All of lore.kernel.org
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Alexandra Winter" <wintera@linux.ibm.com>
Cc: "Vasily Gorbik" <gor@linux.ibm.com>,
	"Christian Borntraeger" <borntraeger@linux.ibm.com>,
	"Heiko Carstens" <hca@linux.ibm.com>,
	linux-s390@vger.kernel.org,
	"Alexander Gordeev" <agordeev@linux.ibm.com>
Subject: Re: [PATCH net] s390/ism: folio_put() after error
Date: Thu, 03 Sep 2026 14:37:46 +0000	[thread overview]
Message-ID: <20260903143746.A5CC41F00A3A@smtp.kernel.org> (raw)
In-Reply-To: <20260902143733.433574-1-wintera@linux.ibm.com>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:

Pre-existing issues:
- [Critical] Missing __GFP_ZERO in folio_alloc() causes uninitialized kernel memory to be exposed in the receive message buffer.
--

commit d942ada155dde57df3b8bd6857db438603cbd218
Author: Alexandra Winter <wintera@linux.ibm.com>

s390/ism: folio_put() after error

This commit uses folio_put() instead of kfree() in the error path of
ism_alloc_dmb() to prevent slab allocator corruption. It also sets
dmb->cpu_addr to NULL after freeing to prevent a potential use-after-free.

Fixes: 83781384a96b ("s390/ism: Properly fix receive message buffer allocation")

> diff --git a/drivers/s390/net/ism_drv.c b/drivers/s390/net/ism_drv.c
> index 242da20f27e0e..035b233abb4e9 100644
> --- a/drivers/s390/net/ism_drv.c
> +++ b/drivers/s390/net/ism_drv.c
[ ... ]
> @@ -274,7 +275,8 @@ static int ism_alloc_dmb(struct ism_dev *ism, struct dibs_dmb *dmb)
>  	return 0;
>  
>  out_free:
> -	kfree(dmb->cpu_addr);
> +	folio_put(folio);

[Severity: Critical]
This isn't a bug introduced by this patch, but the previous replacement
of dma_alloc_coherent() with folio_alloc() removed the implicit
zero-initialization of the Direct Message Buffer (DMB).

Looking at the allocation earlier in ism_alloc_dmb():

drivers/s390/net/ism_drv.c:ism_alloc_dmb() {
        ...
        folio = folio_alloc(GFP_KERNEL | __GFP_NOWARN | __GFP_NOMEMALLOC |
                            __GFP_NORETRY, get_order(dmb->dmb_len));
        ...
}

Does this missing __GFP_ZERO leak uninitialized host kernel memory to an
untrusted remote peer?

A remote, unprivileged peer partition can trigger an SMC connection
establishment via smcd_new_buf_create() -> smc_ism_register_dmb(). This
causes the local host to allocate and map the DMB memory without
zero-filling it locally before the peer partition gains access to it,
potentially exposing uninitialized memory across the virtual machine or
LPAR boundary.

> +	dmb->cpu_addr = NULL;
>  out_bit:
>  	clear_bit(dmb->idx, ism->sba_bitmap);
>  	return rc;

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260902143733.433574-1-wintera@linux.ibm.com?part=1

  parent reply	other threads:[~2026-09-03 14:37 UTC|newest]

Thread overview: 6+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-02 14:37 [PATCH net] s390/ism: folio_put() after error Alexandra Winter
2026-09-02 16:58 ` Gerd Bayer
2026-09-03 14:37 ` sashiko-bot [this message]
2026-09-03 16:40   ` Alexandra Winter
2026-09-03 16:41     ` Alexandra Winter
2026-09-04 23:20 ` patchwork-bot+netdevbpf

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260903143746.A5CC41F00A3A@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=agordeev@linux.ibm.com \
    --cc=borntraeger@linux.ibm.com \
    --cc=gor@linux.ibm.com \
    --cc=hca@linux.ibm.com \
    --cc=linux-s390@vger.kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    --cc=wintera@linux.ibm.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.