* [PATCH net] s390/qeth: validate user buffer length in SNMP and ARP query ioctls
@ 2026-07-30 14:22 Hidayath Khan
2026-07-30 16:15 ` Joe Damato
0 siblings, 1 reply; 2+ messages in thread
From: Hidayath Khan @ 2026-07-30 14:22 UTC (permalink / raw)
To: davem, edumazet, kuba, pabeni, andrew+netdev, wintera, aswin
Cc: hca, gor, agordeev, borntraeger, svens, horms, netdev, linux-s390,
linux-kernel, hidayath, stable
qeth_snmp_command() and qeth_l3_arp_query() allocate a buffer sized by
a user-supplied length (udata_len) without checking a lower bound, then
set udata_offset to a fixed non-zero value and pass both to a reply
callback. The callback bounds-checks the copy with
if ((udata_len - udata_offset) < len)
Both fields are u32, so a udata_len smaller than udata_offset makes the
subtraction wrap and the check pass, and the following memcpy() writes
past the allocation. A udata_len of 0 also yields ZERO_SIZE_PTR from
kzalloc(), which the existing NULL check does not catch.
Reject buffers smaller than udata_offset before allocating, so the
callback subtraction can no longer underflow.
Fixes: 4a71df50047f ("qeth: new qeth device driver")
Cc: stable@vger.kernel.org
Reviewed-by: Alexandra Winter <wintera@linux.ibm.com>
Signed-off-by: Hidayath Khan <hidayath@linux.ibm.com>
---
drivers/s390/net/qeth_core_main.c | 3 +++
drivers/s390/net/qeth_l3_main.c | 5 +++++
2 files changed, 8 insertions(+)
diff --git a/drivers/s390/net/qeth_core_main.c b/drivers/s390/net/qeth_core_main.c
index f18eed9df3c7..c3257b213360 100644
--- a/drivers/s390/net/qeth_core_main.c
+++ b/drivers/s390/net/qeth_core_main.c
@@ -4710,6 +4710,9 @@ static int qeth_snmp_command(struct qeth_card *card, char __user *udata)
if (req_len > QETH_BUFSIZE)
return -EINVAL;
+ if (qinfo.udata_len < sizeof(struct qeth_snmp_ureq_hdr))
+ return -EINVAL;
+
iob = qeth_get_adapter_cmd(card, IPA_SETADP_SET_SNMP_CONTROL, req_len);
if (!iob)
return -ENOMEM;
diff --git a/drivers/s390/net/qeth_l3_main.c b/drivers/s390/net/qeth_l3_main.c
index 1542bfc9f561..f1ac9950dcb4 100644
--- a/drivers/s390/net/qeth_l3_main.c
+++ b/drivers/s390/net/qeth_l3_main.c
@@ -1415,6 +1415,11 @@ static int qeth_l3_arp_query(struct qeth_card *card, char __user *udata)
rc = -EFAULT;
goto out;
}
+
+ if (qinfo.udata_len < QETH_QARP_ENTRIES_OFFSET) {
+ rc = -EINVAL;
+ goto out;
+ }
qinfo.udata = kzalloc(qinfo.udata_len, GFP_KERNEL);
if (!qinfo.udata) {
rc = -ENOMEM;
base-commit: 58c1c294d685baf94801839334df20501711eb8e
--
2.52.0
^ permalink raw reply related [flat|nested] 2+ messages in thread
* Re: [PATCH net] s390/qeth: validate user buffer length in SNMP and ARP query ioctls
2026-07-30 14:22 [PATCH net] s390/qeth: validate user buffer length in SNMP and ARP query ioctls Hidayath Khan
@ 2026-07-30 16:15 ` Joe Damato
0 siblings, 0 replies; 2+ messages in thread
From: Joe Damato @ 2026-07-30 16:15 UTC (permalink / raw)
To: Hidayath Khan
Cc: davem, edumazet, kuba, pabeni, andrew+netdev, wintera, aswin, hca,
gor, agordeev, borntraeger, svens, horms, netdev, linux-s390,
linux-kernel, stable
On Thu, Jul 30, 2026 at 04:22:16PM +0200, Hidayath Khan wrote:
> qeth_snmp_command() and qeth_l3_arp_query() allocate a buffer sized by
> a user-supplied length (udata_len) without checking a lower bound, then
> set udata_offset to a fixed non-zero value and pass both to a reply
> callback. The callback bounds-checks the copy with
>
> if ((udata_len - udata_offset) < len)
>
> Both fields are u32, so a udata_len smaller than udata_offset makes the
> subtraction wrap and the check pass, and the following memcpy() writes
> past the allocation. A udata_len of 0 also yields ZERO_SIZE_PTR from
> kzalloc(), which the existing NULL check does not catch.
>
> Reject buffers smaller than udata_offset before allocating, so the
> callback subtraction can no longer underflow.
>
> Fixes: 4a71df50047f ("qeth: new qeth device driver")
> Cc: stable@vger.kernel.org
> Reviewed-by: Alexandra Winter <wintera@linux.ibm.com>
> Signed-off-by: Hidayath Khan <hidayath@linux.ibm.com>
> ---
> drivers/s390/net/qeth_core_main.c | 3 +++
> drivers/s390/net/qeth_l3_main.c | 5 +++++
> 2 files changed, 8 insertions(+)
Reviewed-by: Joe Damato <joe@dama.to>
^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2026-07-30 16:15 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-07-30 14:22 [PATCH net] s390/qeth: validate user buffer length in SNMP and ARP query ioctls Hidayath Khan
2026-07-30 16:15 ` Joe Damato
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox