diff options
| author | Yousef Alhouseen <alhouseenyousef@gmail.com> | 2026-06-24 19:51:39 +0200 |
|---|---|---|
| committer | Greg Kroah-Hartman <gregkh@linuxfoundation.org> | 2026-07-17 15:50:03 +0200 |
| commit | 18189e5d84aa0b3bc89189cba13b9105634cb6fb (patch) | |
| tree | e3ac5c3550108a7b3f925713e93ada97c649cf27 /drivers/misc | |
| parent | fd62c1f591372f7dc4c5bc041569c2f0a4a86be1 (diff) | |
| download | linux-18189e5d84aa0b3bc89189cba13b9105634cb6fb.tar.gz linux-18189e5d84aa0b3bc89189cba13b9105634cb6fb.zip | |
misc: ibmvmc: reject oversized inbound messages
ibmvmc_recv_msg() trusts the message length from the CRQ.
It passes that length directly to h_copy_rdma().
The destination buffer is only max_mtu bytes.
A larger length can overrun it before userspace reads the message.
Validate the CRQ length before issuing the RDMA copy.
Signed-off-by: Yousef Alhouseen <alhouseenyousef@gmail.com>
Link: https://patch.msgid.link/20260624175139.7981-1-alhouseenyousef@gmail.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Diffstat (limited to 'drivers/misc')
| -rw-r--r-- | drivers/misc/ibmvmc.c | 7 |
1 files changed, 7 insertions, 0 deletions
diff --git a/drivers/misc/ibmvmc.c b/drivers/misc/ibmvmc.c index 1f2968d9d01b..28bf4c352317 100644 --- a/drivers/misc/ibmvmc.c +++ b/drivers/misc/ibmvmc.c @@ -1659,6 +1659,13 @@ static int ibmvmc_recv_msg(struct crq_server_adapter *adapter, return -1; } + if (msg_len > buffer->size) { + dev_err(adapter->dev, "Recv_msg: msg_len 0x%lx exceeds buffer size 0x%x\n", + msg_len, buffer->size); + spin_unlock_irqrestore(&hmc->lock, flags); + return -1; + } + /* RDMA the data into the partition. */ rc = h_copy_rdma(msg_len, adapter->riobn, |
