Linux RDMA and InfiniBand development
 help / color / mirror / Atom feed
* [PATCH] RDMA/rxe: validate receive WQE cursor after snapshot
@ 2026-10-07  6:30 Sung Byeongchan
  2026-10-07  6:46 ` sashiko-bot
  0 siblings, 1 reply; 2+ messages in thread
From: Sung Byeongchan @ 2026-10-07  6:30 UTC (permalink / raw)
  To: Zhu Yanjun, Jason Gunthorpe, Leon Romanovsky; +Cc: linux-rdma

Receive WQEs are held in queues which are writable by userspace.  The
responder bounds num_sge before copying a WQE to its private snapshot, but
does not validate cur_sge.  A non-empty SEND can therefore make copy_data()
select SGE metadata outside the populated receive SGE array.

Validate the immutable snapshot before installing it in the responder.
Require the copied num_sge to match the value used to size the copy and
require cur_sge to name a populated SGE whenever residual data remains.
Apply the same checks to per-QP and shared receive queues.

This was found by source review with AI assistance.  An unprivileged
RXE queue owner reproduced a kernel fault twice with num_sge set to 1,
resid set to 8, and cur_sge set to UINT_MAX.  The fixed kernel rejected
that WQE, while an ordinary eight-byte receive completed successfully.

Fixes: 8700e3e7c485 ("Soft RoCE driver")
Cc: stable@vger.kernel.org
Assisted-by: LLM
Signed-off-by: Sung Byeongchan <tjdqudcks0424@naver.com>
---
 drivers/infiniband/sw/rxe/rxe_resp.c | 17 +++++++++++++++--
 1 file changed, 15 insertions(+), 2 deletions(-)

diff --git a/drivers/infiniband/sw/rxe/rxe_resp.c b/drivers/infiniband/sw/rxe/rxe_resp.c
index 02b16e2b49b8f..f059434eead13 100644
--- a/drivers/infiniband/sw/rxe/rxe_resp.c
+++ b/drivers/infiniband/sw/rxe/rxe_resp.c
@@ -288,8 +288,15 @@ static enum resp_states get_srq_wqe(struct rxe_qp *qp)
 	}
 	size = sizeof(*wqe) + num_sge * sizeof(struct rxe_sge);
 	memcpy(&qp->resp.srq_wqe, wqe, size);
+	wqe = &qp->resp.srq_wqe.wqe;
+	if (unlikely(wqe->dma.num_sge != num_sge ||
+		     (wqe->dma.resid && wqe->dma.cur_sge >= num_sge))) {
+		spin_unlock_irqrestore(&srq->rq.consumer_lock, flags);
+		rxe_dbg_qp(qp, "invalid num_sge/cur_sge in SRQ entry\n");
+		return RESPST_ERR_MALFORMED_WQE;
+	}
 
-	qp->resp.wqe = &qp->resp.srq_wqe.wqe;
+	qp->resp.wqe = wqe;
 	queue_advance_consumer(q, QUEUE_TYPE_FROM_CLIENT);
 	count = queue_count(q, QUEUE_TYPE_FROM_CLIENT);
 
@@ -328,8 +335,14 @@ static enum resp_states rxe_get_recv_wqe(struct rxe_qp *qp)
 	}
 	size = sizeof(*wqe) + num_sge * sizeof(struct rxe_sge);
 	memcpy(&qp->resp.srq_wqe, wqe, size);
+	wqe = &qp->resp.srq_wqe.wqe;
+	if (unlikely(wqe->dma.num_sge != num_sge ||
+		     (wqe->dma.resid && wqe->dma.cur_sge >= num_sge))) {
+		rxe_dbg_qp(qp, "invalid num_sge/cur_sge in recv WQE\n");
+		return RESPST_ERR_MALFORMED_WQE;
+	}
 
-	qp->resp.wqe = &qp->resp.srq_wqe.wqe;
+	qp->resp.wqe = wqe;
 	return RESPST_CHK_LENGTH;
 }
 
-- 
2.43.0


^ permalink raw reply related	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2026-10-07  6:46 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-10-07  6:30 [PATCH] RDMA/rxe: validate receive WQE cursor after snapshot Sung Byeongchan
2026-10-07  6:46 ` sashiko-bot

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox