Linux RDMA and InfiniBand development
 help / color / mirror / Atom feed
* [PATCH] RDMA/rxe: Validate inline data range in user WQEs
@ 2026-09-24 10:05 Jiale Yao
  2026-09-24 10:17 ` sashiko-bot
  0 siblings, 1 reply; 6+ messages in thread
From: Jiale Yao @ 2026-09-24 10:05 UTC (permalink / raw)
  To: Zhu Yanjun, Jason Gunthorpe, Leon Romanovsky, Moni Shoua,
	Kamal Heib, Doug Ledford, Amir Vadai, Haggai Eran, linux-rdma,
	linux-kernel
  Cc: Jiale Yao

For a user QP, the send queue is an mmap'd ring which userspace writes
directly.  rxe_post_send() only schedules the send task for such a QP,
so rxe_requester() must validate the WQE before using it.

Commit 126c757e4cd46f866ddc283143b58eb4d9bf52cd ("RDMA/rxe:
Validate num_sge/cur_sge before indexing wqe->dma.sge[]") added bounds
checks for two members of the userspace-controlled dma structure, but
left sge_offset unchecked.  For an inline WQE, finish_packet() uses that
value directly as an index into inline_data[] and copies dma.resid bytes
from the resulting pointer into the packet payload.

A local user with access to uverbs can therefore put an out-of-range
sge_offset in the mmap'd SQ ring.  This can disclose kernel memory in the
outgoing packet or cause a vmalloc out-of-bounds access.

Validate that the remaining inline data range fits in the per-WQE inline
area.  Check the offset first and use subtraction for the length check to
avoid an integer overflow.

I reproduced this on Linux 7.3-rc4 with an RC user QP, IB_SEND_INLINE,
a 64-byte residual length, and sge_offset set to 0x100000.  KASAN
reported:

  BUG: KASAN: vmalloc-out-of-bounds in rxe_requester+0x1f27/0x4940
  Read of size 64 at addr ffffc90000191250 by task kworker/u16:0/12
  Workqueue: rxe_wq do_work
  Call Trace:
   __asan_memcpy
   rxe_requester+0x1f27/0x4940
   rxe_sender+0xe/0x30
   do_work+0x184/0x3d0
   process_scheduled_works+0x7c0/0xf10

Fixes: 8700e3e7c485 ("Soft RoCE driver")
Link: https://lore.kernel.org/all/20260708224534.1206-1-security@auditcode.ai/
Signed-off-by: Jiale Yao <yaojiale02@163.com>
---
 drivers/infiniband/sw/rxe/rxe_req.c | 9 +++++++++
 1 file changed, 9 insertions(+)

diff --git a/drivers/infiniband/sw/rxe/rxe_req.c b/drivers/infiniband/sw/rxe/rxe_req.c
index 24f5c044363f..f3b3f65d1d0c 100644
--- a/drivers/infiniband/sw/rxe/rxe_req.c
+++ b/drivers/infiniband/sw/rxe/rxe_req.c
@@ -716,6 +716,15 @@ int rxe_requester(struct rxe_qp *qp)
 		goto err;
 	}
 
+	if (unlikely((wqe->wr.send_flags & IB_SEND_INLINE) &&
+		     (wqe->dma.sge_offset > qp->sq.max_inline ||
+		      wqe->dma.resid >
+		      qp->sq.max_inline - wqe->dma.sge_offset))) {
+		rxe_dbg_qp(qp, "invalid inline data range in send wqe\n");
+		wqe->status = IB_WC_LOC_QP_OP_ERR;
+		goto err;
+	}
+
 	if (rxe_wqe_is_fenced(qp, wqe)) {
 		qp->req.wait_fence = 1;
 		goto exit;
-- 
2.34.1


^ permalink raw reply related	[flat|nested] 6+ messages in thread

* Re: [PATCH] RDMA/rxe: Validate inline data range in user WQEs
  2026-09-24 10:05 [PATCH] RDMA/rxe: Validate inline data range in user WQEs Jiale Yao
@ 2026-09-24 10:17 ` sashiko-bot
  2026-09-25 17:23   ` Zhu Yanjun
  0 siblings, 1 reply; 6+ messages in thread
From: sashiko-bot @ 2026-09-24 10:17 UTC (permalink / raw)
  To: Jiale Yao; +Cc: linux-rdma

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [Critical] RDMA/rxe: TOCTOU bypass of inline WQE validation
--

commit e272f5be8d762ea2e78301c1339c440a19e1130b
Author: Jiale Yao <yaojiale02@163.com>

RDMA/rxe: Validate inline data range in user WQEs

This commit adds bounds validation for the inline data range in user WQEs to
prevent kernel memory disclosure or vmalloc out-of-bounds accesses. It checks
the offset and length against the per-WQE inline area to ensure they fit.

Link: https://lore.kernel.org/all/20260708224534.1206-1-security@auditcode.ai/

> diff --git a/drivers/infiniband/sw/rxe/rxe_req.c b/drivers/infiniband/sw/rxe/rxe_req.c
> index 53f7c1e7fe55b..06b7669d7f737 100644
> --- a/drivers/infiniband/sw/rxe/rxe_req.c
> +++ b/drivers/infiniband/sw/rxe/rxe_req.c
> @@ -716,6 +716,15 @@ int rxe_requester(struct rxe_qp *qp)
>  		goto err;
>  	}
>  
> +	if (unlikely((wqe->wr.send_flags & IB_SEND_INLINE) &&
> +		     (wqe->dma.sge_offset > qp->sq.max_inline ||
> +		      wqe->dma.resid >
> +		      qp->sq.max_inline - wqe->dma.sge_offset))) {

[Severity: Critical]
Since wqe points directly to a memory-mapped ring buffer shared with
userspace, can this validation be bypassed via a TOCTOU race?

A malicious userspace program could provide a valid sge_offset here to
pass the bounds check, but then concurrently modify wqe->dma.sge_offset
in shared memory to an out-of-bounds value.

When finish_packet() executes later on:

finish_packet() {
    ...
    u8 *tmp = &wqe->dma.inline_data[wqe->dma.sge_offset];
    ...
}

Could it re-fetch the modified, now out-of-bounds sge_offset directly
from shared memory, resulting in the same kernel memory disclosure or
vmalloc out-of-bounds access this patch intends to fix?

> +		rxe_dbg_qp(qp, "invalid inline data range in send wqe\n");
> +		wqe->status = IB_WC_LOC_QP_OP_ERR;
> +		goto err;
> +	}
> +
>  	if (rxe_wqe_is_fenced(qp, wqe)) {
>  		qp->req.wait_fence = 1;
>  		goto exit;

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260924100515.502912-1-yaojiale02@163.com?part=1

^ permalink raw reply	[flat|nested] 6+ messages in thread

* Re: [PATCH] RDMA/rxe: Validate inline data range in user WQEs
  2026-09-24 10:17 ` sashiko-bot
@ 2026-09-25 17:23   ` Zhu Yanjun
  2026-10-04  4:57     ` jiale yao
  0 siblings, 1 reply; 6+ messages in thread
From: Zhu Yanjun @ 2026-09-25 17:23 UTC (permalink / raw)
  To: Jiale Yao; +Cc: linux-rdma

在 2026/9/24 3:17, sashiko-bot@kernel.org 写道:
> Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
> - [Critical] RDMA/rxe: TOCTOU bypass of inline WQE validation
> --
> 
> commit e272f5be8d762ea2e78301c1339c440a19e1130b
> Author: Jiale Yao <yaojiale02@163.com>
> 
> RDMA/rxe: Validate inline data range in user WQEs
> 
> This commit adds bounds validation for the inline data range in user WQEs to
> prevent kernel memory disclosure or vmalloc out-of-bounds accesses. It checks
> the offset and length against the per-WQE inline area to ensure they fit.
> 
> Link: https://lore.kernel.org/all/20260708224534.1206-1-security@auditcode.ai/
> 
>> diff --git a/drivers/infiniband/sw/rxe/rxe_req.c b/drivers/infiniband/sw/rxe/rxe_req.c
>> index 53f7c1e7fe55b..06b7669d7f737 100644
>> --- a/drivers/infiniband/sw/rxe/rxe_req.c
>> +++ b/drivers/infiniband/sw/rxe/rxe_req.c
>> @@ -716,6 +716,15 @@ int rxe_requester(struct rxe_qp *qp)
>>   		goto err;
>>   	}
>>   
>> +	if (unlikely((wqe->wr.send_flags & IB_SEND_INLINE) &&
>> +		     (wqe->dma.sge_offset > qp->sq.max_inline ||
>> +		      wqe->dma.resid >
>> +		      qp->sq.max_inline - wqe->dma.sge_offset))) {
> 
> [Severity: Critical]
> Since wqe points directly to a memory-mapped ring buffer shared with
> userspace, can this validation be bypassed via a TOCTOU race?
> 
> A malicious userspace program could provide a valid sge_offset here to
> pass the bounds check, but then concurrently modify wqe->dma.sge_offset
> in shared memory to an out-of-bounds value.
> 
> When finish_packet() executes later on:
> 
> finish_packet() {
>      ...
>      u8 *tmp = &wqe->dma.inline_data[wqe->dma.sge_offset];
>      ...
> }
> 
> Could it re-fetch the modified, now out-of-bounds sge_offset directly
> from shared memory, resulting in the same kernel memory disclosure or
> vmalloc out-of-bounds access this patch intends to fix?

Hi, Jiale

Please fix the problem that Sashiko mentioned. Then send out a new commit.

Thanks a lot.
Yanjun Zhu

> 
>> +		rxe_dbg_qp(qp, "invalid inline data range in send wqe\n");
>> +		wqe->status = IB_WC_LOC_QP_OP_ERR;
>> +		goto err;
>> +	}
>> +
>>   	if (rxe_wqe_is_fenced(qp, wqe)) {
>>   		qp->req.wait_fence = 1;
>>   		goto exit;
> 


^ permalink raw reply	[flat|nested] 6+ messages in thread

* Re:Re: [PATCH] RDMA/rxe: Validate inline data range in user WQEs
  2026-09-25 17:23   ` Zhu Yanjun
@ 2026-10-04  4:57     ` jiale yao
  2026-10-04  6:14       ` Zhu Yanjun
  0 siblings, 1 reply; 6+ messages in thread
From: jiale yao @ 2026-10-04  4:57 UTC (permalink / raw)
  To: Zhu Yanjun; +Cc: linux-rdma

At 2026-09-26 01:23:28, "Zhu Yanjun" <yanjun.zhu@linux.dev> wrote:
>在 2026/9/24 3:17, sashiko-bot@kernel.org 写道:
>> Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
>> - [Critical] RDMA/rxe: TOCTOU bypass of inline WQE validation
>> --
>> 
>> commit e272f5be8d762ea2e78301c1339c440a19e1130b
>> Author: Jiale Yao <yaojiale02@163.com>
>> 
>> RDMA/rxe: Validate inline data range in user WQEs
>> 
>> This commit adds bounds validation for the inline data range in user WQEs to
>> prevent kernel memory disclosure or vmalloc out-of-bounds accesses. It checks
>> the offset and length against the per-WQE inline area to ensure they fit.
>> 
>> Link: https://lore.kernel.org/all/20260708224534.1206-1-security@auditcode.ai/
>> 
>>> diff --git a/drivers/infiniband/sw/rxe/rxe_req.c b/drivers/infiniband/sw/rxe/rxe_req.c
>>> index 53f7c1e7fe55b..06b7669d7f737 100644
>>> --- a/drivers/infiniband/sw/rxe/rxe_req.c
>>> +++ b/drivers/infiniband/sw/rxe/rxe_req.c
>>> @@ -716,6 +716,15 @@ int rxe_requester(struct rxe_qp *qp)
>>>   		goto err;
>>>   	}
>>>   
>>> +	if (unlikely((wqe->wr.send_flags & IB_SEND_INLINE) &&
>>> +		     (wqe->dma.sge_offset > qp->sq.max_inline ||
>>> +		      wqe->dma.resid >
>>> +		      qp->sq.max_inline - wqe->dma.sge_offset))) {
>> 
>> [Severity: Critical]
>> Since wqe points directly to a memory-mapped ring buffer shared with
>> userspace, can this validation be bypassed via a TOCTOU race?
>> 
>> A malicious userspace program could provide a valid sge_offset here to
>> pass the bounds check, but then concurrently modify wqe->dma.sge_offset
>> in shared memory to an out-of-bounds value.
>> 
>> When finish_packet() executes later on:
>> 
>> finish_packet() {
>>      ...
>>      u8 *tmp = &wqe->dma.inline_data[wqe->dma.sge_offset];
>>      ...
>> }
>> 
>> Could it re-fetch the modified, now out-of-bounds sge_offset directly
>> from shared memory, resulting in the same kernel memory disclosure or
>> vmalloc out-of-bounds access this patch intends to fix?
>
>Hi, Jiale
>
>Please fix the problem that Sashiko mentioned. Then send out a new commit.
>
>Thanks a lot.
>Yanjun Zhu
How about this one,
https://lore.kernel.org/all/20260926070403.3005250-1-yaojiale02@163.com/
>
>> 
>>> +		rxe_dbg_qp(qp, "invalid inline data range in send wqe\n");
>>> +		wqe->status = IB_WC_LOC_QP_OP_ERR;
>>> +		goto err;
>>> +	}
>>> +
>>>   	if (rxe_wqe_is_fenced(qp, wqe)) {
>>>   		qp->req.wait_fence = 1;
>>>   		goto exit;
>> 

^ permalink raw reply	[flat|nested] 6+ messages in thread

* Re: [PATCH] RDMA/rxe: Validate inline data range in user WQEs
  2026-10-04  4:57     ` jiale yao
@ 2026-10-04  6:14       ` Zhu Yanjun
  2026-10-04  7:02         ` jiale yao
  0 siblings, 1 reply; 6+ messages in thread
From: Zhu Yanjun @ 2026-10-04  6:14 UTC (permalink / raw)
  To: jiale yao, yanjun.zhu@linux.dev; +Cc: linux-rdma


在 2026/10/3 21:57, jiale yao 写道:
>> Hi, Jiale
>>
>> Please fix the problem that Sashiko mentioned. Then send out a new commit.
>>
>> Thanks a lot.
>> Yanjun Zhu
> How about this one,
> https://lore.kernel.org/all/20260926070403.3005250-1-yaojiale02@163.com/

Sashiko still complains something. Please try to fix it.

Thanks a lot.

Yanjun Zhu

>>>> +		rxe_dbg_qp(qp, "invalid inline data range in send wqe\n");
>>>> +		wqe->status = IB_WC_LOC_QP_OP_ERR;
>>>> +		goto err;
>>>> +	}
>>>> +
>>>>    	if (rxe_wqe_is_fenced(qp, wqe)) {
>>>>    		qp->req.wait_fence = 1;
>>>>    		goto exit;

-- 
Best Regards,
Yanjun.Zhu


^ permalink raw reply	[flat|nested] 6+ messages in thread

* Re:Re: [PATCH] RDMA/rxe: Validate inline data range in user WQEs
  2026-10-04  6:14       ` Zhu Yanjun
@ 2026-10-04  7:02         ` jiale yao
  0 siblings, 0 replies; 6+ messages in thread
From: jiale yao @ 2026-10-04  7:02 UTC (permalink / raw)
  To: Zhu Yanjun; +Cc: linux-rdma

Hi Yanjun,
At 2026-10-04 14:14:04, "Zhu Yanjun" <yanjun.zhu@linux.dev> wrote:
>
>在 2026/10/3 21:57, jiale yao 写道:
>>> Hi, Jiale
>>>
>>> Please fix the problem that Sashiko mentioned. Then send out a new commit.
>>>
>>> Thanks a lot.
>>> Yanjun Zhu
>> How about this one,
>> https://lore.kernel.org/all/20260926070403.3005250-1-yaojiale02@163.com/
>
>Sashiko still complains something. Please try to fix it.

Fixed it in, https://lore.kernel.org/all/20261004064445.1488753-1-yaojiale02@163.com/
Sashiko has reviewed this patch and found no issues. 

>
>Thanks a lot.
>
>Yanjun Zhu
>
>>>>> +		rxe_dbg_qp(qp, "invalid inline data range in send wqe\n");
>>>>> +		wqe->status = IB_WC_LOC_QP_OP_ERR;
>>>>> +		goto err;
>>>>> +	}
>>>>> +
>>>>>    	if (rxe_wqe_is_fenced(qp, wqe)) {
>>>>>    		qp->req.wait_fence = 1;
>>>>>    		goto exit;
>
>-- 
>Best Regards,
>Yanjun.Zhu

Jiale

^ permalink raw reply	[flat|nested] 6+ messages in thread

end of thread, other threads:[~2026-10-04  7:02 UTC | newest]

Thread overview: 6+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-24 10:05 [PATCH] RDMA/rxe: Validate inline data range in user WQEs Jiale Yao
2026-09-24 10:17 ` sashiko-bot
2026-09-25 17:23   ` Zhu Yanjun
2026-10-04  4:57     ` jiale yao
2026-10-04  6:14       ` Zhu Yanjun
2026-10-04  7:02         ` jiale yao

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox