All of lore.kernel.org
 help / color / mirror / Atom feed
From: Jason Andryuk <jason.andryuk@amd.com>
To: Jan Beulich <jbeulich@suse.com>,
	"xen-devel@lists.xenproject.org" <xen-devel@lists.xenproject.org>
Cc: Juergen Gross <jgross@suse.com>, Julien Grall <julien@xen.org>
Subject: Re: New Defects reported by Coverity Scan for XenProject
Date: Wed, 24 Jun 2026 17:53:14 -0400	[thread overview]
Message-ID: <eb5a3c83-c470-4c81-b64f-09eaef4131e9@amd.com> (raw)
In-Reply-To: <ee48e27a-049f-43b9-87dd-c9188db26f30@suse.com>

On 2026-06-24 09:04, Jan Beulich wrote:
> On 24.06.2026 14:33, scan-admin@coverity.com wrote:
>> ** CID 1695359:       Insecure data handling  (INTEGER_OVERFLOW)
>> /tools/xenstored/domain.c: 601           in domain_tree_remove_sub()
>>
>>
>> _____________________________________________________________________________________________
>> *** CID 1695359:         Insecure data handling  (INTEGER_OVERFLOW)
>> /tools/xenstored/domain.c: 601             in domain_tree_remove_sub()
>> 595     		node_changed = true;
>> 596     	}
>> 597
>> 598     	for (i = 1; i < node->hdr.num_perms; i++) {
>> 599     		if (node->perms[i].id != domain->domid)
>> 600     			continue;
>>>>>      CID 1695359:         Insecure data handling  (INTEGER_OVERFLOW)
>>>>>      "8UL * (node->hdr.num_perms - i - 1U)", which might have underflowed, is passed to "memmove(node->perms + i, node->perms + i + 1, 8UL * (node->hdr.num_perms - i - 1U))". [Note: The source code implementation of the function has been overridden by a builtin model.]
>> 601     		memmove(node->perms + i, node->perms + i + 1,
>> 602     			sizeof(*node->perms) * (node->hdr.num_perms - i - 1));
> 
> I'm struggling with this one: As i < node->hdr.num_perms, the last argument
> passed to memmove() can be 0, but I can't see potential for underflow.

This gave me pause on my initial review.  On the final iteration,
node->perms + i + 1 will point past the end of the allocation, but as 
you say the size would be 0.  I originally considered suggesting a check 
and then decided it was unnecessary because of the 0.

Regards,
Jason


  reply	other threads:[~2026-06-24 21:53 UTC|newest]

Thread overview: 29+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
     [not found] <6a3bce99e5494_767442bc3001679a440720@prd-scan-dashboard-0.mail>
2026-06-24 13:04 ` New Defects reported by Coverity Scan for XenProject Jan Beulich
2026-06-24 21:53   ` Jason Andryuk [this message]
2026-06-25  5:56     ` Jan Beulich
2026-06-24 13:12 ` Jan Beulich
     [not found] <6922db67d5bee_ec6942e9307a67994398e5@prd-scan-dashboard-0.mail>
2025-11-24  8:37 ` Jan Beulich
     [not found] <68bd98b92c2b2_2afba52d9ed55e79908873e@prd-scan-dashboard-0.mail>
2025-09-08 10:19 ` Jan Beulich
2025-09-08 11:04   ` Alejandro Vallejo
2025-09-08 11:25     ` Jan Beulich
2025-09-08 12:48       ` Alejandro Vallejo
2025-09-08 13:17         ` Jan Beulich
     [not found] <68b9a73be8eb_27ea7e2d9ed55e799088716@prd-scan-dashboard-0.mail>
2025-09-04 14:54 ` Jan Beulich
     [not found] <67f26722e020c_13a342abaf9ddd9a0513e7@prd-scan-dashboard-0.mail>
2025-04-07  7:26 ` Jan Beulich
2025-04-07  7:43   ` Andrew Cooper
     [not found] <67ed34047fd3c_1209992cc92a0f99a0989e0@prd-scan-dashboard-0.mail>
2025-04-02 14:19 ` Jan Beulich
2025-04-02 16:01   ` Andrew Cooper
     [not found] <664dc165759df_5e9362b92d249399c762@prd-scan-dashboard-0.mail>
2024-05-22 10:05 ` Jan Beulich
2024-05-22 13:49   ` Andrew Cooper
     [not found] <6637576caf98c_10d9e42c57d37559ac60499@prd-scan-dashboard-0.mail>
2024-05-06  7:46 ` Jan Beulich
     [not found] <6547674e54da3_1c3af2c62521719a8359bc@prd-scan-dashboard-0.mail>
2023-11-06  7:36 ` Jan Beulich
     [not found] <64859cf3a1e46_712752abb10eab98834b9@prd-scan-dashboard-0.mail>
2023-06-12 10:54 ` Jan Beulich
2023-06-12 11:06   ` Andrew Cooper
     [not found] <600d4d7f99bc3_241662b17c874cf6097f1@prd-scan-dashboard-0.mail>
2021-01-25 10:14 ` Jan Beulich
     [not found] <5700f7b3e7d5c_3fdf4db3186252@ss1435.mail>
2016-04-04 15:07 ` Ian Jackson
     [not found] <56ce8ad13abd2_bd9abd33094410@ss1435.mail>
2016-02-25 10:00 ` Ian Campbell
2016-02-25 10:06   ` George Dunlap
     [not found] <551be9e0474d8_2970d1331454394@scan.coverity.com.mail>
2015-04-02 14:32 ` Ian Campbell
2015-04-02 15:43   ` Charles Arnold
     [not found] <E1Vgaam-0000UH-GS@build-l3.scan.coverity.com>
2013-11-13 13:51 ` Ian Campbell
2013-11-13 14:01   ` David Vrabel

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=eb5a3c83-c470-4c81-b64f-09eaef4131e9@amd.com \
    --to=jason.andryuk@amd.com \
    --cc=jbeulich@suse.com \
    --cc=jgross@suse.com \
    --cc=julien@xen.org \
    --cc=xen-devel@lists.xenproject.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.