* [PATCH v2 0/2] s390: uv: Various fixes for UV secrets
@ 2026-08-11 16:14 Steffen Eiden
2026-08-11 16:14 ` [PATCH v2 1/2] s390: uv: Fix loop condition in uv_find_secrets Steffen Eiden
2026-08-11 16:14 ` [PATCH v2 2/2] s390: uv: Prevent potential out-of-bounds read Steffen Eiden
0 siblings, 2 replies; 4+ messages in thread
From: Steffen Eiden @ 2026-08-11 16:14 UTC (permalink / raw)
To: Christian Borntraeger, Janosch Frank, Claudio Imbrenda
Cc: David Hildenbrand, Heiko Carstens, Vasily Gorbik,
Alexander Gordeev, Sven Schnelle, Christoph Schlameuss,
Harald Freudenberger, kvm, linux-s390, linux-kernel,
Steffen Eiden
Signed-off-by: Steffen Eiden <seiden@linux.ibm.com>
---
Fix some issues in the retrieve secret infrastructure. First, fix the
issue that the loop in uv_find_secret cannot ran more that one round.
Second, fix a potential out of bounds issue in find_secret_in_page.
Changes in v2:
- Add patch that fixes a potential out-of-bounds access in find_secret_in_page
- Link to v1: https://lore.kernel.org/r/20260811-uv_secrets_fix-v1-1-940a421a9292@linux.ibm.com
---
Steffen Eiden (2):
s390: uv: Fix loop condition in uv_find_secrets
s390: uv: Prevent potential out-of-bounds read
arch/s390/kernel/uv.c | 8 +++++---
1 file changed, 5 insertions(+), 3 deletions(-)
---
base-commit: d58772d8520c7ef247c4b95c9bd76d3a25da9ff5
change-id: 20260811-uv_secrets_fix-58a63b4a4ec4
Best regards,
--
Steffen Eiden <seiden@linux.ibm.com>
^ permalink raw reply [flat|nested] 4+ messages in thread* [PATCH v2 1/2] s390: uv: Fix loop condition in uv_find_secrets
2026-08-11 16:14 [PATCH v2 0/2] s390: uv: Various fixes for UV secrets Steffen Eiden
@ 2026-08-11 16:14 ` Steffen Eiden
2026-08-12 10:21 ` Heiko Carstens
2026-08-11 16:14 ` [PATCH v2 2/2] s390: uv: Prevent potential out-of-bounds read Steffen Eiden
1 sibling, 1 reply; 4+ messages in thread
From: Steffen Eiden @ 2026-08-11 16:14 UTC (permalink / raw)
To: Christian Borntraeger, Janosch Frank, Claudio Imbrenda
Cc: David Hildenbrand, Heiko Carstens, Vasily Gorbik,
Alexander Gordeev, Sven Schnelle, Christoph Schlameuss,
Harald Freudenberger, kvm, linux-s390, linux-kernel,
Steffen Eiden
Nothing modified `start_idx` between the assignment and the comparison,
so the condition was always false and the do/while ran exactly once
even when the UV returned UVC_RC_MORE_DATA. Systems with more than
85 UV secrets got -ENOENT for any secret past the first page.
Fix this by setting the start index at the beginning of the loop not at
the end. First test if there are more secrets left by comparing
start_idx with list->next_secret_idx, and then set the start index to the
next secret index.
Fixes: 7c9137af2042 ("s390/uv: Retrieve UV secrets support")
Acked-by: Claudio Imbrenda <imbrenda@linux.ibm.com>
Signed-off-by: Steffen Eiden <seiden@linux.ibm.com>
---
arch/s390/kernel/uv.c | 6 ++++--
1 file changed, 4 insertions(+), 2 deletions(-)
diff --git a/arch/s390/kernel/uv.c b/arch/s390/kernel/uv.c
index a284f98d9716..d970b15ef126 100644
--- a/arch/s390/kernel/uv.c
+++ b/arch/s390/kernel/uv.c
@@ -781,11 +781,14 @@ int uv_find_secret(const u8 secret_id[UV_SECRET_ID_LEN],
struct uv_secret_list *list,
struct uv_secret_list_item_hdr *secret)
{
- u16 start_idx = 0;
+ u16 start_idx;
u16 list_rc;
int ret;
+ list->next_secret_idx = 0;
+
do {
+ start_idx = list->next_secret_idx;
uv_list_secrets(list, start_idx, &list_rc, NULL);
if (list_rc != UVC_RC_EXECUTED && list_rc != UVC_RC_MORE_DATA) {
if (list_rc == UVC_RC_INV_CMD)
@@ -796,7 +799,6 @@ int uv_find_secret(const u8 secret_id[UV_SECRET_ID_LEN],
ret = find_secret_in_page(secret_id, list, secret);
if (ret == 0)
return ret;
- start_idx = list->next_secret_idx;
} while (list_rc == UVC_RC_MORE_DATA && start_idx < list->next_secret_idx);
return -ENOENT;
--
2.53.0
^ permalink raw reply related [flat|nested] 4+ messages in thread* Re: [PATCH v2 1/2] s390: uv: Fix loop condition in uv_find_secrets
2026-08-11 16:14 ` [PATCH v2 1/2] s390: uv: Fix loop condition in uv_find_secrets Steffen Eiden
@ 2026-08-12 10:21 ` Heiko Carstens
0 siblings, 0 replies; 4+ messages in thread
From: Heiko Carstens @ 2026-08-12 10:21 UTC (permalink / raw)
To: Steffen Eiden
Cc: Christian Borntraeger, Janosch Frank, Claudio Imbrenda,
David Hildenbrand, Vasily Gorbik, Alexander Gordeev,
Sven Schnelle, Christoph Schlameuss, Harald Freudenberger, kvm,
linux-s390, linux-kernel
On Tue, Aug 11, 2026 at 06:14:21PM +0200, Steffen Eiden wrote:
> Nothing modified `start_idx` between the assignment and the comparison,
> so the condition was always false and the do/while ran exactly once
> even when the UV returned UVC_RC_MORE_DATA. Systems with more than
> 85 UV secrets got -ENOENT for any secret past the first page.
If you would leave the first sentence away this would be much more readable.
Starting like above makes me wonder: "what is this all about? context?".
> Fix this by setting the start index at the beginning of the loop not at
Please add reference to the function where you fix a loop.
> the end. First test if there are more secrets left by comparing
> start_idx with list->next_secret_idx, and then set the start index to the
> next secret index.
>
> Fixes: 7c9137af2042 ("s390/uv: Retrieve UV secrets support")
> Acked-by: Claudio Imbrenda <imbrenda@linux.ibm.com>
> Signed-off-by: Steffen Eiden <seiden@linux.ibm.com>
> ---
> arch/s390/kernel/uv.c | 6 ++++--
> 1 file changed, 4 insertions(+), 2 deletions(-)
Please also fix the patch subject: It should be "s390/uv:"
instead of "s390: uv:".
^ permalink raw reply [flat|nested] 4+ messages in thread
* [PATCH v2 2/2] s390: uv: Prevent potential out-of-bounds read
2026-08-11 16:14 [PATCH v2 0/2] s390: uv: Various fixes for UV secrets Steffen Eiden
2026-08-11 16:14 ` [PATCH v2 1/2] s390: uv: Fix loop condition in uv_find_secrets Steffen Eiden
@ 2026-08-11 16:14 ` Steffen Eiden
1 sibling, 0 replies; 4+ messages in thread
From: Steffen Eiden @ 2026-08-11 16:14 UTC (permalink / raw)
To: Christian Borntraeger, Janosch Frank, Claudio Imbrenda
Cc: David Hildenbrand, Heiko Carstens, Vasily Gorbik,
Alexander Gordeev, Sven Schnelle, Christoph Schlameuss,
Harald Freudenberger, kvm, linux-s390, linux-kernel,
Steffen Eiden
When the system has more than 85 secrets, the uv_secret_list struct array
only holds up to 85 items per page, resulting in an out of bounds read
if the targeted secret is in the next page or not stored at all.
Fix this by looping only over number of stored secrets which is the per
sub-list count of stored secrets and not the overall count.
Fixes: 7c9137af2042 ("s390/uv: Retrieve UV secrets support")
Signed-off-by: Steffen Eiden <seiden@linux.ibm.com>
---
arch/s390/kernel/uv.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/arch/s390/kernel/uv.c b/arch/s390/kernel/uv.c
index d970b15ef126..e70acad09cd5 100644
--- a/arch/s390/kernel/uv.c
+++ b/arch/s390/kernel/uv.c
@@ -760,7 +760,7 @@ static int find_secret_in_page(const u8 secret_id[UV_SECRET_ID_LEN],
{
u16 i;
- for (i = 0; i < list->total_num_secrets; i++) {
+ for (i = 0; i < list->num_secr_stored; i++) {
if (memcmp(secret_id, list->secrets[i].id, UV_SECRET_ID_LEN) == 0) {
*secret = list->secrets[i].hdr;
return 0;
--
2.53.0
^ permalink raw reply related [flat|nested] 4+ messages in thread
end of thread, other threads:[~2026-08-12 10:21 UTC | newest]
Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-08-11 16:14 [PATCH v2 0/2] s390: uv: Various fixes for UV secrets Steffen Eiden
2026-08-11 16:14 ` [PATCH v2 1/2] s390: uv: Fix loop condition in uv_find_secrets Steffen Eiden
2026-08-12 10:21 ` Heiko Carstens
2026-08-11 16:14 ` [PATCH v2 2/2] s390: uv: Prevent potential out-of-bounds read Steffen Eiden
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).