From: Juergen Gross <jgross@suse.com>
To: Yehyeong Lee <yhlee@isslab.korea.ac.kr>,
Eric Van Hensbergen <ericvh@kernel.org>,
Latchesar Ionkov <lucho@ionkov.net>,
Dominique Martinet <asmadeus@codewreck.org>,
Christian Schoenebeck <linux_oss@crudebyte.com>,
Stefano Stabellini <sstabellini@kernel.org>,
Boris Ostrovsky <boris.ostrovsky@oracle.com>,
v9fs@lists.linux.dev, linux-kernel@vger.kernel.org
Cc: stable@vger.kernel.org
Subject: Re: [PATCH v2] 9p/xen: validate the response size from the backend
Date: Thu, 8 Oct 2026 13:40:07 +0200 [thread overview]
Message-ID: <bd207068-5674-4ffa-aa34-57b07b2bcffa@suse.com> (raw)
In-Reply-To: <20261005125640.274054-1-yhlee@isslab.korea.ac.kr>
[-- Attachment #1.1.1: Type: text/plain, Size: 2679 bytes --]
On 05.10.26 14:56, Yehyeong Lee wrote:
> p9_xen_response() takes the length of an incoming response from the ring
> -- the first field of the 9p header, which the Xen transport reuses as
> its framing header -- and uses it to advance the consumer index, but
> never checks that it is at least the header size or no larger than the
> number of bytes the backend has actually produced.
>
> A malicious or buggy backend can post a response whose size is smaller
> than the header (for example 0). The consumer index then never advances,
> so the response work re-reads the same ring contents instead of making
> progress. In testing this raced with the teardown that the malformed
> reply triggers and dereferenced a freed p9_client:
>
> 9pfs 9pfs-0: Wrong req tag=ffff
> BUG: kernel NULL pointer dereference, address: 0000000000000060
> #PF: supervisor read access in kernel mode
> #PF: error_code(0x0000) - not-present page
> PGD 0 P4D 0
> Oops: Oops: 0000 [#1] SMP NOPTI
> CPU: 0 UID: 0 PID: 11 Comm: kworker/0:1 Not tainted 7.2.0-rc5 #6 PREEMPT(lazy)
> Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS rel-1.17.0-0-gb52ca86e094d-prebuilt.qemu.org 04/01/2014
> Workqueue: events p9_xen_response
> RIP: 0010:idr_find+0x4/0x10
> RSP: 0018:ffffbf5d80063de8 EFLAGS: 00010202
> RAX: 0000000000000001 RBX: ffffa229c21195a0 RCX: ffffa229c2400000
> RDX: ffffa229c11c2200 RSI: 000000000000ffff RDI: 0000000000000050
> RBP: 000000000000ffff R08: 3fffffffffffdfff R09: ffffffffffffffff
> R10: 3fffffffffffdfff R11: ffffffff87a60e80 R12: 0000000000000050
> R13: 0000000000000000 R14: 000000000000ffff R15: 0000000000100000
> FS: 0000000000000000(0000) GS:ffffa22a7661c000(0000) knlGS:0000000000000000
> CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
> CR2: 0000000000000060 CR3: 000000003ac34002 CR4: 0000000000770ef0
> PKRU: 55555554
> Call Trace:
> <TASK>
> p9_tag_lookup+0x2b/0x90
> p9_xen_response+0x17c/0x2e0
> process_one_work+0x16a/0x3a0
> worker_thread+0x172/0x2e0
> kthread+0xdd/0x110
> ret_from_fork+0x18b/0x240
> ret_from_fork_asm+0x1a/0x30
> </TASK>
> Modules linked in:
> CR2: 0000000000000060
> ---[ end trace 0000000000000000 ]---
>
> Reject a response whose size is outside [sizeof(header), queued] before
> using it, matching the validation the backend already applies to
> incoming requests.
>
> Fixes: f66c72bea129 ("xen/9pfs: receive responses")
> Cc: stable@vger.kernel.org
> Signed-off-by: Yehyeong Lee <yhlee@isslab.korea.ac.kr>
Reviewed-by: Juergen Gross <jgross@suse.com>
Juergen
[-- Attachment #1.1.2: OpenPGP public key --]
[-- Type: application/pgp-keys, Size: 3743 bytes --]
[-- Attachment #2: OpenPGP digital signature --]
[-- Type: application/pgp-signature, Size: 495 bytes --]
prev parent reply other threads:[~2026-10-08 11:40 UTC|newest]
Thread overview: 2+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-05 12:56 Yehyeong Lee
2026-10-08 11:40 ` Juergen Gross [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=bd207068-5674-4ffa-aa34-57b07b2bcffa@suse.com \
--to=jgross@suse.com \
--cc=asmadeus@codewreck.org \
--cc=boris.ostrovsky@oracle.com \
--cc=ericvh@kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux_oss@crudebyte.com \
--cc=lucho@ionkov.net \
--cc=sstabellini@kernel.org \
--cc=stable@vger.kernel.org \
--cc=v9fs@lists.linux.dev \
--cc=yhlee@isslab.korea.ac.kr \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®