99bde48b8054ae2c0 Mon Sep 17 00:00:00 2001 From: Xu Rao Date: Mon, 6 Jul 2026 17:25:00 +0800 Subject: mmc: block: reject invalid perdev_minors before division The mmcblk.perdev_minors module parameter is parsed as a signed int and is used during mmc_blk_init() to compute the number of supported block devices. Passing perdev_minors=0 makes the init path divide by zero when it computes max_devices. Negative values are invalid as well and would make max_devices negative before it is later used as an IDA limit. Reject non-positive perdev_minors values before registering any mmcblk resources. Signed-off-by: Xu Rao Signed-off-by: Ulf Hansson --- drivers/mmc/core/block.c | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/drivers/mmc/core/block.c b/drivers/mmc/core/block.c index 54a923ba4f1e..e760d13ee325 100644 --- a/drivers/mmc/core/block.c +++ b/drivers/mmc/core/block.c @@ -3337,6 +3337,11 @@ static int __init mmc_blk_init(void) { int res; + if (perdev_minors <= 0) { + pr_err("mmcblk: invalid minors per device: %d\n", perdev_minors); + return -EINVAL; + } + res = bus_register(&mmc_rpmb_bus_type); if (res < 0) { pr_err("mmcblk: could not register RPMB bus type\n"); -- cgit v1.2.3