From 7dfa2e8a7a6bd8e86060bf4ea99b54091b3fd971 Mon Sep 17 00:00:00 2001 From: Sean Young Date: Sun, 13 Sep 2026 15:12:27 +0100 Subject: parisc: unwind: Replace open-coded binary search with bsearch() There is a bug in the binary search where hi can underflow. If addr is less than the first entry, then "hi = mid - 1" will underflow to ULONG_MAX. Then we have an out-of-bounds read. Replace the open-coded binary search with bsearch(). Issue found by an LLM. Signed-off-by: Sean Young Signed-off-by: Helge Deller --- arch/parisc/kernel/unwind.c | 33 +++++++++++++++------------------ 1 file changed, 15 insertions(+), 18 deletions(-) diff --git a/arch/parisc/kernel/unwind.c b/arch/parisc/kernel/unwind.c index 32103a270a8e..fab9ae22191a 100644 --- a/arch/parisc/kernel/unwind.c +++ b/arch/parisc/kernel/unwind.c @@ -14,6 +14,7 @@ #include #include #include +#include #include #include @@ -49,27 +50,23 @@ static DEFINE_SPINLOCK(unwind_lock); static struct unwind_table kernel_unwind_table __ro_after_init; static LIST_HEAD(unwind_tables); -static inline const struct unwind_table_entry * -find_unwind_entry_in_table(const struct unwind_table *table, unsigned long addr) +static int cmp_unwind_entry(const void *key, const void *elt) { - const struct unwind_table_entry *e = NULL; - unsigned long lo, hi, mid; + unsigned long addr = (unsigned long)key; + const struct unwind_table_entry *e = elt; - lo = 0; - hi = table->length - 1; - - while (lo <= hi) { - mid = (hi - lo) / 2 + lo; - e = &table->table[mid]; - if (addr < e->region_start) - hi = mid - 1; - else if (addr > e->region_end) - lo = mid + 1; - else - return e; - } + if (addr < e->region_start) + return -1; + if (addr > e->region_end) + return 1; + return 0; +} - return NULL; +static inline const struct unwind_table_entry * +find_unwind_entry_in_table(const struct unwind_table *table, unsigned long addr) +{ + return bsearch((void *)addr, table->table, table->length, + sizeof(*table->table), cmp_unwind_entry); } static const struct unwind_table_entry * -- cgit v1.2.3