Netdev List
 help / color / mirror / Atom feed
* [PATCH net] s390/qeth: validate user buffer length in SNMP and ARP query ioctls
@ 2026-07-30 14:22 Hidayath Khan
  2026-07-30 16:15 ` Joe Damato
  0 siblings, 1 reply; 2+ messages in thread
From: Hidayath Khan @ 2026-07-30 14:22 UTC (permalink / raw)
  To: davem, edumazet, kuba, pabeni, andrew+netdev, wintera, aswin
  Cc: hca, gor, agordeev, borntraeger, svens, horms, netdev, linux-s390,
	linux-kernel, hidayath, stable

qeth_snmp_command() and qeth_l3_arp_query() allocate a buffer sized by
a user-supplied length (udata_len) without checking a lower bound, then
set udata_offset to a fixed non-zero value and pass both to a reply
callback. The callback bounds-checks the copy with

        if ((udata_len - udata_offset) < len)

Both fields are u32, so a udata_len smaller than udata_offset makes the
subtraction wrap and the check pass, and the following memcpy() writes
past the allocation. A udata_len of 0 also yields ZERO_SIZE_PTR from
kzalloc(), which the existing NULL check does not catch.

Reject buffers smaller than udata_offset before allocating, so the
callback subtraction can no longer underflow.

Fixes: 4a71df50047f ("qeth: new qeth device driver")
Cc: stable@vger.kernel.org
Reviewed-by: Alexandra Winter <wintera@linux.ibm.com>
Signed-off-by: Hidayath Khan <hidayath@linux.ibm.com>
---
 drivers/s390/net/qeth_core_main.c | 3 +++
 drivers/s390/net/qeth_l3_main.c   | 5 +++++
 2 files changed, 8 insertions(+)

diff --git a/drivers/s390/net/qeth_core_main.c b/drivers/s390/net/qeth_core_main.c
index f18eed9df3c7..c3257b213360 100644
--- a/drivers/s390/net/qeth_core_main.c
+++ b/drivers/s390/net/qeth_core_main.c
@@ -4710,6 +4710,9 @@ static int qeth_snmp_command(struct qeth_card *card, char __user *udata)
 	if (req_len > QETH_BUFSIZE)
 		return -EINVAL;
 
+	if (qinfo.udata_len < sizeof(struct qeth_snmp_ureq_hdr))
+		return -EINVAL;
+
 	iob = qeth_get_adapter_cmd(card, IPA_SETADP_SET_SNMP_CONTROL, req_len);
 	if (!iob)
 		return -ENOMEM;
diff --git a/drivers/s390/net/qeth_l3_main.c b/drivers/s390/net/qeth_l3_main.c
index 1542bfc9f561..f1ac9950dcb4 100644
--- a/drivers/s390/net/qeth_l3_main.c
+++ b/drivers/s390/net/qeth_l3_main.c
@@ -1415,6 +1415,11 @@ static int qeth_l3_arp_query(struct qeth_card *card, char __user *udata)
 		rc = -EFAULT;
 		goto out;
 	}
+
+	if (qinfo.udata_len < QETH_QARP_ENTRIES_OFFSET) {
+		rc = -EINVAL;
+		goto out;
+	}
 	qinfo.udata = kzalloc(qinfo.udata_len, GFP_KERNEL);
 	if (!qinfo.udata) {
 		rc = -ENOMEM;

base-commit: 58c1c294d685baf94801839334df20501711eb8e
-- 
2.52.0


^ permalink raw reply related	[flat|nested] 2+ messages in thread

* Re: [PATCH net] s390/qeth: validate user buffer length in SNMP and ARP query ioctls
  2026-07-30 14:22 [PATCH net] s390/qeth: validate user buffer length in SNMP and ARP query ioctls Hidayath Khan
@ 2026-07-30 16:15 ` Joe Damato
  0 siblings, 0 replies; 2+ messages in thread
From: Joe Damato @ 2026-07-30 16:15 UTC (permalink / raw)
  To: Hidayath Khan
  Cc: davem, edumazet, kuba, pabeni, andrew+netdev, wintera, aswin, hca,
	gor, agordeev, borntraeger, svens, horms, netdev, linux-s390,
	linux-kernel, stable

On Thu, Jul 30, 2026 at 04:22:16PM +0200, Hidayath Khan wrote:
> qeth_snmp_command() and qeth_l3_arp_query() allocate a buffer sized by
> a user-supplied length (udata_len) without checking a lower bound, then
> set udata_offset to a fixed non-zero value and pass both to a reply
> callback. The callback bounds-checks the copy with
> 
>         if ((udata_len - udata_offset) < len)
> 
> Both fields are u32, so a udata_len smaller than udata_offset makes the
> subtraction wrap and the check pass, and the following memcpy() writes
> past the allocation. A udata_len of 0 also yields ZERO_SIZE_PTR from
> kzalloc(), which the existing NULL check does not catch.
> 
> Reject buffers smaller than udata_offset before allocating, so the
> callback subtraction can no longer underflow.
> 
> Fixes: 4a71df50047f ("qeth: new qeth device driver")
> Cc: stable@vger.kernel.org
> Reviewed-by: Alexandra Winter <wintera@linux.ibm.com>
> Signed-off-by: Hidayath Khan <hidayath@linux.ibm.com>
> ---
>  drivers/s390/net/qeth_core_main.c | 3 +++
>  drivers/s390/net/qeth_l3_main.c   | 5 +++++
>  2 files changed, 8 insertions(+)

Reviewed-by: Joe Damato <joe@dama.to>

^ permalink raw reply	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2026-07-30 16:15 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-07-30 14:22 [PATCH net] s390/qeth: validate user buffer length in SNMP and ARP query ioctls Hidayath Khan
2026-07-30 16:15 ` Joe Damato

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox