This is an automated email from the ASF dual-hosted git repository.

xiaoxiang781216 pushed a commit to branch master
in repository https://gitbox.apache.org/repos/asf/nuttx.git


The following commit(s) were added to refs/heads/master by this push:
     new 9f73ff7e773 arch/arm64: bound pgalloc() to the user heap
9f73ff7e773 is described below

commit 9f73ff7e773347f88eccfc6882f0017392171137
Author: Royyan Zahir <[email protected]>
AuthorDate: Wed Sep 30 09:53:32 2026 +0400

    arch/arm64: bound pgalloc() to the user heap
    
    pgalloc() is a syscall in a kernel build. Its start was checked by
    DEBUGASSERT only and its end not at all, so a user task could map pages
    past ARCH_ADDRENV_VEND.
    
    Signed-off-by: Royyan Zahir <[email protected]>
---
 arch/arm64/src/common/arm64_pgalloc.c | 9 +++++----
 1 file changed, 5 insertions(+), 4 deletions(-)

diff --git a/arch/arm64/src/common/arm64_pgalloc.c 
b/arch/arm64/src/common/arm64_pgalloc.c
index 42f35f13a2e..8dcc12f69a4 100644
--- a/arch/arm64/src/common/arm64_pgalloc.c
+++ b/arch/arm64/src/common/arm64_pgalloc.c
@@ -121,10 +121,11 @@ uintptr_t pgalloc(uintptr_t brkaddr, unsigned int npages)
   vaddr   = brkaddr;
   ptlevel = MMU_PGT_LEVEL_MAX;
 
-  /* Sanity checks */
-
-  DEBUGASSERT(brkaddr >= addrenv->heapvbase);
-  DEBUGASSERT(MM_ISALIGNED(brkaddr));
+  if (brkaddr < addrenv->heapvbase || !MM_ISALIGNED(brkaddr) ||
+      npages > (ARCH_ADDRENV_VEND - brkaddr + 1) / MM_PGSIZE)
+    {
+      return 0;
+    }
 
   for (; npages > 0; npages--)
     {

Reply via email to