Am 28.09.26 um 11:09 schrieb [email protected]:
Thank you for your contribution! Sashiko AI review found 1 potential issue(s)
to consider:
- [Low] vt: unprivileged log injection via pr_warn_once in cursor sizing
FYI this is by intention. In DRM land, we usually allow for warn_once to
be triggered by user-space code. If that's not an option for vt, let's
use pr_debug() instead.
--
commit 4874174842fbef217a6215957d5bf1bff1442b36
Author: Thomas Zimmermann <[email protected]>
vt: Add cursor-size helpers
The new helpers vc_cursor_start() and vc_cursor_end() return the scanlines
in which the cursor block starts respectively ends. Users can control the
cursor size with the vt module's parameter cur_default or with the ESC
sequence \e[?Nc. In case of an invalid setting, the new helpers fall back
to cur_default and then underline cursors.
diff --git a/drivers/tty/vt/vt.c b/drivers/tty/vt/vt.c
index 57edf37495a81..8141296ccad05 100644
--- a/drivers/tty/vt/vt.c
+++ b/drivers/tty/vt/vt.c
[ ... ]
@@ -264,6 +265,109 @@ unsigned int vc_font_size(const struct vc_font *font)
}
EXPORT_SYMBOL_GPL(vc_font_size);
+/*
+ * Cursors
+ */
+
+static unsigned int vc_cursor_size(unsigned int cursor_size)
+{
+ const unsigned int cursor_default_size =
CUR_SIZE(READ_ONCE(cur_default));
+
+retry:
+ switch (cursor_size) {
+ case CUR_NONE:
+ case CUR_UNDERLINE:
+ case CUR_LOWER_THIRD:
+ case CUR_LOWER_HALF:
+ case CUR_TWO_THIRDS:
+ case CUR_BLOCK:
+ return cursor_size;
+ default:
+ pr_warn_once("Unknown cursor %u\n", cursor_size);
+ fallthrough;
[Severity: Low]
Is it expected that an unprivileged user can trigger this warning message?
An unprivileged user can write a specific DEC escape sequence (e.g.,
\e[?103c) to the VT, which parses an unhandled size into
vc->vc_cursor_type via CSI_MAKE.
When the console driver later updates the cursor, vc_cursor_size() hits
the default case and emits this warning.
Since pr_warn_once() is rate-limited to once per boot, it cannot cause
a denial of service, but it still allows local unprivileged users with
write access to a VT to add a warning line to the kernel log.
+ case CUR_DEF:
+ /*
+ * Use user-given default size, or underline if
+ * the given default is invalid.
+ */
+ if (cursor_size != cursor_default_size)
+ cursor_size = cursor_default_size;
+ else
+ cursor_size = CUR_UNDERLINE;
+ goto retry;
+ }
+}
[ ... ]
--
--
Thomas Zimmermann
Graphics Driver Developer
SUSE Software Solutions Germany GmbH
Frankenstr. 146, 90461 Nürnberg, Germany, www.suse.com
GF: Stefan Gaiser, Jochen Jaser, Abhinav Puri, (HRB 36809, AG Nürnberg)