From: cdall@cs.columbia.edu (Christoffer Dall)
To: linux-arm-kernel@lists.infradead.org
Subject: [PATCH] ARM: KVM: prevent NULL pointer dereference with KVM ioctl
Date: Sun, 12 May 2013 22:13:52 -0700 [thread overview]
Message-ID: <20130513051352.GA64337@ubuntu> (raw)
In-Reply-To: <518A2098.9010909@arm.com>
On Wed, May 08, 2013 at 10:53:28AM +0100, Marc Zyngier wrote:
> On 07/05/13 13:55, Andre Przywara wrote:
> > Some ARM KVM VCPU ioctls require the vCPU to be properly initialized
> > with the KVM_ARM_VCPU_INIT ioctl before being used with further
> > requests. KVM_RUN checks whether this initialization has been
> > done, but other ioctls do not.
> > Namely KVM_GET_REG_LIST will dereference an array with index -1
> > without initialization and thus leads to a kernel oops.
> > Fix this by adding checks before executing the ioctl handlers.
> >
> > Signed-off-by: Andre Przywara <andre.przywara@linaro.org>
> > ---
> > arch/arm/kvm/arm.c | 9 +++++++++
> > 1 file changed, 9 insertions(+)
> >
> > diff --git a/arch/arm/kvm/arm.c b/arch/arm/kvm/arm.c
> > index c1fe498..0c571ff 100644
> > --- a/arch/arm/kvm/arm.c
> > +++ b/arch/arm/kvm/arm.c
> > @@ -893,6 +893,11 @@ long kvm_arch_vcpu_ioctl(struct file *filp,
> > case KVM_SET_ONE_REG:
> > case KVM_GET_ONE_REG: {
> > struct kvm_one_reg reg;
> > +
> > + /* Make sure they initialize the vcpu with KVM_ARM_VCPU_INIT */
> > + if (unlikely(vcpu->arch.target < 0))
> > + return -ENOEXEC;
> > +
> > if (copy_from_user(®, argp, sizeof(reg)))
> > return -EFAULT;
> > if (ioctl == KVM_SET_ONE_REG)
> > @@ -905,6 +910,10 @@ long kvm_arch_vcpu_ioctl(struct file *filp,
> > struct kvm_reg_list reg_list;
> > unsigned n;
> >
> > + /* Make sure they initialize the vcpu with KVM_ARM_VCPU_INIT */
> > + if (unlikely(vcpu->arch.target < 0))
> > + return -ENOEXEC;
> > +
> > if (copy_from_user(®_list, user_list, sizeof(reg_list)))
> > return -EFAULT;
> > n = reg_list.n;
> >
>
> So we also have the same snippet in kvm_arch_vcpu_ioctl_run().
>
> Can you create a static function (kvm_vcpu_initialized?) containing that
> code and make all three sites use it?
>
Andre, will you re-spin your patch as per Marc's comments?
Thanks,
-Christoffer
next prev parent reply other threads:[~2013-05-13 5:13 UTC|newest]
Thread overview: 4+ messages / expand[flat|nested] mbox.gz Atom feed top
2013-05-07 12:55 [PATCH] ARM: KVM: prevent NULL pointer dereference with KVM ioctl Andre Przywara
2013-05-08 9:53 ` Marc Zyngier
2013-05-13 5:13 ` Christoffer Dall [this message]
2013-05-13 5:53 ` Christoffer Dall
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20130513051352.GA64337@ubuntu \
--to=cdall@cs.columbia.edu \
--cc=linux-arm-kernel@lists.infradead.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.