|
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index] [PATCH] xen/argo: make the ring copy length check overflow-safe
From: Weiqi Wang <weiqi.wang-2@xxxxxxxxxxxxxxxxxxxxxxxxx>
memcpy_to_guest_ring() bounds the copy against the ring size with
if ( len + offset > XEN_ARGO_MAX_RING_SIZE )
where len and offset are unsigned int. offset is masked below PAGE_SIZE
just above, but a len close to UINT_MAX makes len + offset wrap below
XEN_ARGO_MAX_RING_SIZE and pass the check. The head_len computation in
the loop wraps the same way, so the copy length is no longer bounded.
All current callers bound len via iov_count(), so this is not reachable
in practice. Do not rely on that: bound len first, then compare offset
against the room that is left.
No functional change for in-range inputs.
Signed-off-by: WeiqiW <lukewang19@xxxxxxxxxxx>
---
xen/common/argo.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/xen/common/argo.c b/xen/common/argo.c
index 0b9a54db36..b308ee8311 100644
--- a/xen/common/argo.c
+++ b/xen/common/argo.c
@@ -568,7 +568,8 @@ memcpy_to_guest_ring(const struct domain *d, struct
argo_ring_info *ring_info,
offset &= ~PAGE_MASK;
- if ( len + offset > XEN_ARGO_MAX_RING_SIZE )
+ if ( len > XEN_ARGO_MAX_RING_SIZE ||
+ offset > XEN_ARGO_MAX_RING_SIZE - len )
return -EFAULT;
while ( len )
--
2.50.1 (Apple Git-155)
|
![]() |
Lists.xenproject.org is hosted with RackSpace, monitoring our |