* [PATCH v2] RDMA/rxe: Use validated num_sge in local buffer
@ 2026-09-09 16:01 Nicolas Morey
2026-09-14 12:10 ` Leon Romanovsky
0 siblings, 1 reply; 2+ messages in thread
From: Nicolas Morey @ 2026-09-09 16:01 UTC (permalink / raw)
To: Zhu Yanjun, Jason Gunthorpe, Leon Romanovsky, Tristan Madani,
open list:SOFT-ROCE DRIVER (rxe),
open list
Cc: Nicolas Morey, Zhu Yanjun
For both SRQ and non-SRQ receive paths, the WQE is copied into a local
buffer to provide a kernel-owned, validated copy. While calculating the
memcpy size from the validated num_sge prevents overflow during the
copy, memcpy() itself still copies num_sge from shared memory.
A concurrent userspace modification before or during memcpy() leaves
an unvalidated num_sge in the local buffer, leading to potential
out-of-bounds reads in rxe_resp_check_length() and copy_data() causing:
BUG: KASAN: slab-out-of-bounds in rxe_receiver+0x8109/0x9ec0 [rdma_rxe]
Read of size 4 at addr ffff88812c4867f8 by task kworker/u9:6/361
Workqueue: rxe_wq do_work [rdma_rxe]
Call Trace:
rxe_receiver+0x8109/0x9ec0 [rdma_rxe]
do_work+0x149/0x610 [rdma_rxe]
process_one_work+0x726/0x10a0
The buggy address belongs to the object at ffff88812c486000
which belongs to the cache kmalloc-part-13-2k of size 2048
The buggy address is located 0 bytes to the right of
allocated 2040-byte region [ffff88812c486000, ffff88812c4867f8)
Explicitly assign the validated num_sge to the local buffer after the
copy to prevent this race.
Fixes: 22b8fbded65b ("RDMA/rxe: Fix TOCTOU heap overflow in get_srq_wqe")
Fixes: d6ab440240a0 ("RDMA/rxe: Copy WQE to local buffer in non-SRQ receive path")
Reviewed-by: Zhu Yanjun <yanjun.zhu@linux.dev>
Signed-off-by: Nicolas Morey <nmorey@suse.com>
---
v1 -> v2:
- Added KASAN call trace to the commit log
- Collected Reviewed-by tag.
drivers/infiniband/sw/rxe/rxe_resp.c | 2 ++
1 file changed, 2 insertions(+)
diff --git a/drivers/infiniband/sw/rxe/rxe_resp.c b/drivers/infiniband/sw/rxe/rxe_resp.c
index 02b16e2b49b8..cd51042857d6 100644
--- a/drivers/infiniband/sw/rxe/rxe_resp.c
+++ b/drivers/infiniband/sw/rxe/rxe_resp.c
@@ -288,6 +288,7 @@ static enum resp_states get_srq_wqe(struct rxe_qp *qp)
}
size = sizeof(*wqe) + num_sge * sizeof(struct rxe_sge);
memcpy(&qp->resp.srq_wqe, wqe, size);
+ qp->resp.srq_wqe.wqe.dma.num_sge = num_sge;
qp->resp.wqe = &qp->resp.srq_wqe.wqe;
queue_advance_consumer(q, QUEUE_TYPE_FROM_CLIENT);
@@ -328,6 +329,7 @@ static enum resp_states rxe_get_recv_wqe(struct rxe_qp *qp)
}
size = sizeof(*wqe) + num_sge * sizeof(struct rxe_sge);
memcpy(&qp->resp.srq_wqe, wqe, size);
+ qp->resp.srq_wqe.wqe.dma.num_sge = num_sge;
qp->resp.wqe = &qp->resp.srq_wqe.wqe;
return RESPST_CHK_LENGTH;
--
2.54.0
^ permalink raw reply [flat|nested] 2+ messages in thread
* Re: [PATCH v2] RDMA/rxe: Use validated num_sge in local buffer
2026-09-09 16:01 [PATCH v2] RDMA/rxe: Use validated num_sge in local buffer Nicolas Morey
@ 2026-09-14 12:10 ` Leon Romanovsky
0 siblings, 0 replies; 2+ messages in thread
From: Leon Romanovsky @ 2026-09-14 12:10 UTC (permalink / raw)
To: Zhu Yanjun, Jason Gunthorpe, Tristan Madani, linux-rdma,
linux-kernel, Nicolas Morey
Cc: Zhu Yanjun
On Wed, 09 Sep 2026 18:01:31 +0200, Nicolas Morey wrote:
> For both SRQ and non-SRQ receive paths, the WQE is copied into a local
> buffer to provide a kernel-owned, validated copy. While calculating the
> memcpy size from the validated num_sge prevents overflow during the
> copy, memcpy() itself still copies num_sge from shared memory.
>
> A concurrent userspace modification before or during memcpy() leaves
> an unvalidated num_sge in the local buffer, leading to potential
> out-of-bounds reads in rxe_resp_check_length() and copy_data() causing:
>
> [...]
Applied, thanks!
[1/1] RDMA/rxe: Use validated num_sge in local buffer
https://git.kernel.org/rdma/rdma/c/112f2b6925c2d7
Best regards,
--
Leon Romanovsky <leon@kernel.org>
^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2026-09-14 12:10 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-09-09 16:01 [PATCH v2] RDMA/rxe: Use validated num_sge in local buffer Nicolas Morey
2026-09-14 12:10 ` Leon Romanovsky
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®