mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH net] RDS/IB: validate receive completion payload length
@ 2026-10-06 20:52 sungbyeongchan
  2026-10-06 20:55 ` netdev-bot+sinfo
  2026-10-07  1:13 ` Allison Henderson
  0 siblings, 2 replies; 3+ messages in thread
From: sungbyeongchan @ 2026-10-06 20:52 UTC (permalink / raw)
  To: Allison Henderson, David S . Miller, Eric Dumazet,
	Jakub Kicinski, Paolo Abeni, Simon Horman, Andy Grover
  Cc: netdev, linux-rdma, rds-devel, linux-kernel

An RDS/RDMA peer can declare a fragment length larger than the payload
reported by the receive completion. The receive path attaches the recycled
receive fragment without validating those lengths, allowing recvmsg() to
return stale bytes beyond the actual payload.

Validate data_len against the expected current-fragment length before
transferring fragment ownership. Disconnect and reconnect on mismatch.

The issue reproduced in two clean QEMU boots. A peer declared 4096 bytes
while posting only 16 bytes, and a receiver under a different UID obtained
4080-byte tails from prior messages in all 256 attempts in each boot. With
this change, the malformed message was not delivered, reconnection
succeeded, and a subsequent normal 4096-byte message was delivered intact.

Fixes: 1e23b3ee0e94 ("RDS/IB: Receive datagrams via IB")
Cc: stable@vger.kernel.org
Assisted-by: LLM
Signed-off-by: sungbyeongchan <tjdqudcks0424@naver.com>
---
 net/rds/ib_recv.c | 9 +++++++++
 1 file changed, 9 insertions(+)

diff --git a/net/rds/ib_recv.c b/net/rds/ib_recv.c
index bd6cb3ffaa571..0daddb108c8a7 100644
--- a/net/rds/ib_recv.c
+++ b/net/rds/ib_recv.c
@@ -949,6 +949,15 @@ static void rds_ib_process_recv(struct rds_connection *conn,
 		}
 	}
 
+	if (data_len != min_t(u32, ic->i_recv_data_rem, RDS_FRAG_SIZE)) {
+		rds_ib_conn_error(conn,
+				  "incoming fragment payload length %u, expected %u; "
+				  "disconnecting and reconnecting\n",
+				  data_len,
+				  min_t(u32, ic->i_recv_data_rem, RDS_FRAG_SIZE));
+		goto done;
+	}
+
 	list_add_tail(&recv->r_frag->f_item, &ibinc->ii_frags);
 	recv->r_frag = NULL;
 
-- 
2.43.0


^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2026-10-07  1:13 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-10-06 20:52 [PATCH net] RDS/IB: validate receive completion payload length sungbyeongchan
2026-10-06 20:55 ` netdev-bot+sinfo
2026-10-07  1:13 ` Allison Henderson

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®