All of lore.kernel.org
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Norbert Szetei" <norbert@doyensec.com>
Cc: linux-rdma@vger.kernel.org
Subject: Re: [PATCH v2 1/2] RDMA/rxe: Reject IB_ACCESS_ON_DEMAND changes after MR creation
Date: Sun, 13 Sep 2026 12:03:26 +0000	[thread overview]
Message-ID: <20260913120327.5ECA61F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20260913-rxe-advise-mr-v2-v2-1-b806c789871c@doyensec.com>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:

Pre-existing issues:
- [Critical] Arbitrary Kernel Pointer Dereference / Local Privilege Escalation via IB_WR_REG_MR WQE
--

commit fa8758be337c701491b43023c09167d84e64fdc0
Author: Norbert Szetei <norbert@doyensec.com>

RDMA/rxe: Reject IB_ACCESS_ON_DEMAND changes after MR creation

This commit prevents userspace from setting or clearing the
IB_ACCESS_ON_DEMAND flag on memory regions after they are created. This
ensures that the access flag correctly matches the underlying capabilities
of the memory region.

> diff --git a/drivers/infiniband/sw/rxe/rxe_mr.c b/drivers/infiniband/sw/rxe/rxe_mr.c
> index 71d9ea4772890..615da4bb9a38c 100644
> --- a/drivers/infiniband/sw/rxe/rxe_mr.c
> +++ b/drivers/infiniband/sw/rxe/rxe_mr.c
> @@ -796,6 +796,12 @@ int rxe_reg_fast_mr(struct rxe_qp *qp, struct rxe_send_wqe *wqe)
>  		return -EINVAL;
>  	}
>  
> +	/* an MR with no umem is never an ODP MR */
> +	if (unlikely(access & IB_ACCESS_ON_DEMAND)) {
> +		rxe_dbg_mr(mr, "access = 0x%x requests ODP\n", access);
> +		return -EINVAL;
> +	}
> +

[Severity: Critical]
This is a pre-existing issue, but does writing to mr here allow an arbitrary
kernel memory overwrite?

If an unprivileged local user creates a Reliable Connection Queue Pair and
memory-maps its send queue ring buffer, they can write a crafted WQE with
IB_WR_REG_MR and set wqe->wr.wr.reg.mr to an arbitrary kernel pointer.

The kernel processes this WQE in rxe_requester(), which routes the WQE to
kernel-only local operations without verifying if the Queue Pair belongs to
a privileged context:

rxe_req.c:rxe_requester() {
    ...
    if (wqe->mask & WR_LOCAL_OP_MASK) {
        err = rxe_do_local_ops(qp, wqe);
    ...
}

Since rxe_wr_opcode_info allows WR_LOCAL_OP_MASK for IB_WR_REG_MR,
rxe_do_local_ops() dispatches it to rxe_reg_fast_mr().

In rxe_reg_fast_mr(), the arbitrary pointer from the user is directly cast:

rxe_mr.c:rxe_reg_fast_mr() {
    struct rxe_mr *mr = to_rmr(wqe->wr.wr.reg.mr);
    ...
}

Could this cause the subsequent assignments to mr->access, mr->lkey,
mr->rkey, and mr->state to overwrite arbitrary kernel memory?

>  	mr->access = access;
>  	mr->lkey = key;
>  	mr->rkey = key;

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260913-rxe-advise-mr-v2-v2-0-b806c789871c@doyensec.com?part=1

  reply	other threads:[~2026-09-13 12:03 UTC|newest]

Thread overview: 8+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-13 11:45 [PATCH v2 0/2] RDMA/rxe: fix ADVISE_MR prefetch on non-ODP MRs Norbert Szetei via B4 Relay
2026-09-13 11:45 ` Norbert Szetei
2026-09-13 11:45 ` [PATCH v2 1/2] RDMA/rxe: Reject IB_ACCESS_ON_DEMAND changes after MR creation Norbert Szetei via B4 Relay
2026-09-13 11:45   ` Norbert Szetei
2026-09-13 12:03   ` sashiko-bot [this message]
2026-09-13 11:45 ` [PATCH v2 2/2] RDMA/rxe: Reject prefetch of a non-ODP MR Norbert Szetei via B4 Relay
2026-09-13 11:45   ` Norbert Szetei
2026-09-13 11:58   ` sashiko-bot

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260913120327.5ECA61F000FF@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=linux-rdma@vger.kernel.org \
    --cc=norbert@doyensec.com \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.