From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 8D42A31D366; Wed, 30 Sep 2026 15:39:08 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790782752; cv=none; b=Fyy9WG7kUItd00ibfKS6DBp/3C/qxs/qY6GZI9oQbmXQAX+pNugirrVbFwO5ki2zqFZ9GylBZYB2WhKYvMyWTDYJREeW00WXYZibFNdj5H38Fq8JfTNWz2nGINBH+a3uAshxVhIG4xpUeqi4l0kgVn4ZiVG1ftzn8+5xJDkfygo= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790782752; c=relaxed/simple; bh=wBdkLOujItxWKeREStz18P5IHwbEQd3kffM0reIBxx0=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=Awtjq11ltBqHvtg7q0dbMaHQWHeT9jtp6Bws+RlksgIUvceSfWpeV3dLy/o0HHi6SYAf1Hw2gWnvRf3wNN5vofUFh/8GW2nhcNRT5d1sMXi9Dsyv6SLnoY5jpBhgYKpCMzS2c3mprmzo5O6QKpb9kyDZj8Uook4u+aX6p4lHe/U= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=qZgAU6UZ; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="qZgAU6UZ" Received: by smtp.kernel.org (Postfix) with ESMTPSA id DA3351F000FF; Wed, 30 Sep 2026 15:39:05 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1790782746; bh=j50hhx2UZEyyhZCH5/kQ0i2i25OZ6D/57iRMzXpW6cI=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=qZgAU6UZ1IbaLDQIfVFkuuDGwVT7tgW4Zuj7kHV99emCfj0zQNFk5kW7SjkyZh3vD ACGmFQKLFacdldWmqPgFOfT0pVfogK5arEEMOeLCHcQ6xp/heWlccJRdnb4nDVvGX4 Yu1Iet5mSJKQm6KJW/k3a/KOWxQLXl5eIt+Cirqo= From: Greg Kroah-Hartman To: stable@vger.kernel.org Cc: Greg Kroah-Hartman , patches@lists.linux.dev, Yousef Alhouseen , Juergen Gross , Sasha Levin Subject: [PATCH 5.10 153/595] xen/gntalloc: validate grant count before allocation Date: Wed, 30 Sep 2026 17:20:46 +0200 Message-ID: <20260930152351.025539148@linuxfoundation.org> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260930152347.700140858@linuxfoundation.org> References: <20260930152347.700140858@linuxfoundation.org> User-Agent: quilt/0.69 X-stable: review X-Patchwork-Hint: ignore Precedence: bulk X-Mailing-List: patches@lists.linux.dev List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit 5.10-stable review patch. If anyone has any objections, please let me know. ------------------ From: Yousef Alhouseen [ Upstream commit 2299822f3f466b5dcad2377bf63986199f881a6b ] gntalloc_ioctl_alloc() allocates the grant-id array before checking whether the requested count fits within the global grant limit. Counts above that limit cannot succeed, so reject them before the user-controlled allocation reaches kcalloc(). Use a subtraction-based check while holding gref_mutex so adding the requested count cannot wrap. Also cast the count before advancing the per-file index so the page-size multiplication is performed in 64-bit arithmetic. Signed-off-by: Yousef Alhouseen Reviewed-by: Juergen Gross Signed-off-by: Juergen Gross Message-ID: <20260626223805.43781-3-alhouseenyousef@gmail.com> Signed-off-by: Sasha Levin --- drivers/xen/gntalloc.c | 13 +++++++++++-- 1 file changed, 11 insertions(+), 2 deletions(-) diff --git a/drivers/xen/gntalloc.c b/drivers/xen/gntalloc.c index edb0acd0b8323..e95dd0b9b6ba9 100644 --- a/drivers/xen/gntalloc.c +++ b/drivers/xen/gntalloc.c @@ -275,6 +275,7 @@ static long gntalloc_ioctl_alloc(struct gntalloc_file_private_data *priv, int rc = 0; struct ioctl_gntalloc_alloc_gref op; uint32_t *gref_ids; + unsigned int limit_snapshot; pr_debug("%s: priv %p\n", __func__, priv); @@ -283,6 +284,12 @@ static long gntalloc_ioctl_alloc(struct gntalloc_file_private_data *priv, goto out; } + limit_snapshot = READ_ONCE(limit); + if (op.count > limit_snapshot) { + rc = -ENOSPC; + goto out; + } + gref_ids = kcalloc(op.count, sizeof(gref_ids[0]), GFP_KERNEL); if (!gref_ids) { rc = -ENOMEM; @@ -295,14 +302,16 @@ static long gntalloc_ioctl_alloc(struct gntalloc_file_private_data *priv, * are about to enforce, removing them here is a good idea. */ do_cleanup(); - if (gref_size + op.count > limit) { + limit_snapshot = READ_ONCE(limit); + if (gref_size > limit_snapshot || + op.count > limit_snapshot - gref_size) { mutex_unlock(&gref_mutex); rc = -ENOSPC; goto out_free; } gref_size += op.count; op.index = priv->index; - priv->index += op.count * PAGE_SIZE; + priv->index += (uint64_t)op.count * PAGE_SIZE; mutex_unlock(&gref_mutex); rc = add_grefs(&op, gref_ids, priv); -- 2.53.0