* [BUG] RDMA/rxe: MW rkey authorizes accesses outside the bound range
@ 2026-10-06 9:11 sungbyeongchan
2026-10-06 16:22 ` Greg KH
0 siblings, 1 reply; 3+ messages in thread
From: sungbyeongchan @ 2026-10-06 9:11 UTC (permalink / raw)
To: Zhu Yanjun, Jason Gunthorpe, Leon Romanovsky
Cc: linux-rdma, linux-kernel, security
Hello,
I found a memory-window range authorization bug in the RXE responder.
A peer with a valid type-2 MW rkey can issue RDMA READ or WRITE outside
the interval authorized by the MW bind, provided the request remains
inside the wider backing MR. rxe_lookup_mw() validates the key, PD, QP,
access rights, state, and nonzero length, but check_rkey() checks the
request address only against the backing MR. It never checks the full
request extent against mw->addr and mw->length.
I reproduced this twice on commit
ff47652a4b66c067c765a7ad464d930b5a9367cc. A 64-byte type-2 MW at
offset 1024 in a 4096-byte MR allowed a valid connected peer to read an
eight-byte sentinel at offset 2048 and replace it with peer-selected
bytes. In-window READ and WRITE succeeded, while a request crossing the
backing-MR end was rejected.
The demonstrated impact is disclosure and modification of registered
userspace memory outside the delegated MW. I did not demonstrate kernel
memory access, a kernel crash, code execution, or privilege escalation.
The affected path is:
rxe_responder()
-> check_rkey()
-> rxe_lookup_mw()
-> mr_check_range() against only the backing MR
I tested an overflow-safe MW interval check immediately after MW lookup.
With that change, outside-window READ and WRITE return a remote-access
error, while valid in-window operations continue to work. Fixed A/B
testing passed with the same kernel configuration.
I performed a best-effort public duplicate search through 2026-10-06.
The public RXE MW/MR lifetime-race series addresses reference and object
lifetime races, not this missing MW range check; I found no exact public
report of this range bypass.
This report was prepared with AI assistance and is being treated as
public under Documentation/process/security-bugs.rst. A tested source
reproducer, logs, configuration, and proposed patch are available to the
maintainers on request; the reproducer is intentionally not attached to
this public report.
Assisted-by: LLM
Regards,
sungbyeongchan
^ permalink raw reply [flat|nested] 3+ messages in thread
* Re: [BUG] RDMA/rxe: MW rkey authorizes accesses outside the bound range
2026-10-06 9:11 [BUG] RDMA/rxe: MW rkey authorizes accesses outside the bound range sungbyeongchan
@ 2026-10-06 16:22 ` Greg KH
2026-10-06 18:33 ` Zhu Yanjun
0 siblings, 1 reply; 3+ messages in thread
From: Greg KH @ 2026-10-06 16:22 UTC (permalink / raw)
To: sungbyeongchan
Cc: Zhu Yanjun, Jason Gunthorpe, Leon Romanovsky, linux-rdma,
linux-kernel, security
On Tue, Oct 06, 2026 at 06:11:03PM +0900, sungbyeongchan wrote:
> Hello,
>
> I found a memory-window range authorization bug in the RXE responder.
Great! Please submit a patch for these issues as you have a reproducer
and can test them and that way you get proper credit for resolving the
issue.
Also, no need to cc: security@kernel.org on public issues like this.
thanks,
greg k-h
^ permalink raw reply [flat|nested] 3+ messages in thread
* Re: [BUG] RDMA/rxe: MW rkey authorizes accesses outside the bound range
2026-10-06 16:22 ` Greg KH
@ 2026-10-06 18:33 ` Zhu Yanjun
0 siblings, 0 replies; 3+ messages in thread
From: Zhu Yanjun @ 2026-10-06 18:33 UTC (permalink / raw)
To: Greg KH, sungbyeongchan, yanjun.zhu
Cc: Zhu Yanjun, Jason Gunthorpe, Leon Romanovsky, linux-rdma,
linux-kernel, security
在 2026/10/6 9:22, Greg KH 写道:
> On Tue, Oct 06, 2026 at 06:11:03PM +0900, sungbyeongchan wrote:
>> Hello,
>>
>> I found a memory-window range authorization bug in the RXE responder.
> Great! Please submit a patch for these issues as you have a reproducer
> and can test them and that way you get proper credit for resolving the
> issue.
Please explain the problems in the commit logs and share the reproducer
program with us.
If you think that it is not good to share the reproducer program in
public, you can share it offline.
Yanjun Zhu
>
> Also, no need to cc: security@kernel.org on public issues like this.
>
> thanks,
>
> greg k-h
--
Best Regards,
Yanjun.Zhu
^ permalink raw reply [flat|nested] 3+ messages in thread
end of thread, other threads:[~2026-10-06 18:33 UTC | newest]
Thread overview: 3+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-10-06 9:11 [BUG] RDMA/rxe: MW rkey authorizes accesses outside the bound range sungbyeongchan
2026-10-06 16:22 ` Greg KH
2026-10-06 18:33 ` Zhu Yanjun
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®