From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-yw1-f180.google.com (mail-yw1-f180.google.com [209.85.128.180]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id B870A3C4B9A for ; Fri, 26 Jun 2026 22:38:28 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.128.180 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1782513510; cv=none; b=dahwQOztZilGl4AtoLsnTSmi9zuZwedx2BL6s38vYNij5vm0+DyujSIhrlZxP8hcIzj/rcTCBAwrPA1OR3WoDekOpGY3Ps7kgzUOmIm3H/RH3rNhBvWj6PhysMf4NGyGSGiwHPCp+yXX0oSgdKiNbqMRIIP2RrO4j2TxEXqOWMc= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1782513510; c=relaxed/simple; bh=ghy78NVBgjcBIYIGbczgClWj/BE51nB233XQWn5smo0=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=CXBrJgstyVmVK7dDIBF17SXbzinJhgOvv49w5eCT+J7c16/kPHQ1Yrj8tQA5c8ncCKJW+6qpCyHk1MxYLmOlb8KCg0vyH3i8A4b6vblIWuyxdoHCTJZ2nysqz3Jpiw6sq77gsL1QNAjz1WjMcEPM53ybq4JixkepluXo45gnJeI= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=e2hoChd4; arc=none smtp.client-ip=209.85.128.180 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="e2hoChd4" Received: by mail-yw1-f180.google.com with SMTP id 00721157ae682-804e46366d7so16953057b3.2 for ; Fri, 26 Jun 2026 15:38:28 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1782513508; x=1783118308; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to; bh=CI5He4iihLUJokMNvGv1uiqx/8mjJsZ4EoloRA/RmsI=; b=e2hoChd4bIwQknIX8NGKoQPMJ7YdbDgc/VwJ9PiZD1bYhuxGT+f2n1AZobuziZUB6r BOSQ9cCG1A1Pc9ABlX1x7Y5zr5uuwaTFiVaVKzpi6PhgKE6zGb6w7D0fr0vDN2FnWLCf ne5LZmg2Eo3SKWz9TVd+zSTxsSQ+4bDUPFIDZxRVeuhAiwUULei/yH5FNhGjVf3JAKLV BE/wGwn/S0gyuPQUBrWcCo6MLFN+k9EFfoRigk5sWGsviRtM/qfSmvQfLts/vt3rwi1Z opA/16AZkF0WFpBCWS5n1Q/CzBe2MlGwPhFLuFuy/eRrtAyeNKC1XwVW/fRKv909VQw+ xj2Q== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1782513508; x=1783118308; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to; bh=CI5He4iihLUJokMNvGv1uiqx/8mjJsZ4EoloRA/RmsI=; b=U4+hdslsUkqftY4Ld31w5NmFwMd6e6cDJjzn9xUu39RRrGbYRWX3oKSiGTFZqTofso wzlJ0LZkfZnY5V+E2aLFJQ4uGsO7IlwsM7g3vgqYQvd3SWWDdQLopoUN1LElhQd2+lUL lXXl4iMcIX/xQoBS6kRkMLbI/h/UpXokvIyhSwLQ6ABU9tlphqY+faeMdpsnWUfyTGfn zf6E4lpuomnS1W3F7oX+bSbbdNX+LjlcH6vfNyFBJRcRXb9Sqa0lPh00nuhThO1SIaB5 wFjNsaSpe4LV2HQ8vjZqWBCU6qp0vdmG7+fHWxi9HZjZ5xcAspyUYgcL0WHcItt9TGJo BCGg== X-Forwarded-Encrypted: i=1; AHgh+RqVdcPeCC+r0FOL8UcPwymMBmnKxwdY199JajHsfIZHaQFj6tFUA4N29152C0VUiPwIAaM8a5/VzwzU8+c=@vger.kernel.org X-Gm-Message-State: AOJu0YzFcZh0iblK4RYhUY3Yy8t+1/rcZ+cnBInurkKtUByK+nuPzMm5 kBVKKHOHYNhfauQg4jdNCqIO7ODwy3nXioT6Aouho24oS6GOO1npwNV2 X-Gm-Gg: AfdE7clMYmaewX7Bv6KOhLC9iGS+0cUDL4wacstOHFk0l6IQPI9uuJf3QGYJyJKsLLe 0WTIWNBOj0dA9xVHfQSxYdXX+JIGD1Ia/8a3fpglrb4wDuqptDFfx7fjriPAYzNcVPeMZrzoK3M nMXvSrk4SFD3ThoQTBp2VNemJZsw6EAWmsxAParLKJpydhl0jm4qowF1g+wnuT2GMP0aR/3T0OV gCYShz1ob725VsLIJsUGnIX9YYckKINfAJg0rapJW/EVIuGkQ9RGqCoNb6tRqdNfQomOC1MBHIX pNXw5QTg3WJeG9MGTl9ytsX6FH8Sg8EwvLqRKxKyLR/7sjJkX3o7d+ZvsISt9Esi7a7ZYlkb18C 7EVDfyPO+d94YZD2qv6UVEFCuyY6QEZn9NhVHncXWj5H7MJNIViFdNyNQKGEOxoYIoa56r5abrq vF1mEHifFcBkAzB9i6X4VX6lF6QaKuKA9xZT+E X-Received: by 2002:a05:690c:d8d:b0:7bd:5af9:f0a2 with SMTP id 00721157ae682-80a691c3383mr84757587b3.14.1782513507711; Fri, 26 Jun 2026 15:38:27 -0700 (PDT) Received: from Dev-Null-MSI ([2a0d:3344:52ac:a808:98a4:4381:be45:536f]) by smtp.gmail.com with ESMTPSA id 00721157ae682-80abc3d1734sm23177557b3.15.2026.06.26.15.38.25 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 26 Jun 2026 15:38:27 -0700 (PDT) From: Yousef Alhouseen To: Juergen Gross , Stefano Stabellini , Oleksandr Tyshchenko Cc: xen-devel@lists.xenproject.org, linux-kernel@vger.kernel.org, Yousef Alhouseen Subject: [PATCH v2 2/2] xen/gntalloc: validate grant count before allocation Date: Sat, 27 Jun 2026 00:38:05 +0200 Message-ID: <20260626223805.43781-3-alhouseenyousef@gmail.com> X-Mailer: git-send-email 2.54.0 In-Reply-To: <20260626223805.43781-1-alhouseenyousef@gmail.com> References: <20260624124745.10073-1-alhouseenyousef@gmail.com> <20260626223805.43781-1-alhouseenyousef@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit gntalloc_ioctl_alloc() allocates the grant-id array before checking whether the requested count fits within the global grant limit. Counts above that limit cannot succeed, so reject them before the user-controlled allocation reaches kcalloc(). Use a subtraction-based check while holding gref_mutex so adding the requested count cannot wrap. Also cast the count before advancing the per-file index so the page-size multiplication is performed in 64-bit arithmetic. Signed-off-by: Yousef Alhouseen --- drivers/xen/gntalloc.c | 13 +++++++++++-- 1 file changed, 11 insertions(+), 2 deletions(-) diff --git a/drivers/xen/gntalloc.c b/drivers/xen/gntalloc.c index 9279f1521..3218686be 100644 --- a/drivers/xen/gntalloc.c +++ b/drivers/xen/gntalloc.c @@ -272,6 +272,7 @@ static long gntalloc_ioctl_alloc(struct gntalloc_file_private_data *priv, int rc = 0; struct ioctl_gntalloc_alloc_gref op; uint32_t *gref_ids; + unsigned int limit_snapshot; pr_debug("%s: priv %p\n", __func__, priv); @@ -280,6 +281,12 @@ static long gntalloc_ioctl_alloc(struct gntalloc_file_private_data *priv, goto out; } + limit_snapshot = READ_ONCE(limit); + if (op.count > limit_snapshot) { + rc = -ENOSPC; + goto out; + } + gref_ids = kcalloc(op.count, sizeof(gref_ids[0]), GFP_KERNEL); if (!gref_ids) { rc = -ENOMEM; @@ -292,14 +299,16 @@ static long gntalloc_ioctl_alloc(struct gntalloc_file_private_data *priv, * are about to enforce, removing them here is a good idea. */ do_cleanup(); - if (gref_size + op.count > limit) { + limit_snapshot = READ_ONCE(limit); + if (gref_size > limit_snapshot || + op.count > limit_snapshot - gref_size) { mutex_unlock(&gref_mutex); rc = -ENOSPC; goto out_free; } gref_size += op.count; op.index = priv->index; - priv->index += op.count * PAGE_SIZE; + priv->index += (uint64_t)op.count * PAGE_SIZE; mutex_unlock(&gref_mutex); rc = add_grefs(&op, gref_ids, priv); -- 2.54.0