All of lore.kernel.org
 help / color / mirror / Atom feed
From: Alexandra Winter <wintera@linux.ibm.com>
To: sashiko-reviews@lists.linux.dev
Cc: Vasily Gorbik <gor@linux.ibm.com>,
	Christian Borntraeger <borntraeger@linux.ibm.com>,
	Heiko Carstens <hca@linux.ibm.com>,
	linux-s390@vger.kernel.org,
	Alexander Gordeev <agordeev@linux.ibm.com>,
	Julian Wiedmann <jwi@linux.ibm.com>,
	Tobias Schumacher <ts@linux.ibm.com>
Subject: Re: [PATCH net] s390/ism: folio_put() after error
Date: Thu, 3 Sep 2026 18:40:22 +0200	[thread overview]
Message-ID: <5c27d8f1-67bb-4845-b9ac-ea4bef34c7bc@linux.ibm.com> (raw)
In-Reply-To: <20260903143746.A5CC41F00A3A@smtp.kernel.org>



On 03.09.26 16:37, sashiko-bot@kernel.org wrote:
> Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
> 
> Pre-existing issues:
> - [Critical] Missing __GFP_ZERO in folio_alloc() causes uninitialized kernel memory to be exposed in the receive message buffer.
> --
> 
> commit d942ada155dde57df3b8bd6857db438603cbd218
> Author: Alexandra Winter <wintera@linux.ibm.com>
> 
> s390/ism: folio_put() after error
> 
> This commit uses folio_put() instead of kfree() in the error path of
> ism_alloc_dmb() to prevent slab allocator corruption. It also sets
> dmb->cpu_addr to NULL after freeing to prevent a potential use-after-free.
> 
> Fixes: 83781384a96b ("s390/ism: Properly fix receive message buffer allocation")
> 
>> diff --git a/drivers/s390/net/ism_drv.c b/drivers/s390/net/ism_drv.c
>> index 242da20f27e0e..035b233abb4e9 100644
>> --- a/drivers/s390/net/ism_drv.c
>> +++ b/drivers/s390/net/ism_drv.c
> [ ... ]
>> @@ -274,7 +275,8 @@ static int ism_alloc_dmb(struct ism_dev *ism, struct dibs_dmb *dmb)
>>  	return 0;
>>  
>>  out_free:
>> -	kfree(dmb->cpu_addr);
>> +	folio_put(folio);
> 
> [Severity: Critical]
> This isn't a bug introduced by this patch, but the previous replacement
> of dma_alloc_coherent() with folio_alloc() removed the implicit
> zero-initialization of the Direct Message Buffer (DMB).
> 
> Looking at the allocation earlier in ism_alloc_dmb():
> 
> drivers/s390/net/ism_drv.c:ism_alloc_dmb() {
>         ...
>         folio = folio_alloc(GFP_KERNEL | __GFP_NOWARN | __GFP_NOMEMALLOC |
>                             __GFP_NORETRY, get_order(dmb->dmb_len));
>         ...
> }
> 
> Does this missing __GFP_ZERO leak uninitialized host kernel memory to an
> untrusted remote peer?
> 

This is actually already on my ToDo list.
See also my discussion with Julian on 12.08.2026 about
Re: [PATCH v2 1/6] dibs: remove __GFP_ZERO from loopback



> A remote, unprivileged peer partition can trigger an SMC connection
> establishment via smcd_new_buf_create() -> smc_ism_register_dmb(). This
> causes the local host to allocate and map the DMB memory without
> zero-filling it locally before the peer partition gains access to it,
> potentially exposing uninitialized memory across the virtual machine or
> LPAR boundary.
> 
>> +	dmb->cpu_addr = NULL;
>>  out_bit:
>>  	clear_bit(dmb->idx, ism->sba_bitmap);
>>  	return rc;
> 


  reply	other threads:[~2026-09-03 16:40 UTC|newest]

Thread overview: 6+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-02 14:37 [PATCH net] s390/ism: folio_put() after error Alexandra Winter
2026-09-02 16:58 ` Gerd Bayer
2026-09-03 14:37 ` sashiko-bot
2026-09-03 16:40   ` Alexandra Winter [this message]
2026-09-03 16:41     ` Alexandra Winter
2026-09-04 23:20 ` patchwork-bot+netdevbpf

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=5c27d8f1-67bb-4845-b9ac-ea4bef34c7bc@linux.ibm.com \
    --to=wintera@linux.ibm.com \
    --cc=agordeev@linux.ibm.com \
    --cc=borntraeger@linux.ibm.com \
    --cc=gor@linux.ibm.com \
    --cc=hca@linux.ibm.com \
    --cc=jwi@linux.ibm.com \
    --cc=linux-s390@vger.kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    --cc=ts@linux.ibm.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.