From: Jiale Yao <yaojiale02@163.com>
To: Zhu Yanjun <zyjzyj2000@gmail.com>, Jason Gunthorpe <jgg@ziepe.ca>,
Leon Romanovsky <leon@kernel.org>,
Moni Shoua <monis@mellanox.com>, Kamal Heib <kamalh@mellanox.com>,
Doug Ledford <dledford@redhat.com>,
Amir Vadai <amirv@mellanox.com>,
Haggai Eran <haggaie@mellanox.com>,
linux-rdma@vger.kernel.org, linux-kernel@vger.kernel.org
Cc: Jiale Yao <yaojiale02@163.com>
Subject: [PATCH] RDMA/rxe: Validate inline data range in user WQEs
Date: Thu, 24 Sep 2026 18:05:14 +0800 [thread overview]
Message-ID: <20260924100515.502912-1-yaojiale02@163.com> (raw)
For a user QP, the send queue is an mmap'd ring which userspace writes
directly. rxe_post_send() only schedules the send task for such a QP,
so rxe_requester() must validate the WQE before using it.
Commit 126c757e4cd46f866ddc283143b58eb4d9bf52cd ("RDMA/rxe:
Validate num_sge/cur_sge before indexing wqe->dma.sge[]") added bounds
checks for two members of the userspace-controlled dma structure, but
left sge_offset unchecked. For an inline WQE, finish_packet() uses that
value directly as an index into inline_data[] and copies dma.resid bytes
from the resulting pointer into the packet payload.
A local user with access to uverbs can therefore put an out-of-range
sge_offset in the mmap'd SQ ring. This can disclose kernel memory in the
outgoing packet or cause a vmalloc out-of-bounds access.
Validate that the remaining inline data range fits in the per-WQE inline
area. Check the offset first and use subtraction for the length check to
avoid an integer overflow.
I reproduced this on Linux 7.3-rc4 with an RC user QP, IB_SEND_INLINE,
a 64-byte residual length, and sge_offset set to 0x100000. KASAN
reported:
BUG: KASAN: vmalloc-out-of-bounds in rxe_requester+0x1f27/0x4940
Read of size 64 at addr ffffc90000191250 by task kworker/u16:0/12
Workqueue: rxe_wq do_work
Call Trace:
__asan_memcpy
rxe_requester+0x1f27/0x4940
rxe_sender+0xe/0x30
do_work+0x184/0x3d0
process_scheduled_works+0x7c0/0xf10
Fixes: 8700e3e7c485 ("Soft RoCE driver")
Link: https://lore.kernel.org/all/20260708224534.1206-1-security@auditcode.ai/
Signed-off-by: Jiale Yao <yaojiale02@163.com>
---
drivers/infiniband/sw/rxe/rxe_req.c | 9 +++++++++
1 file changed, 9 insertions(+)
diff --git a/drivers/infiniband/sw/rxe/rxe_req.c b/drivers/infiniband/sw/rxe/rxe_req.c
index 24f5c044363f..f3b3f65d1d0c 100644
--- a/drivers/infiniband/sw/rxe/rxe_req.c
+++ b/drivers/infiniband/sw/rxe/rxe_req.c
@@ -716,6 +716,15 @@ int rxe_requester(struct rxe_qp *qp)
goto err;
}
+ if (unlikely((wqe->wr.send_flags & IB_SEND_INLINE) &&
+ (wqe->dma.sge_offset > qp->sq.max_inline ||
+ wqe->dma.resid >
+ qp->sq.max_inline - wqe->dma.sge_offset))) {
+ rxe_dbg_qp(qp, "invalid inline data range in send wqe\n");
+ wqe->status = IB_WC_LOC_QP_OP_ERR;
+ goto err;
+ }
+
if (rxe_wqe_is_fenced(qp, wqe)) {
qp->req.wait_fence = 1;
goto exit;
--
2.34.1
next reply other threads:[~2026-09-24 10:05 UTC|newest]
Thread overview: 6+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-24 10:05 Jiale Yao [this message]
2026-09-24 10:17 ` [PATCH] RDMA/rxe: Validate inline data range in user WQEs sashiko-bot
2026-09-25 17:23 ` Zhu Yanjun
2026-10-04 4:57 ` jiale yao
2026-10-04 6:14 ` Zhu Yanjun
2026-10-04 7:02 ` jiale yao
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260924100515.502912-1-yaojiale02@163.com \
--to=yaojiale02@163.com \
--cc=amirv@mellanox.com \
--cc=dledford@redhat.com \
--cc=haggaie@mellanox.com \
--cc=jgg@ziepe.ca \
--cc=kamalh@mellanox.com \
--cc=leon@kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-rdma@vger.kernel.org \
--cc=monis@mellanox.com \
--cc=zyjzyj2000@gmail.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox