From: sashiko-bot@kernel.org
To: "Eric Farman" <farman@linux.ibm.com>
Cc: kvm@vger.kernel.org, "Heiko Carstens" <hca@linux.ibm.com>,
linux-s390@vger.kernel.org, "Vasily Gorbik" <gor@linux.ibm.com>,
"Alexander Gordeev" <agordeev@linux.ibm.com>
Subject: Re: [PATCH v8 02/10] s390/vfio_ccw: limit the number of channel program segments
Date: Tue, 28 Jul 2026 01:52:14 +0000 [thread overview]
Message-ID: <20260728015214.C95101F000E9@smtp.kernel.org> (raw)
In-Reply-To: <20260728013509.1551753-3-farman@linux.ibm.com>
Thank you for your contribution! Sashiko AI review found 2 potential issue(s) to consider:
Pre-existing issues:
- [Critical] A malicious guest can trigger a host kernel out-of-bounds read and potentially execute DMA to arbitrary host physical addresses by concurrently modifying the first IDAW in a channel program.
- [High] An off-by-one error in `ccwchain_calc_length` causes a deterministic out-of-bounds read when processing a channel program with exactly `CCWCHAIN_LEN_MAX` chained CCWs, which can crash the host if KASAN is enabled.
--
--- Patch [2]: [PATCH v8 02/10] s390/vfio_ccw: limit the number of channel program segments ---
commit 8d46ac3adbb3bfeb184e8057b932faa35fe79719
Author: Eric Farman <farman@linux.ibm.com>
s390/vfio_ccw: limit the number of channel program segments
The processing of channel programs, and the CCWs within them, is done
recursively. As such, there is an arbitrary (but not architectural)
limit to the number of CCWs that can exist in a single channel program.
The vfio-ccw logic breaks these channel programs into segments whenever
it encounters a Transfer-In-Channel (TIC) CCW, and the combined number
of segments count towards the global limit. Impose an equivalent limit
to the number of segments until such logic can be made non-recursive.
> diff --git a/drivers/s390/cio/vfio_ccw_cp.c b/drivers/s390/cio/vfio_ccw_cp.c
> index 086d1b54bdb05..1c2890d139c6b 100644
> --- a/drivers/s390/cio/vfio_ccw_cp.c
> +++ b/drivers/s390/cio/vfio_ccw_cp.c
[ ... ]
> @@ -441,6 +442,10 @@ static int ccwchain_handle_ccw(dma32_t cda, struct channel_program *cp)
> if (len < 0)
> return len;
>
[Severity: High]
This is a pre-existing issue, but does ccwchain_calc_length() have an
off-by-one error leading to an out-of-bounds read?
When a guest provides a channel program with exactly CCWCHAIN_LEN_MAX chained
CCWs, the do-while loop in ccwchain_calc_length() executes 256 times:
drivers/s390/cio/vfio_ccw_cp.c:ccwchain_calc_length() {
...
} while (cnt < CCWCHAIN_LEN_MAX + 1);
...
}
This increments cnt to 256 and advances ccw to point to guest_cp[256].
Since the loop condition (256 < 257) evaluates to true, the loop executes
a 257th time, dereferencing ccw in !ccw_is_chain(ccw). Since guest_cp is
allocated with exactly 256 elements, this read crosses the slab boundary.
Could this crash the host if KASAN is enabled?
[Severity: Critical]
This is a pre-existing issue, but can a malicious guest trigger an
out-of-bounds read and potentially execute DMA to arbitrary host physical
addresses by concurrently modifying the first IDAW in a channel program?
When fetching a guest CCW, ccw_count_idaws() performs the first fetch from
guest memory to calculate the required array size:
drivers/s390/cio/vfio_ccw_cp.c:ccw_count_idaws() {
...
ret = vfio_dma_rw(vdev, dma32_to_u32(ccw->cda), &iova, size, false);
...
}
It then calls get_guest_idal(), which allocates a kernel buffer and reads the
entire IDAL from guest memory again into the undersized kernel buffer:
drivers/s390/cio/vfio_ccw_cp.c:get_guest_idal() {
...
ret = vfio_dma_rw(vdev, dma32_to_u32(ccw->cda), idaws, idal_len, false);
...
}
If a guest provides a page-aligned first IDAW during the first fetch, and
concurrently modifies its memory so the second fetch reads a misaligned first
IDAW, the hardware will require more IDAWs than originally allocated.
Does this cause the hardware to read past the end of the idaws kernel buffer
and interpret adjacent memory as host physical addresses for DMA?
> + /* Limit number of chains in a single channel program */
> + if (cp->ccwchain_count >= CCWCHAIN_COUNT_MAX)
> + return -EINVAL;
> +
> /* Need alloc a new chain for this one. */
> chain = ccwchain_alloc(cp, len);
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260728013509.1551753-1-farman@linux.ibm.com?part=2
next prev parent reply other threads:[~2026-07-28 1:52 UTC|newest]
Thread overview: 25+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-07-28 1:34 [PATCH v8 00/10] s390/vfio_ccw fixes Eric Farman
2026-07-28 1:35 ` [PATCH v8 01/10] s390/vfio_ccw: free all memory if cp_init() fails Eric Farman
2026-07-28 1:51 ` sashiko-bot
2026-07-28 1:35 ` [PATCH v8 02/10] s390/vfio_ccw: limit the number of channel program segments Eric Farman
2026-07-28 1:52 ` sashiko-bot [this message]
2026-07-28 1:35 ` [PATCH v8 03/10] s390/vfio_ccw: fix out of bounds check on CCW array Eric Farman
2026-07-28 1:50 ` sashiko-bot
2026-07-28 1:35 ` [PATCH v8 04/10] s390/vfio_ccw: ensure first IDAW remains constant Eric Farman
2026-07-28 1:45 ` sashiko-bot
2026-07-28 1:35 ` [PATCH v8 05/10] s390/vfio_ccw: calculate idal length based on idaw type Eric Farman
2026-07-28 1:49 ` sashiko-bot
2026-07-28 1:35 ` [PATCH v8 06/10] s390/vfio_ccw: ensure index for read/write regions are within range Eric Farman
2026-07-28 1:54 ` sashiko-bot
2026-07-28 1:35 ` [PATCH v8 07/10] s390/vfio_ccw: cancel existing workqueues Eric Farman
2026-07-28 1:53 ` sashiko-bot
2026-07-28 2:07 ` Matthew Rosato
2026-07-28 1:35 ` [PATCH v8 08/10] s390/vfio_ccw: move cp cleanup out of not operational Eric Farman
2026-07-28 1:49 ` sashiko-bot
2026-07-28 2:08 ` Matthew Rosato
2026-07-28 3:23 ` Eric Farman
2026-07-28 1:35 ` [PATCH v8 09/10] s390/vfio_ccw: selectively expand io_mutex Eric Farman
2026-07-28 1:57 ` sashiko-bot
2026-07-28 2:08 ` Matthew Rosato
2026-07-28 1:35 ` [PATCH v8 10/10] s390/vfio_ccw: implement a crw lock Eric Farman
2026-07-28 2:01 ` sashiko-bot
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260728015214.C95101F000E9@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=agordeev@linux.ibm.com \
--cc=farman@linux.ibm.com \
--cc=gor@linux.ibm.com \
--cc=hca@linux.ibm.com \
--cc=kvm@vger.kernel.org \
--cc=linux-s390@vger.kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox