* [PATCH] RDMA/rxe: Validate inline data range in user WQEs
@ 2026-09-24 10:05 Jiale Yao
2026-09-24 10:17 ` sashiko-bot
0 siblings, 1 reply; 6+ messages in thread
From: Jiale Yao @ 2026-09-24 10:05 UTC (permalink / raw)
To: Zhu Yanjun, Jason Gunthorpe, Leon Romanovsky, Moni Shoua,
Kamal Heib, Doug Ledford, Amir Vadai, Haggai Eran, linux-rdma,
linux-kernel
Cc: Jiale Yao
For a user QP, the send queue is an mmap'd ring which userspace writes
directly. rxe_post_send() only schedules the send task for such a QP,
so rxe_requester() must validate the WQE before using it.
Commit 126c757e4cd46f866ddc283143b58eb4d9bf52cd ("RDMA/rxe:
Validate num_sge/cur_sge before indexing wqe->dma.sge[]") added bounds
checks for two members of the userspace-controlled dma structure, but
left sge_offset unchecked. For an inline WQE, finish_packet() uses that
value directly as an index into inline_data[] and copies dma.resid bytes
from the resulting pointer into the packet payload.
A local user with access to uverbs can therefore put an out-of-range
sge_offset in the mmap'd SQ ring. This can disclose kernel memory in the
outgoing packet or cause a vmalloc out-of-bounds access.
Validate that the remaining inline data range fits in the per-WQE inline
area. Check the offset first and use subtraction for the length check to
avoid an integer overflow.
I reproduced this on Linux 7.3-rc4 with an RC user QP, IB_SEND_INLINE,
a 64-byte residual length, and sge_offset set to 0x100000. KASAN
reported:
BUG: KASAN: vmalloc-out-of-bounds in rxe_requester+0x1f27/0x4940
Read of size 64 at addr ffffc90000191250 by task kworker/u16:0/12
Workqueue: rxe_wq do_work
Call Trace:
__asan_memcpy
rxe_requester+0x1f27/0x4940
rxe_sender+0xe/0x30
do_work+0x184/0x3d0
process_scheduled_works+0x7c0/0xf10
Fixes: 8700e3e7c485 ("Soft RoCE driver")
Link: https://lore.kernel.org/all/20260708224534.1206-1-security@auditcode.ai/
Signed-off-by: Jiale Yao <yaojiale02@163.com>
---
drivers/infiniband/sw/rxe/rxe_req.c | 9 +++++++++
1 file changed, 9 insertions(+)
diff --git a/drivers/infiniband/sw/rxe/rxe_req.c b/drivers/infiniband/sw/rxe/rxe_req.c
index 24f5c044363f..f3b3f65d1d0c 100644
--- a/drivers/infiniband/sw/rxe/rxe_req.c
+++ b/drivers/infiniband/sw/rxe/rxe_req.c
@@ -716,6 +716,15 @@ int rxe_requester(struct rxe_qp *qp)
goto err;
}
+ if (unlikely((wqe->wr.send_flags & IB_SEND_INLINE) &&
+ (wqe->dma.sge_offset > qp->sq.max_inline ||
+ wqe->dma.resid >
+ qp->sq.max_inline - wqe->dma.sge_offset))) {
+ rxe_dbg_qp(qp, "invalid inline data range in send wqe\n");
+ wqe->status = IB_WC_LOC_QP_OP_ERR;
+ goto err;
+ }
+
if (rxe_wqe_is_fenced(qp, wqe)) {
qp->req.wait_fence = 1;
goto exit;
--
2.34.1
^ permalink raw reply related [flat|nested] 6+ messages in thread* Re: [PATCH] RDMA/rxe: Validate inline data range in user WQEs
2026-09-24 10:05 [PATCH] RDMA/rxe: Validate inline data range in user WQEs Jiale Yao
@ 2026-09-24 10:17 ` sashiko-bot
2026-09-25 17:23 ` Zhu Yanjun
0 siblings, 1 reply; 6+ messages in thread
From: sashiko-bot @ 2026-09-24 10:17 UTC (permalink / raw)
To: Jiale Yao; +Cc: linux-rdma
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [Critical] RDMA/rxe: TOCTOU bypass of inline WQE validation
--
commit e272f5be8d762ea2e78301c1339c440a19e1130b
Author: Jiale Yao <yaojiale02@163.com>
RDMA/rxe: Validate inline data range in user WQEs
This commit adds bounds validation for the inline data range in user WQEs to
prevent kernel memory disclosure or vmalloc out-of-bounds accesses. It checks
the offset and length against the per-WQE inline area to ensure they fit.
Link: https://lore.kernel.org/all/20260708224534.1206-1-security@auditcode.ai/
> diff --git a/drivers/infiniband/sw/rxe/rxe_req.c b/drivers/infiniband/sw/rxe/rxe_req.c
> index 53f7c1e7fe55b..06b7669d7f737 100644
> --- a/drivers/infiniband/sw/rxe/rxe_req.c
> +++ b/drivers/infiniband/sw/rxe/rxe_req.c
> @@ -716,6 +716,15 @@ int rxe_requester(struct rxe_qp *qp)
> goto err;
> }
>
> + if (unlikely((wqe->wr.send_flags & IB_SEND_INLINE) &&
> + (wqe->dma.sge_offset > qp->sq.max_inline ||
> + wqe->dma.resid >
> + qp->sq.max_inline - wqe->dma.sge_offset))) {
[Severity: Critical]
Since wqe points directly to a memory-mapped ring buffer shared with
userspace, can this validation be bypassed via a TOCTOU race?
A malicious userspace program could provide a valid sge_offset here to
pass the bounds check, but then concurrently modify wqe->dma.sge_offset
in shared memory to an out-of-bounds value.
When finish_packet() executes later on:
finish_packet() {
...
u8 *tmp = &wqe->dma.inline_data[wqe->dma.sge_offset];
...
}
Could it re-fetch the modified, now out-of-bounds sge_offset directly
from shared memory, resulting in the same kernel memory disclosure or
vmalloc out-of-bounds access this patch intends to fix?
> + rxe_dbg_qp(qp, "invalid inline data range in send wqe\n");
> + wqe->status = IB_WC_LOC_QP_OP_ERR;
> + goto err;
> + }
> +
> if (rxe_wqe_is_fenced(qp, wqe)) {
> qp->req.wait_fence = 1;
> goto exit;
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260924100515.502912-1-yaojiale02@163.com?part=1
^ permalink raw reply [flat|nested] 6+ messages in thread* Re: [PATCH] RDMA/rxe: Validate inline data range in user WQEs
2026-09-24 10:17 ` sashiko-bot
@ 2026-09-25 17:23 ` Zhu Yanjun
2026-10-04 4:57 ` jiale yao
0 siblings, 1 reply; 6+ messages in thread
From: Zhu Yanjun @ 2026-09-25 17:23 UTC (permalink / raw)
To: Jiale Yao; +Cc: linux-rdma
在 2026/9/24 3:17, sashiko-bot@kernel.org 写道:
> Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
> - [Critical] RDMA/rxe: TOCTOU bypass of inline WQE validation
> --
>
> commit e272f5be8d762ea2e78301c1339c440a19e1130b
> Author: Jiale Yao <yaojiale02@163.com>
>
> RDMA/rxe: Validate inline data range in user WQEs
>
> This commit adds bounds validation for the inline data range in user WQEs to
> prevent kernel memory disclosure or vmalloc out-of-bounds accesses. It checks
> the offset and length against the per-WQE inline area to ensure they fit.
>
> Link: https://lore.kernel.org/all/20260708224534.1206-1-security@auditcode.ai/
>
>> diff --git a/drivers/infiniband/sw/rxe/rxe_req.c b/drivers/infiniband/sw/rxe/rxe_req.c
>> index 53f7c1e7fe55b..06b7669d7f737 100644
>> --- a/drivers/infiniband/sw/rxe/rxe_req.c
>> +++ b/drivers/infiniband/sw/rxe/rxe_req.c
>> @@ -716,6 +716,15 @@ int rxe_requester(struct rxe_qp *qp)
>> goto err;
>> }
>>
>> + if (unlikely((wqe->wr.send_flags & IB_SEND_INLINE) &&
>> + (wqe->dma.sge_offset > qp->sq.max_inline ||
>> + wqe->dma.resid >
>> + qp->sq.max_inline - wqe->dma.sge_offset))) {
>
> [Severity: Critical]
> Since wqe points directly to a memory-mapped ring buffer shared with
> userspace, can this validation be bypassed via a TOCTOU race?
>
> A malicious userspace program could provide a valid sge_offset here to
> pass the bounds check, but then concurrently modify wqe->dma.sge_offset
> in shared memory to an out-of-bounds value.
>
> When finish_packet() executes later on:
>
> finish_packet() {
> ...
> u8 *tmp = &wqe->dma.inline_data[wqe->dma.sge_offset];
> ...
> }
>
> Could it re-fetch the modified, now out-of-bounds sge_offset directly
> from shared memory, resulting in the same kernel memory disclosure or
> vmalloc out-of-bounds access this patch intends to fix?
Hi, Jiale
Please fix the problem that Sashiko mentioned. Then send out a new commit.
Thanks a lot.
Yanjun Zhu
>
>> + rxe_dbg_qp(qp, "invalid inline data range in send wqe\n");
>> + wqe->status = IB_WC_LOC_QP_OP_ERR;
>> + goto err;
>> + }
>> +
>> if (rxe_wqe_is_fenced(qp, wqe)) {
>> qp->req.wait_fence = 1;
>> goto exit;
>
^ permalink raw reply [flat|nested] 6+ messages in thread* Re:Re: [PATCH] RDMA/rxe: Validate inline data range in user WQEs
2026-09-25 17:23 ` Zhu Yanjun
@ 2026-10-04 4:57 ` jiale yao
2026-10-04 6:14 ` Zhu Yanjun
0 siblings, 1 reply; 6+ messages in thread
From: jiale yao @ 2026-10-04 4:57 UTC (permalink / raw)
To: Zhu Yanjun; +Cc: linux-rdma
At 2026-09-26 01:23:28, "Zhu Yanjun" <yanjun.zhu@linux.dev> wrote:
>在 2026/9/24 3:17, sashiko-bot@kernel.org 写道:
>> Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
>> - [Critical] RDMA/rxe: TOCTOU bypass of inline WQE validation
>> --
>>
>> commit e272f5be8d762ea2e78301c1339c440a19e1130b
>> Author: Jiale Yao <yaojiale02@163.com>
>>
>> RDMA/rxe: Validate inline data range in user WQEs
>>
>> This commit adds bounds validation for the inline data range in user WQEs to
>> prevent kernel memory disclosure or vmalloc out-of-bounds accesses. It checks
>> the offset and length against the per-WQE inline area to ensure they fit.
>>
>> Link: https://lore.kernel.org/all/20260708224534.1206-1-security@auditcode.ai/
>>
>>> diff --git a/drivers/infiniband/sw/rxe/rxe_req.c b/drivers/infiniband/sw/rxe/rxe_req.c
>>> index 53f7c1e7fe55b..06b7669d7f737 100644
>>> --- a/drivers/infiniband/sw/rxe/rxe_req.c
>>> +++ b/drivers/infiniband/sw/rxe/rxe_req.c
>>> @@ -716,6 +716,15 @@ int rxe_requester(struct rxe_qp *qp)
>>> goto err;
>>> }
>>>
>>> + if (unlikely((wqe->wr.send_flags & IB_SEND_INLINE) &&
>>> + (wqe->dma.sge_offset > qp->sq.max_inline ||
>>> + wqe->dma.resid >
>>> + qp->sq.max_inline - wqe->dma.sge_offset))) {
>>
>> [Severity: Critical]
>> Since wqe points directly to a memory-mapped ring buffer shared with
>> userspace, can this validation be bypassed via a TOCTOU race?
>>
>> A malicious userspace program could provide a valid sge_offset here to
>> pass the bounds check, but then concurrently modify wqe->dma.sge_offset
>> in shared memory to an out-of-bounds value.
>>
>> When finish_packet() executes later on:
>>
>> finish_packet() {
>> ...
>> u8 *tmp = &wqe->dma.inline_data[wqe->dma.sge_offset];
>> ...
>> }
>>
>> Could it re-fetch the modified, now out-of-bounds sge_offset directly
>> from shared memory, resulting in the same kernel memory disclosure or
>> vmalloc out-of-bounds access this patch intends to fix?
>
>Hi, Jiale
>
>Please fix the problem that Sashiko mentioned. Then send out a new commit.
>
>Thanks a lot.
>Yanjun Zhu
How about this one,
https://lore.kernel.org/all/20260926070403.3005250-1-yaojiale02@163.com/
>
>>
>>> + rxe_dbg_qp(qp, "invalid inline data range in send wqe\n");
>>> + wqe->status = IB_WC_LOC_QP_OP_ERR;
>>> + goto err;
>>> + }
>>> +
>>> if (rxe_wqe_is_fenced(qp, wqe)) {
>>> qp->req.wait_fence = 1;
>>> goto exit;
>>
^ permalink raw reply [flat|nested] 6+ messages in thread* Re: [PATCH] RDMA/rxe: Validate inline data range in user WQEs
2026-10-04 4:57 ` jiale yao
@ 2026-10-04 6:14 ` Zhu Yanjun
2026-10-04 7:02 ` jiale yao
0 siblings, 1 reply; 6+ messages in thread
From: Zhu Yanjun @ 2026-10-04 6:14 UTC (permalink / raw)
To: jiale yao, yanjun.zhu@linux.dev; +Cc: linux-rdma
在 2026/10/3 21:57, jiale yao 写道:
>> Hi, Jiale
>>
>> Please fix the problem that Sashiko mentioned. Then send out a new commit.
>>
>> Thanks a lot.
>> Yanjun Zhu
> How about this one,
> https://lore.kernel.org/all/20260926070403.3005250-1-yaojiale02@163.com/
Sashiko still complains something. Please try to fix it.
Thanks a lot.
Yanjun Zhu
>>>> + rxe_dbg_qp(qp, "invalid inline data range in send wqe\n");
>>>> + wqe->status = IB_WC_LOC_QP_OP_ERR;
>>>> + goto err;
>>>> + }
>>>> +
>>>> if (rxe_wqe_is_fenced(qp, wqe)) {
>>>> qp->req.wait_fence = 1;
>>>> goto exit;
--
Best Regards,
Yanjun.Zhu
^ permalink raw reply [flat|nested] 6+ messages in thread* Re:Re: [PATCH] RDMA/rxe: Validate inline data range in user WQEs
2026-10-04 6:14 ` Zhu Yanjun
@ 2026-10-04 7:02 ` jiale yao
0 siblings, 0 replies; 6+ messages in thread
From: jiale yao @ 2026-10-04 7:02 UTC (permalink / raw)
To: Zhu Yanjun; +Cc: linux-rdma
Hi Yanjun,
At 2026-10-04 14:14:04, "Zhu Yanjun" <yanjun.zhu@linux.dev> wrote:
>
>在 2026/10/3 21:57, jiale yao 写道:
>>> Hi, Jiale
>>>
>>> Please fix the problem that Sashiko mentioned. Then send out a new commit.
>>>
>>> Thanks a lot.
>>> Yanjun Zhu
>> How about this one,
>> https://lore.kernel.org/all/20260926070403.3005250-1-yaojiale02@163.com/
>
>Sashiko still complains something. Please try to fix it.
Fixed it in, https://lore.kernel.org/all/20261004064445.1488753-1-yaojiale02@163.com/
Sashiko has reviewed this patch and found no issues.
>
>Thanks a lot.
>
>Yanjun Zhu
>
>>>>> + rxe_dbg_qp(qp, "invalid inline data range in send wqe\n");
>>>>> + wqe->status = IB_WC_LOC_QP_OP_ERR;
>>>>> + goto err;
>>>>> + }
>>>>> +
>>>>> if (rxe_wqe_is_fenced(qp, wqe)) {
>>>>> qp->req.wait_fence = 1;
>>>>> goto exit;
>
>--
>Best Regards,
>Yanjun.Zhu
Jiale
^ permalink raw reply [flat|nested] 6+ messages in thread
end of thread, other threads:[~2026-10-04 7:02 UTC | newest]
Thread overview: 6+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-24 10:05 [PATCH] RDMA/rxe: Validate inline data range in user WQEs Jiale Yao
2026-09-24 10:17 ` sashiko-bot
2026-09-25 17:23 ` Zhu Yanjun
2026-10-04 4:57 ` jiale yao
2026-10-04 6:14 ` Zhu Yanjun
2026-10-04 7:02 ` jiale yao
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox