summaryrefslogtreecommitdiff
path: root/drivers/misc
diff options
context:
space:
mode:
authorYousef Alhouseen <alhouseenyousef@gmail.com>2026-06-24 19:51:39 +0200
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>2026-07-17 15:50:03 +0200
commit18189e5d84aa0b3bc89189cba13b9105634cb6fb (patch)
treee3ac5c3550108a7b3f925713e93ada97c649cf27 /drivers/misc
parentfd62c1f591372f7dc4c5bc041569c2f0a4a86be1 (diff)
downloadlinux-18189e5d84aa0b3bc89189cba13b9105634cb6fb.tar.gz
linux-18189e5d84aa0b3bc89189cba13b9105634cb6fb.zip
misc: ibmvmc: reject oversized inbound messages
ibmvmc_recv_msg() trusts the message length from the CRQ. It passes that length directly to h_copy_rdma(). The destination buffer is only max_mtu bytes. A larger length can overrun it before userspace reads the message. Validate the CRQ length before issuing the RDMA copy. Signed-off-by: Yousef Alhouseen <alhouseenyousef@gmail.com> Link: https://patch.msgid.link/20260624175139.7981-1-alhouseenyousef@gmail.com Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Diffstat (limited to 'drivers/misc')
-rw-r--r--drivers/misc/ibmvmc.c7
1 files changed, 7 insertions, 0 deletions
diff --git a/drivers/misc/ibmvmc.c b/drivers/misc/ibmvmc.c
index 1f2968d9d01b..28bf4c352317 100644
--- a/drivers/misc/ibmvmc.c
+++ b/drivers/misc/ibmvmc.c
@@ -1659,6 +1659,13 @@ static int ibmvmc_recv_msg(struct crq_server_adapter *adapter,
return -1;
}
+ if (msg_len > buffer->size) {
+ dev_err(adapter->dev, "Recv_msg: msg_len 0x%lx exceeds buffer size 0x%x\n",
+ msg_len, buffer->size);
+ spin_unlock_irqrestore(&hmc->lock, flags);
+ return -1;
+ }
+
/* RDMA the data into the partition. */
rc = h_copy_rdma(msg_len,
adapter->riobn,