From: Fang Xieyan <fangxy@xiaopeng.com>
To: "Michael S . Tsirkin" <mst@redhat.com>,
"Jason Wang" <jasowangio@gmail.com>,
"Eugenio Pérez" <eperezma@redhat.com>
Cc: Rusty Russell <rusty@rustcorp.com.au>,
stable@vger.kernel.org, virtualization@lists.linux.dev,
kvm@vger.kernel.org, netdev@vger.kernel.org,
linux-kernel@vger.kernel.org
Subject: [PATCH v2] vringh: reject empty / undersized indirect descriptor tables
Date: Sun, 27 Sep 2026 00:07:55 +0800 [thread overview]
Message-ID: <20260926160755.21485-1-fangxy@xiaopeng.com> (raw)
In-Reply-To: <20260924030627.13287-1-fangxy@xiaopeng.com>
move_to_indirect() validates an indirect descriptor table only with
"len % sizeof(struct vring_desc)". A descriptor flagged
VRING_DESC_F_INDIRECT with len == 0 passes that test, so *desc_max is
set to 0 while *descs points at the empty table. __vringh_iov() then
copies one struct vring_desc from descs[0] -- 16 bytes past the end of
the table -- before the "indirect_count > desc_max" loop detection
aborts the walk. The over-read value is discarded when the walk aborts
and is never used to map anything, but the access itself is out of
bounds.
Reject any len smaller than one descriptor, alongside the existing
stride check, so an empty table is refused with -EINVAL and no
descriptor is ever fetched from it.
Fixes: f87d0fbb5798 ("vringh: host-side implementation of virtio rings.")
Cc: stable@vger.kernel.org
Assisted-by: Hawkeye:GLM-5.3-flash
Assisted-by: Qoder:Qwen3.8-Max
Signed-off-by: Fang Xieyan <fangxy@xiaopeng.com>
---
drivers/vhost/vringh.c | 5 +++--
1 file changed, 3 insertions(+), 2 deletions(-)
Changes in v2:
- Commit message rewritten per Michael's review: the over-read value
is copied into a local struct vring_desc and never reaches the
caller, so the security framing ("leak" etc.) is dropped and this
is presented as the plain out-of-bounds read fix it is.
- Code is unchanged; the diff is identical to v1.
Testing:
Userspace reproducer carrying the move_to_indirect()/__vringh_iov()
logic with an instrumented copy() (len == 0 indirect table, 2048-byte
mapped region followed by 64 guard bytes):
without the fix: reads 16 bytes past the table end, returns -ELOOP
with the fix: returns -EINVAL, no read past the table end
diff --git a/drivers/vhost/vringh.c b/drivers/vhost/vringh.c
index 9066f9f..0767748 100644
--- a/drivers/vhost/vringh.c
+++ b/drivers/vhost/vringh.c
@@ -197,8 +197,9 @@ static int move_to_indirect(const struct vringh *vrh,
}
len = vringh32_to_cpu(vrh, desc->len);
- if (unlikely(len % sizeof(struct vring_desc))) {
- vringh_bad("Strange indirect len %u", desc->len);
+ if (unlikely(len < sizeof(struct vring_desc) ||
+ len % sizeof(struct vring_desc))) {
+ vringh_bad("Invalid indirect len %u", desc->len);
return -EINVAL;
}
--
2.50.1
next prev parent reply other threads:[~2026-09-26 16:08 UTC|newest]
Thread overview: 5+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-24 3:06 [PATCH] vringh: reject empty / undersized indirect descriptor tables Fang Xieyan
2026-09-24 3:13 ` sashiko-bot
2026-09-24 15:56 ` Michael S. Tsirkin
2026-09-26 16:07 ` Fang Xieyan [this message]
2026-09-26 16:16 ` [PATCH v2] " sashiko-bot
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260926160755.21485-1-fangxy@xiaopeng.com \
--to=fangxy@xiaopeng.com \
--cc=eperezma@redhat.com \
--cc=jasowangio@gmail.com \
--cc=kvm@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=mst@redhat.com \
--cc=netdev@vger.kernel.org \
--cc=rusty@rustcorp.com.au \
--cc=stable@vger.kernel.org \
--cc=virtualization@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox