* re: vduse: add vq group support
@ 2025-09-27 14:21 Colin King (gmail)
2025-09-29 6:07 ` Eugenio Perez Martin
0 siblings, 1 reply; 2+ messages in thread
From: Colin King (gmail) @ 2025-09-27 14:21 UTC (permalink / raw)
To: Eugenio Pérez, Michael S. Tsirkin, Jason Wang,
virtualization, kvm, netdev
Cc: linux-kernel
[-- Attachment #1.1.1: Type: text/plain, Size: 1205 bytes --]
Hi,
Static analysis on linux-next has found an issue with the following commit:
commit ffc3634b66967445f3368c3b53a42bccc52b2c7f
Author: Eugenio Pérez <eperezma@redhat.com>
Date: Thu Sep 25 11:13:32 2025 +0200
vduse: add vq group support
This issue is as follows in function vhost_vdpa_vring_ioct:
case VHOST_VDPA_GET_VRING_GROUP: {
u64 group;
if (!ops->get_vq_group)
return -EOPNOTSUPP;
s.index = idx;
group = ops->get_vq_group(vdpa, idx);
if (group >= vdpa->ngroups || group > U32_MAX || group < 0)
return -EIO;
else if (copy_to_user(argp, &s, sizeof(s)))
return -EFAULT;
s.num = group;
return 0;
}
The copy_to_user of struct s is copying a partially initialized struct
s, field s.num contains garbage data from the stack and this is being
copied back to user space. Field s.num should be assigned some value
before the copy_to_user call to avoid uninitialized data from the stack
being leaked to user space.
Colin
[-- Attachment #1.1.2: OpenPGP public key --]
[-- Type: application/pgp-keys, Size: 4901 bytes --]
[-- Attachment #2: OpenPGP digital signature --]
[-- Type: application/pgp-signature, Size: 840 bytes --]
^ permalink raw reply [flat|nested] 2+ messages in thread
* Re: vduse: add vq group support
2025-09-27 14:21 vduse: add vq group support Colin King (gmail)
@ 2025-09-29 6:07 ` Eugenio Perez Martin
0 siblings, 0 replies; 2+ messages in thread
From: Eugenio Perez Martin @ 2025-09-29 6:07 UTC (permalink / raw)
To: Colin King (gmail)
Cc: Michael S. Tsirkin, Jason Wang, virtualization, kvm, netdev,
linux-kernel
On Sat, Sep 27, 2025 at 4:22 PM Colin King (gmail)
<colin.i.king@gmail.com> wrote:
>
> Hi,
>
> Static analysis on linux-next has found an issue with the following commit:
>
> commit ffc3634b66967445f3368c3b53a42bccc52b2c7f
> Author: Eugenio Pérez <eperezma@redhat.com>
> Date: Thu Sep 25 11:13:32 2025 +0200
>
> vduse: add vq group support
>
>
> This issue is as follows in function vhost_vdpa_vring_ioct:
>
> case VHOST_VDPA_GET_VRING_GROUP: {
> u64 group;
>
> if (!ops->get_vq_group)
> return -EOPNOTSUPP;
> s.index = idx;
> group = ops->get_vq_group(vdpa, idx);
> if (group >= vdpa->ngroups || group > U32_MAX || group < 0)
> return -EIO;
> else if (copy_to_user(argp, &s, sizeof(s)))
> return -EFAULT;
> s.num = group;
> return 0;
> }
>
>
> The copy_to_user of struct s is copying a partially initialized struct
> s, field s.num contains garbage data from the stack and this is being
> copied back to user space. Field s.num should be assigned some value
> before the copy_to_user call to avoid uninitialized data from the stack
> being leaked to user space.
>
That's right! v5 of the patch fixes the issue.
Thanks!
^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2025-09-29 6:07 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2025-09-27 14:21 vduse: add vq group support Colin King (gmail)
2025-09-29 6:07 ` Eugenio Perez Martin
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®