[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[PATCH] xen/argo: make the ring copy length check overflow-safe



From: Weiqi Wang <weiqi.wang-2@xxxxxxxxxxxxxxxxxxxxxxxxx>

memcpy_to_guest_ring() bounds the copy against the ring size with

    if ( len + offset > XEN_ARGO_MAX_RING_SIZE )

where len and offset are unsigned int.  offset is masked below PAGE_SIZE
just above, but a len close to UINT_MAX makes len + offset wrap below
XEN_ARGO_MAX_RING_SIZE and pass the check.  The head_len computation in
the loop wraps the same way, so the copy length is no longer bounded.

All current callers bound len via iov_count(), so this is not reachable
in practice.  Do not rely on that: bound len first, then compare offset
against the room that is left.

No functional change for in-range inputs.

Signed-off-by: WeiqiW <lukewang19@xxxxxxxxxxx>
---
 xen/common/argo.c | 3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

diff --git a/xen/common/argo.c b/xen/common/argo.c
index 0b9a54db36..b308ee8311 100644
--- a/xen/common/argo.c
+++ b/xen/common/argo.c
@@ -568,7 +568,8 @@ memcpy_to_guest_ring(const struct domain *d, struct 
argo_ring_info *ring_info,
 
     offset &= ~PAGE_MASK;
 
-    if ( len + offset > XEN_ARGO_MAX_RING_SIZE )
+    if ( len > XEN_ARGO_MAX_RING_SIZE ||
+         offset > XEN_ARGO_MAX_RING_SIZE - len )
         return -EFAULT;
 
     while ( len )
-- 
2.50.1 (Apple Git-155)




 


Rackspace

Lists.xenproject.org is hosted with RackSpace, monitoring our
servers 24x7x365 and backed by RackSpace's Fanatical Support®.