From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-qv1-f46.google.com (mail-qv1-f46.google.com [209.85.219.46]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 6D11F383C8F for ; Sun, 14 Jun 2026 13:06:29 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.219.46 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1781442390; cv=none; b=Y+nN8MWJBNF1LOprisc3kQAmWc+wHHNntr1d9KLGFtqWUEuUK9xIL82uGg/zlzU7mlWBQSeB7jEYm0+zA+Yy8QihpdjUr+MbweuLsCI1Bdimj20uhwvNPjoyt2+H4RQY1brvafj1pwpFPqQHVavbYdwEpvXNsivScjvhsT9puPY= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1781442390; c=relaxed/simple; bh=nKb+W2wmLqLuHK9GreXOyec5jACQecKb+WCn9wI9HhA=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=qLn60ryfjhW8MXVz/eKHRsA+qT75QitR1EbHKdVDYytYDprigu+iUN0N372QcTxiGkUQVWWlE6gFropWI+FlzaElBD3g7SczNlfR6paDQ3A4Sr/owqzK0wmiajDiRlhbPjAuqcHF6FZgYbCnfvmoS+h10A3NiDN96E2taarp000= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=fvQ/mhW6; arc=none smtp.client-ip=209.85.219.46 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="fvQ/mhW6" Received: by mail-qv1-f46.google.com with SMTP id 6a1803df08f44-8d18de80b29so34990546d6.1 for ; Sun, 14 Jun 2026 06:06:29 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1781442388; x=1782047188; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to; bh=hjXLO5H1+5ds8HPQ/tLoLCzBushFbkoltn8TPIfOX1c=; b=fvQ/mhW6nFjRZdyqv8JHXQy0hCwPVwJMs3A0GDp0CeWb5MR2BvJKh3F4WN5p2IryWk HmNyeAZj9d37U1qqrjFPr8Lj/hsmpXarpwASjGKVA6bXtQk29b8EhRNQOFPZmFogIZ7M ir3SunPfGUnKF2O83V45RAk7RRcQJ9xkjULKW0dBDPTCJ8uY/xhZ/sHRyrz/FMoWABRM cgqCoox8+oXnYjJp4R3BJAW2E6YLFNyvMDd+sxJ+xuqXfmZmUcDeI4lmJzFtKmnXU59T CxwEQ2mVl8KmGwoaRf2Y3MZScafBa1r13Fl26cV17ToKcKs8Tq9EXN/splufPb9ztnfy ncLQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1781442388; x=1782047188; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to; bh=hjXLO5H1+5ds8HPQ/tLoLCzBushFbkoltn8TPIfOX1c=; b=cvHJZ5neHmuJQv3V+8Wvm6Ltd7oLoNcg19XEnZVoE7v0BULxgMWYYrzHGX8ftgyrND sQqOEdicabWf3W4AwiB96SjbIGUhdboggBKml8sdONg8ZmbTGXijuEWhf0nsWb6u8vFP orOz/oJy4XB363OEfPpe+12c67S0iBbHzOsM0s/IBDFtPEumv85hA63b0jPHzPTIwQ2M roEcud704g5cDMLvzSmZeh3ZFdIisneB9xzgRRROz5zLPMf2Js/Q0cOL0MK8QG0H+BEp RBCet9edZXcVF7GQkbF9w/5oBOl/6ZAndxuvYY+INagJGDCSuv2dx/lPZoYgXrptWxY5 hFIQ== X-Forwarded-Encrypted: i=1; AFNElJ+WW5SujWdkYRDvRFaYmLW7hds1WJYJ0B034zXSttS0I8UPe2wh0TxDHgwKLxRb7cR8LVwCGmRmG17xzdc=@vger.kernel.org X-Gm-Message-State: AOJu0YxLD61qSxgM6MGvbZMy1FKZSbobMPRfMXkvyH3iG6tVjFWQTRYy 2aPGor+gucWEid5HZ5Y3D6wqP/mxq2+rbIu3AIaLjoS3EFjff5YQJzG/ X-Gm-Gg: Acq92OEnimqaoVvgdop1faTW2zcjKWEDcB/Mo32izDD40KZxF4yGQbtIy6bePooNYkP JPBoaUtTLKbTgXldWIW8Yd0zXzYcXD34/Rsm17FoVjhnu/22WuusCTn65GCCfBaiQoWAWCo/7xb tDWEIHgbm67MVyZu+/SiK0xp08DTJV7U4D/zHICxI8wD3EdCL9vUpch0JsJHoUCZn0Z2hAX0zLo