On 7/29/26 14:31, Anuj Gupta/Anuj Gupta wrote:
On 7/29/2026 2:59 AM, Pavel Begunkov wrote:
@@ -882,8 +894,13 @@ static struct io_rsrc_node *io_sqe_buffer_register(struct 
io_ring_ctx *ctx,
        struct io_imu_folio_data data;
        bool coalesced = false;
- if (!uaddr) {
-               if (size)
+       if (desc->type >= __IO_REGBUF_TYPE_MAX)
+               return ERR_PTR(-EINVAL);
+       if (!mem_is_zero(&desc->__resv, sizeof(desc->__resv)))
+               return ERR_PTR(-EINVAL);

desc->flags  isn't validated here, unlike __resv. nonzero flags should
be rejected too?

good catch

--
Pavel Begunkov


Reply via email to