From: Greg KH <gregkh@suse.de>
To: linux-kernel@vger.kernel.org, stable@kernel.org
Cc: stable-review@kernel.org, torvalds@linux-foundation.org,
akpm@linux-foundation.org, alan@lxorguk.ukuu.org.uk,
Andy Grover <andy.grover@oracle.com>,
"David S. Miller" <davem@davemloft.net>,
Stefan Bader <stefan.bader@canonical.com>,
Tim Gardner <tim.gardner@canonical.com>,
Brad Figg <brad.figg@canonical.com>
Subject: [26/26] net: fix rds_iovec page count overflow
Date: Tue, 19 Apr 2011 14:02:42 -0700 [thread overview]
Message-ID: <20110419210325.008446775@clark.kroah.org> (raw)
In-Reply-To: <20110419210333.GA17417@kroah.com>
2.6.33-longterm review patch. If anyone has any objections, please let us know.
------------------
From: Linus Torvalds <torvalds@linux-foundation.org>
commit 1b1f693d7ad6d193862dcb1118540a030c5e761f upstream.
As reported by Thomas Pollet, the rdma page counting can overflow. We
get the rdma sizes in 64-bit unsigned entities, but then limit it to
UINT_MAX bytes and shift them down to pages (so with a possible "+1" for
an unaligned address).
So each individual page count fits comfortably in an 'unsigned int' (not
even close to overflowing into signed), but as they are added up, they
might end up resulting in a signed return value. Which would be wrong.
Catch the case of tot_pages turning negative, and return the appropriate
error code.
Reported-by: Thomas Pollet <thomas.pollet@gmail.com>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
Signed-off-by: Andy Grover <andy.grover@oracle.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
[v2: nr is unsigned in the old code]
Signed-off-by: Stefan Bader <stefan.bader@canonical.com>
Acked-by: Tim Gardner <tim.gardner@canonical.com>
Acked-by: Brad Figg <brad.figg@canonical.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@suse.de>
---
net/rds/rdma.c | 11 +++++++++++
1 file changed, 11 insertions(+)
--- a/net/rds/rdma.c
+++ b/net/rds/rdma.c
@@ -497,6 +497,17 @@ static struct rds_rdma_op *rds_rdma_prep
max_pages = max(nr, max_pages);
nr_pages += nr;
+
+ /*
+ * nr for one entry in limited to (UINT_MAX>>PAGE_SHIFT)+1
+ * so nr_pages cannot overflow without becoming bigger than
+ * INT_MAX first. If nr cannot overflow then max_pages should
+ * be ok.
+ */
+ if (nr_pages > INT_MAX) {
+ ret = -EINVAL;
+ goto out;
+ }
}
pages = kcalloc(max_pages, sizeof(struct page *), GFP_KERNEL);
prev parent reply other threads:[~2011-04-19 21:04 UTC|newest]
Thread overview: 27+ messages / expand[flat|nested] mbox.gz Atom feed top
2011-04-19 21:03 [00/26] 2.6.33.12-longterm review Greg KH
2011-04-19 21:02 ` [01/26] cifs: always do is_path_accessible check in cifs_mount Greg KH
2011-04-19 21:02 ` [02/26] [media] video: sn9c102: world-wirtable sysfs files Greg KH
2011-04-19 21:02 ` [03/26] UBIFS: restrict world-writable debugfs files Greg KH
2011-04-19 21:02 ` [04/26] NET: cdc-phonet, handle empty phonet header Greg KH
2011-04-19 21:02 ` [05/26] x86: Fix a bogus unwind annotation in lib/semaphore_32.S Greg KH
2011-04-19 21:02 ` [06/26] [IA64] tioca: Fix assignment from incompatible pointer warnings Greg KH
2011-04-19 21:02 ` [07/26] [IA64] mca.c: Fix cast from integer to pointer warning Greg KH
2011-04-19 21:02 ` [08/26] ramfs: fix memleak on no-mmu arch Greg KH
2011-04-19 21:02 ` [09/26] MAINTAINERS: update STABLE BRANCH info Greg KH
2011-04-19 21:02 ` [10/26] UBIFS: fix oops when R/O file-system is fsynced Greg KH
2011-04-19 21:02 ` [11/26] x86, AMD: Set ARAT feature on AMD processors Greg KH
2011-04-19 21:02 ` [12/26] x86, cpu: AMD errata checking framework Greg KH
2011-04-19 21:02 ` [13/26] x86, cpu: Clean up AMD erratum 400 workaround Greg KH
2011-04-19 21:02 ` [14/26] x86, amd: Disable GartTlbWlkErr when BIOS forgets it Greg KH
2011-04-19 21:02 ` [15/26] USB: ftdi_sio: Added IDs for CTI USB Serial Devices Greg KH
2011-04-19 21:02 ` [16/26] USB: ftdi_sio: add PID for OCT DK201 docking station Greg KH
2011-04-19 21:02 ` [17/26] USB: ftdi_sio: add ids for Hameg HO720 and HO730 Greg KH
2011-04-19 21:02 ` [18/26] next_pidmap: fix overflow condition Greg KH
2011-04-19 21:02 ` [19/26] proc: do proper range check on readdir offset Greg KH
2011-04-19 21:02 ` [20/26] USB: EHCI: unlink unused QHs when the controller is stopped Greg KH
2011-04-19 21:02 ` [21/26] USB: fix formatting of SuperSpeed endpoints in /proc/bus/usb/devices Greg KH
2011-04-19 21:02 ` [22/26] USB: xhci - fix unsafe macro definitions Greg KH
2011-04-19 21:02 ` [23/26] USB: xhci - fix math in xhci_get_endpoint_interval() Greg KH
2011-04-19 21:02 ` [24/26] x86, cpu: Fix regression in AMD errata checking code Greg KH
2011-04-19 21:02 ` [25/26] net: ax25: fix information leak to userland harder Greg KH
2011-04-19 21:02 ` Greg KH [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20110419210325.008446775@clark.kroah.org \
--to=gregkh@suse.de \
--cc=akpm@linux-foundation.org \
--cc=alan@lxorguk.ukuu.org.uk \
--cc=andy.grover@oracle.com \
--cc=brad.figg@canonical.com \
--cc=davem@davemloft.net \
--cc=linux-kernel@vger.kernel.org \
--cc=stable-review@kernel.org \
--cc=stable@kernel.org \
--cc=stefan.bader@canonical.com \
--cc=tim.gardner@canonical.com \
--cc=torvalds@linux-foundation.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®