B7JaRn+7IuNVTufAPJ5s5Kl8Auxcjm88mLmZLCIkh74d/bteqD6VgjJpCLJjT833OWxQ/rouCvD 0Gs8yLnWRJoxzJwOPj7QrWY2Ah0KpOnXGPObdqgWQxz8K/OzTZlcZuFv7yCcir3vuSuxUXfEB2D lXd7Ly2EOoysPwVEDjvhJBlSo9VtmcT366JDXQOrXjP2l+ob/CTg4FOQIbMU9iOfKk+CaGS4V5M YBCJPGMoNHTIu/E1ClJjs1wGof62uVVfzQWHZuAbyNzgyX1k3LIARpHmzzLrRAB295E8YOlIQG3 OuvhdQVLSQC4Pj44hKwtJYZuH1ZqaaA36PvvJzUJTM= X-Received: by 2002:a05:6214:5f83:b0:8ac:a91c:c99 with SMTP id 6a1803df08f44-8d317b453c6mr134108656d6.29.1781442388310; Sun, 14 Jun 2026 06:06:28 -0700 (PDT) Received: from server0.tail6e7dd.ts.net (c-68-48-65-54.hsd1.mi.comcast.net. [68.48.65.54]) by smtp.gmail.com with ESMTPSA id 6a1803df08f44-8d301a32d5csm77937106d6.12.2026.06.14.06.06.27 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 14 Jun 2026 06:06:27 -0700 (PDT) From: Michael Bommarito To: Giovanni Cabiddu , Herbert Xu Cc: "David S . Miller" , Kees Cook , qat-linux@intel.com, linux-crypto@vger.kernel.org, linux-kernel@vger.kernel.org Subject: [PATCH 0/2] crypto: qat - bound the live migration import parser Date: Sun, 14 Jun 2026 09:06:17 -0400 Message-ID: <20260614130619.2519534-1-michael.bommarito@gmail.com> X-Mailer: git-send-email 2.53.0 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 7bit adf_mstate_mgr_init_from_remote() sets the section-walk cursor to mgr->buf + preh_len from a remote-supplied preh_len, and the default preamble checker only rejects preh_len > mgr->size. A remote preamble with preh_len == mgr->size moves the cursor one region past the allocation while n_sects is still honoured, so adf_mstate_sect_validate() reads sect->size before the section header is proven in bounds. The remote stream reaches this parser from the destination-host VFIO migration path (qat_vf_resume_write), so a malformed import reads out of bounds in the destination host kernel (fatal under KASAN / panic_on_warn). Patch 1 rejects section headers not fully contained in the state buffer. Patch 2 adds KUnit coverage and is offered separately so it can be taken or dropped on its own. The parser was driven on QEMU x86_64 under KASAN via the patch 2 suite (Level-2: buggy code unchanged, surrounding VFIO/PF environment synthesized); the boundary trigger reports the out-of-bounds read on the unfixed parser and is gone after patch 1, with two benign controls passing on both trees. Michael Bommarito (2): crypto: qat - validate migration section header is in bounds crypto: qat - add KUnit coverage for the migration import parser drivers/crypto/intel/qat/Kconfig | 16 ++++ .../intel/qat/qat_common/adf_mstate_mgr.c | 18 ++++- .../qat/qat_common/adf_mstate_mgr_test.c | 81 +++++++++++++++++++ 3 files changed, 113 insertions(+), 2 deletions(-) create mode 100644 drivers/crypto/intel/qat/qat_common/adf_mstate_mgr_test.c -- 2.53.0