Linux s390 Architecture development
 help / color / mirror / Atom feed
* [PATCH v4 0/1] Fix buffer over-read in cca_cipher2protkey
@ 2026-07-29 11:40 Harald Freudenberger
  2026-07-29 11:40 ` [PATCH v4 1/1] s390/zcrypt: " Harald Freudenberger
  0 siblings, 1 reply; 4+ messages in thread
From: Harald Freudenberger @ 2026-07-29 11:40 UTC (permalink / raw)
  To: Heiko Carstens, Vasily Gorbik, Alexander Gordeev
  Cc: freude, linux-s390, ifranzki

Add validation of both the actual key buffer size and token length
fields in all the cca_check_sec*token() functions. Additionally check
in cca_gencipherkey() for possible underflow with returned key size.

The CCA token structures contain user-controlled len fields that
were used in operations without proper validation against both the
actual buffer size and minimum token structure size. An attacker
could set this field larger than the actual buffer size, leading to
reading beyond buffer boundaries. This may result in a kernel crash or
exposure of memory via sending this as part of a request down to the
crypto card. Also an attacker could have used a very small len value
and thus enforce a buffer under-run which may produce similar effects
as a over-read.

So now a key must
- key buf length must be at least sizeof the token struct
- the key len field inside the token must fit into the range of
  sizeof key token struct ... key buf length

Changelog:
v1 - initial version
v2 - extend the length check to all cca_check_sec*token() functions,
     also check for min given buffer length and token length field.
v3 - there was still a possibility to under-run the length checks in
     function  cca_gencipherkey(). Fixed as suggested by Ingo.
v4 - Reviewd-by from Ingo added.

Harald Freudenberger (1):
  s390/zcrypt: Fix buffer over-read in cca_cipher2protkey

 drivers/s390/crypto/pkey_cca.c       | 15 +++----
 drivers/s390/crypto/zcrypt_ccamisc.c | 64 +++++++++++++++++++++++-----
 drivers/s390/crypto/zcrypt_ccamisc.h |  6 +--
 3 files changed, 62 insertions(+), 23 deletions(-)

-- 
2.43.0


^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2026-07-29 13:49 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-07-29 11:40 [PATCH v4 0/1] Fix buffer over-read in cca_cipher2protkey Harald Freudenberger
2026-07-29 11:40 ` [PATCH v4 1/1] s390/zcrypt: " Harald Freudenberger
2026-07-29 12:06   ` sashiko-bot
2026-07-29 13:49     ` Harald Freudenberger

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox