* [PATCH v3 0/2] s390/uv: Various fixes for UV secrets
@ 2026-08-12 15:55 Steffen Eiden
2026-08-12 15:55 ` [PATCH v3 1/2] s390/uv: Fix loop condition in uv_find_secrets Steffen Eiden
` (2 more replies)
0 siblings, 3 replies; 7+ messages in thread
From: Steffen Eiden @ 2026-08-12 15:55 UTC (permalink / raw)
To: Christian Borntraeger, Janosch Frank, Claudio Imbrenda
Cc: David Hildenbrand, Heiko Carstens, Vasily Gorbik,
Alexander Gordeev, Sven Schnelle, Christoph Schlameuss,
Harald Freudenberger, Steffen Eiden, kvm, linux-s390,
linux-kernel
To: Christian Borntraeger <borntraeger@linux.ibm.com>
To: Janosch Frank <frankja@linux.ibm.com>
To: Claudio Imbrenda <imbrenda@linux.ibm.com>
Cc: David Hildenbrand <david@kernel.org>
Cc: Heiko Carstens <hca@linux.ibm.com>
Cc: Vasily Gorbik <gor@linux.ibm.com>
Cc: Alexander Gordeev <agordeev@linux.ibm.com>
Cc: Sven Schnelle <svens@linux.ibm.com>
Cc: Christoph Schlameuss <schlameuss@linux.ibm.com>
Cc: Harald Freudenberger <freude@linux.ibm.com>
Cc: Steffen Eiden <seiden@linux.ibm.com>
Cc: kvm@vger.kernel.org
Cc: linux-s390@vger.kernel.org
Cc: linux-kernel@vger.kernel.org
Fix some issues in the retrieve secret infrastructure. First, fix the
issue that the loop in uv_find_secret cannot ran more that one round.
Second, fix a potential out of bounds issue in find_secret_in_page.
---
Changes in v3:
- Add R-b from Christoph for patch 1
- Improved commit message in patch 1
- Link to v2: https://lore.kernel.org/r/20260811-uv_secrets_fix-v2-0-64444968ec55@linux.ibm.com
Changes in v2:
- Add Ack from Claudio
- Add patch that fixes a potential out-of-bounds access in find_secret_in_page
- Link to v1: https://lore.kernel.org/r/20260811-uv_secrets_fix-v1-1-940a421a9292@linux.ibm.com
---
Steffen Eiden (2):
s390/uv: Fix loop condition in uv_find_secrets
s390/uv: Prevent potential out-of-bounds read
arch/s390/kernel/uv.c | 8 +++++---
1 file changed, 5 insertions(+), 3 deletions(-)
---
base-commit: d58772d8520c7ef247c4b95c9bd76d3a25da9ff5
change-id: 20260811-uv_secrets_fix-58a63b4a4ec4
Best regards,
--
Steffen Eiden <seiden@linux.ibm.com>
^ permalink raw reply [flat|nested] 7+ messages in thread
* [PATCH v3 1/2] s390/uv: Fix loop condition in uv_find_secrets
2026-08-12 15:55 [PATCH v3 0/2] s390/uv: Various fixes for UV secrets Steffen Eiden
@ 2026-08-12 15:55 ` Steffen Eiden
2026-08-12 16:04 ` sashiko-bot
2026-08-12 15:55 ` [PATCH v3 2/2] s390/uv: Prevent potential out-of-bounds read Steffen Eiden
2026-08-19 7:18 ` [PATCH v3 0/2] s390/uv: Various fixes for UV secrets Christian Borntraeger
2 siblings, 1 reply; 7+ messages in thread
From: Steffen Eiden @ 2026-08-12 15:55 UTC (permalink / raw)
To: Christian Borntraeger, Janosch Frank, Claudio Imbrenda
Cc: David Hildenbrand, Heiko Carstens, Vasily Gorbik,
Alexander Gordeev, Sven Schnelle, Christoph Schlameuss,
Harald Freudenberger, Steffen Eiden, kvm, linux-s390,
linux-kernel
Systems with more than 85 UV secrets got -ENOENT for any secret past the
first page.
Fix this by setting the start index at the beginning of the loop in
uv_find_secret() and not at the end. First test if there are more
secrets left by comparing start_idx with list->next_secret_idx, and then
set the start index to the next secret index.
Fixes: 7c9137af2042 ("s390/uv: Retrieve UV secrets support")
Acked-by: Claudio Imbrenda <imbrenda@linux.ibm.com>
Reviewed-by: Christoph Schlameuss <schlameuss@linux.ibm.com>
Signed-off-by: Steffen Eiden <seiden@linux.ibm.com>
---
arch/s390/kernel/uv.c | 6 ++++--
1 file changed, 4 insertions(+), 2 deletions(-)
diff --git a/arch/s390/kernel/uv.c b/arch/s390/kernel/uv.c
index a284f98d9716..d970b15ef126 100644
--- a/arch/s390/kernel/uv.c
+++ b/arch/s390/kernel/uv.c
@@ -781,11 +781,14 @@ int uv_find_secret(const u8 secret_id[UV_SECRET_ID_LEN],
struct uv_secret_list *list,
struct uv_secret_list_item_hdr *secret)
{
- u16 start_idx = 0;
+ u16 start_idx;
u16 list_rc;
int ret;
+ list->next_secret_idx = 0;
+
do {
+ start_idx = list->next_secret_idx;
uv_list_secrets(list, start_idx, &list_rc, NULL);
if (list_rc != UVC_RC_EXECUTED && list_rc != UVC_RC_MORE_DATA) {
if (list_rc == UVC_RC_INV_CMD)
@@ -796,7 +799,6 @@ int uv_find_secret(const u8 secret_id[UV_SECRET_ID_LEN],
ret = find_secret_in_page(secret_id, list, secret);
if (ret == 0)
return ret;
- start_idx = list->next_secret_idx;
} while (list_rc == UVC_RC_MORE_DATA && start_idx < list->next_secret_idx);
return -ENOENT;
--
2.53.0
^ permalink raw reply related [flat|nested] 7+ messages in thread
* [PATCH v3 2/2] s390/uv: Prevent potential out-of-bounds read
2026-08-12 15:55 [PATCH v3 0/2] s390/uv: Various fixes for UV secrets Steffen Eiden
2026-08-12 15:55 ` [PATCH v3 1/2] s390/uv: Fix loop condition in uv_find_secrets Steffen Eiden
@ 2026-08-12 15:55 ` Steffen Eiden
2026-08-12 16:15 ` sashiko-bot
2026-08-13 10:20 ` Christoph Schlameuss
2026-08-19 7:18 ` [PATCH v3 0/2] s390/uv: Various fixes for UV secrets Christian Borntraeger
2 siblings, 2 replies; 7+ messages in thread
From: Steffen Eiden @ 2026-08-12 15:55 UTC (permalink / raw)
To: Christian Borntraeger, Janosch Frank, Claudio Imbrenda
Cc: David Hildenbrand, Heiko Carstens, Vasily Gorbik,
Alexander Gordeev, Sven Schnelle, Christoph Schlameuss,
Harald Freudenberger, Steffen Eiden, kvm, linux-s390,
linux-kernel
When the system has more than 85 secrets, the uv_secret_list struct
array only holds up to 85 items per page, resulting in an out of bounds
read in find_secret_in_page if the targeted secret is in the next page
or not stored at all.
Fix this by looping over the number of stored secrets which is the
per sub-list count of stored secrets and not the overall count.
Fixes: 7c9137af2042 ("s390/uv: Retrieve UV secrets support")
Signed-off-by: Steffen Eiden <seiden@linux.ibm.com>
---
arch/s390/kernel/uv.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/arch/s390/kernel/uv.c b/arch/s390/kernel/uv.c
index d970b15ef126..e70acad09cd5 100644
--- a/arch/s390/kernel/uv.c
+++ b/arch/s390/kernel/uv.c
@@ -760,7 +760,7 @@ static int find_secret_in_page(const u8 secret_id[UV_SECRET_ID_LEN],
{
u16 i;
- for (i = 0; i < list->total_num_secrets; i++) {
+ for (i = 0; i < list->num_secr_stored; i++) {
if (memcmp(secret_id, list->secrets[i].id, UV_SECRET_ID_LEN) == 0) {
*secret = list->secrets[i].hdr;
return 0;
--
2.53.0
^ permalink raw reply related [flat|nested] 7+ messages in thread
* Re: [PATCH v3 1/2] s390/uv: Fix loop condition in uv_find_secrets
2026-08-12 15:55 ` [PATCH v3 1/2] s390/uv: Fix loop condition in uv_find_secrets Steffen Eiden
@ 2026-08-12 16:04 ` sashiko-bot
0 siblings, 0 replies; 7+ messages in thread
From: sashiko-bot @ 2026-08-12 16:04 UTC (permalink / raw)
To: Steffen Eiden
Cc: kvm, Heiko Carstens, Vasily Gorbik, linux-s390, Alexander Gordeev,
Christian Borntraeger
> Systems with more than 85 UV secrets got -ENOENT for any secret past the
> first page.
>
> Fix this by setting the start index at the beginning of the loop in
> uv_find_secret() and not at the end. First test if there are more
> secrets left by comparing start_idx with list->next_secret_idx, and then
> set the start index to the next secret index.
>
> Fixes: 7c9137af2042 ("s390/uv: Retrieve UV secrets support")
> Acked-by: Claudio Imbrenda <imbrenda@linux.ibm.com>
> Reviewed-by: Christoph Schlameuss <schlameuss@linux.ibm.com>
> Signed-off-by: Steffen Eiden <seiden@linux.ibm.com>
Sashiko has reviewed this patch and found no issues. It looks great!
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260812-uv_secrets_fix-v3-0-a85bd29e0666@linux.ibm.com?part=1
^ permalink raw reply [flat|nested] 7+ messages in thread
* Re: [PATCH v3 2/2] s390/uv: Prevent potential out-of-bounds read
2026-08-12 15:55 ` [PATCH v3 2/2] s390/uv: Prevent potential out-of-bounds read Steffen Eiden
@ 2026-08-12 16:15 ` sashiko-bot
2026-08-13 10:20 ` Christoph Schlameuss
1 sibling, 0 replies; 7+ messages in thread
From: sashiko-bot @ 2026-08-12 16:15 UTC (permalink / raw)
To: Steffen Eiden
Cc: kvm, Vasily Gorbik, linux-s390, Heiko Carstens, Alexander Gordeev,
Christian Borntraeger
> When the system has more than 85 secrets, the uv_secret_list struct
> array only holds up to 85 items per page, resulting in an out of bounds
> read in find_secret_in_page if the targeted secret is in the next page
> or not stored at all.
>
> Fix this by looping over the number of stored secrets which is the
> per sub-list count of stored secrets and not the overall count.
>
> Fixes: 7c9137af2042 ("s390/uv: Retrieve UV secrets support")
> Signed-off-by: Steffen Eiden <seiden@linux.ibm.com>
Sashiko has reviewed this patch and found no issues. It looks great!
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260812-uv_secrets_fix-v3-0-a85bd29e0666@linux.ibm.com?part=2
^ permalink raw reply [flat|nested] 7+ messages in thread
* Re: [PATCH v3 2/2] s390/uv: Prevent potential out-of-bounds read
2026-08-12 15:55 ` [PATCH v3 2/2] s390/uv: Prevent potential out-of-bounds read Steffen Eiden
2026-08-12 16:15 ` sashiko-bot
@ 2026-08-13 10:20 ` Christoph Schlameuss
1 sibling, 0 replies; 7+ messages in thread
From: Christoph Schlameuss @ 2026-08-13 10:20 UTC (permalink / raw)
To: Steffen Eiden, Christian Borntraeger, Janosch Frank,
Claudio Imbrenda
Cc: David Hildenbrand, Heiko Carstens, Vasily Gorbik,
Alexander Gordeev, Sven Schnelle, Christoph Schlameuss,
Harald Freudenberger, kvm, linux-s390, linux-kernel
On Wed Aug 12, 2026 at 5:55 PM CEST, Steffen Eiden wrote:
> When the system has more than 85 secrets, the uv_secret_list struct
> array only holds up to 85 items per page, resulting in an out of bounds
> read in find_secret_in_page if the targeted secret is in the next page
> or not stored at all.
>
> Fix this by looping over the number of stored secrets which is the
> per sub-list count of stored secrets and not the overall count.
>
> Fixes: 7c9137af2042 ("s390/uv: Retrieve UV secrets support")
> Signed-off-by: Steffen Eiden <seiden@linux.ibm.com>
Reviewed-by: Christoph Schlameuss <schlameuss@linux.ibm.com>
> ---
> arch/s390/kernel/uv.c | 2 +-
> 1 file changed, 1 insertion(+), 1 deletion(-)
>
> diff --git a/arch/s390/kernel/uv.c b/arch/s390/kernel/uv.c
> index d970b15ef126..e70acad09cd5 100644
> --- a/arch/s390/kernel/uv.c
> +++ b/arch/s390/kernel/uv.c
> @@ -760,7 +760,7 @@ static int find_secret_in_page(const u8 secret_id[UV_SECRET_ID_LEN],
> {
> u16 i;
>
> - for (i = 0; i < list->total_num_secrets; i++) {
> + for (i = 0; i < list->num_secr_stored; i++) {
> if (memcmp(secret_id, list->secrets[i].id, UV_SECRET_ID_LEN) == 0) {
> *secret = list->secrets[i].hdr;
> return 0;
^ permalink raw reply [flat|nested] 7+ messages in thread
* Re: [PATCH v3 0/2] s390/uv: Various fixes for UV secrets
2026-08-12 15:55 [PATCH v3 0/2] s390/uv: Various fixes for UV secrets Steffen Eiden
2026-08-12 15:55 ` [PATCH v3 1/2] s390/uv: Fix loop condition in uv_find_secrets Steffen Eiden
2026-08-12 15:55 ` [PATCH v3 2/2] s390/uv: Prevent potential out-of-bounds read Steffen Eiden
@ 2026-08-19 7:18 ` Christian Borntraeger
2 siblings, 0 replies; 7+ messages in thread
From: Christian Borntraeger @ 2026-08-19 7:18 UTC (permalink / raw)
To: Steffen Eiden, Janosch Frank, Claudio Imbrenda
Cc: David Hildenbrand, Heiko Carstens, Vasily Gorbik,
Alexander Gordeev, Sven Schnelle, Christoph Schlameuss,
Harald Freudenberger, kvm, linux-s390, linux-kernel
Am 12.08.26 um 17:55 schrieb Steffen Eiden:
> To: Christian Borntraeger <borntraeger@linux.ibm.com>
> To: Janosch Frank <frankja@linux.ibm.com>
> To: Claudio Imbrenda <imbrenda@linux.ibm.com>
> Cc: David Hildenbrand <david@kernel.org>
> Cc: Heiko Carstens <hca@linux.ibm.com>
> Cc: Vasily Gorbik <gor@linux.ibm.com>
> Cc: Alexander Gordeev <agordeev@linux.ibm.com>
> Cc: Sven Schnelle <svens@linux.ibm.com>
> Cc: Christoph Schlameuss <schlameuss@linux.ibm.com>
> Cc: Harald Freudenberger <freude@linux.ibm.com>
> Cc: Steffen Eiden <seiden@linux.ibm.com>
> Cc: kvm@vger.kernel.org
> Cc: linux-s390@vger.kernel.org
> Cc: linux-kernel@vger.kernel.org
>
> Fix some issues in the retrieve secret infrastructure. First, fix the
> issue that the loop in uv_find_secret cannot ran more that one round.
> Second, fix a potential out of bounds issue in find_secret_in_page.
>
> ---
> Changes in v3:
> - Add R-b from Christoph for patch 1
> - Improved commit message in patch 1
> - Link to v2: https://lore.kernel.org/r/20260811-uv_secrets_fix-v2-0-64444968ec55@linux.ibm.com
> Changes in v2:
> - Add Ack from Claudio
> - Add patch that fixes a potential out-of-bounds access in find_secret_in_page
> - Link to v1: https://lore.kernel.org/r/20260811-uv_secrets_fix-v1-1-940a421a9292@linux.ibm.com
>
> ---
> Steffen Eiden (2):
> s390/uv: Fix loop condition in uv_find_secrets
> s390/uv: Prevent potential out-of-bounds read
>
> arch/s390/kernel/uv.c | 8 +++++---
> 1 file changed, 5 insertions(+), 3 deletions(-)
> ---
> base-commit: d58772d8520c7ef247c4b95c9bd76d3a25da9ff5
> change-id: 20260811-uv_secrets_fix-58a63b4a4ec4
>
> Best regards,
Thanks applied.
^ permalink raw reply [flat|nested] 7+ messages in thread
end of thread, other threads:[~2026-08-19 7:18 UTC | newest]
Thread overview: 7+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-08-12 15:55 [PATCH v3 0/2] s390/uv: Various fixes for UV secrets Steffen Eiden
2026-08-12 15:55 ` [PATCH v3 1/2] s390/uv: Fix loop condition in uv_find_secrets Steffen Eiden
2026-08-12 16:04 ` sashiko-bot
2026-08-12 15:55 ` [PATCH v3 2/2] s390/uv: Prevent potential out-of-bounds read Steffen Eiden
2026-08-12 16:15 ` sashiko-bot
2026-08-13 10:20 ` Christoph Schlameuss
2026-08-19 7:18 ` [PATCH v3 0/2] s390/uv: Various fixes for UV secrets Christian Borntraeger
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.