Received: by 2002:a25:c593:0:0:0:0:0 with SMTP id v141csp789863ybe; Fri, 13 Sep 2019 06:25:51 -0700 (PDT) X-Google-Smtp-Source: APXvYqzo+iTytx91zDR6OuCstikAJHkREwz2xOvxz2fgiAGKaAzl6oxovHgnO6/6eQEqgJDBwJQf X-Received: by 2002:a17:906:4a81:: with SMTP id x1mr40312481eju.23.1568381151574; Fri, 13 Sep 2019 06:25:51 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1568381151; cv=none; d=google.com; s=arc-20160816; b=nkpHk3SPwyPdu7+99L14FKaYZblAnFtA9Y+TZCJZRZVSrCqcFZ0JHGnbB2ut+1hZq8 EgKMkGmH9ShxGJdWN1p0nI4+ZzBLzEw+7d+uEQ+jZ+iERUigQIR7LEuMQqGpRGZp71NW OEe/CTKqqlr8IvZ005v65UjlkdwJH4hy8BVhhprbuo+Kzn6j3FvBwND4zoxtJmWRwD5E mnthiDDKlsndZF6d0DruovCpKjEVQYvYeMYCn3GRXt5BcB8iK4BE0ugcedPcawwDhG9c JxHmhRLPuEHJ+KOssNKc686n0/ToWL+NpuqrHRCL8QZsCKqMOP6JBCCdV98w/nlYmkIw zJig== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:sender:content-transfer-encoding:mime-version :user-agent:references:in-reply-to:message-id:date:subject:cc:to :from:dkim-signature; bh=LegV00HDOZikqtYsGKDSugkJ5zGMjcdzMPEepksQLHQ=; b=LpKJpa1QGQzlTxmZ/mHHr2DOZBoQGXGb9kxYRkNN7cqQ7OK72waU6fY90goGBOLkds fiKsk9VvYimII5hBtOfUE6XUrXvfQy2WLclG3N60w7AJvZhCfYpjE2UXUjFzkNnPSXYs ijQkzSU6W5iO1oqkP+onkSUyf69MW3i+LdYucCKTgBOD8XzkVbHh4iwKmcqP4SGlN4VF o4ROOBkIPgZn2kVxTRmGRnKiFDiFeDzHxxjI+/azF3QZE+L8XPvrGKsC4n0YZ2GChhnD d38VBI1LMCOJQOQzek6ZKzAbWLz0uPihRUgzt5ano1BRx4dxdFoxEddUI3rRhkHnduOf BDHA== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@kernel.org header.s=default header.b=vYkd9s5d; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org Return-Path: Received: from vger.kernel.org (vger.kernel.org. [209.132.180.67]) by mx.google.com with ESMTP id g5si14306060ejw.309.2019.09.13.06.25.27; Fri, 13 Sep 2019 06:25:51 -0700 (PDT) Received-SPF: pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) client-ip=209.132.180.67; Authentication-Results: mx.google.com; dkim=pass header.i=@kernel.org header.s=default header.b=vYkd9s5d; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S2390931AbfIMNV4 (ORCPT + 99 others); Fri, 13 Sep 2019 09:21:56 -0400 Received: from mail.kernel.org ([198.145.29.99]:51844 "EHLO mail.kernel.org" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S2390926AbfIMNVy (ORCPT ); Fri, 13 Sep 2019 09:21:54 -0400 Received: from localhost (unknown [104.132.45.99]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by mail.kernel.org (Postfix) with ESMTPSA id 5E4C4206BB; Fri, 13 Sep 2019 13:21:53 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kernel.org; s=default; t=1568380913; bh=2pVP602cg00sCTVTT665bmE2gN0S7xfI1q9R3UMw/Go=; h=From:To:Cc:Subject:Date:In-Reply-To:References:From; b=vYkd9s5dAYrycD3TNDbllrMEMBUF7rn97WTEXVXKXTyhJrAkOvxzqZokYPcisBFY0 mWlSdI4nwE9B+A/gLEqL1sAF3xyDPV7Vekz03R3WEZMEAvq+pxcgHTY9Vo8RVcfYAD Ign6uJZOjwW66KkzOgb/EH2G/KToRNoQQF3fa4ak= From: Greg Kroah-Hartman To: linux-kernel@vger.kernel.org Cc: Greg Kroah-Hartman , stable@vger.kernel.org, "Michael S. Tsirkin" , Jason Wang Subject: [PATCH 5.2 36/37] vhost: block speculation of translated descriptors Date: Fri, 13 Sep 2019 14:07:41 +0100 Message-Id: <20190913130522.155505270@linuxfoundation.org> X-Mailer: git-send-email 2.23.0 In-Reply-To: <20190913130510.727515099@linuxfoundation.org> References: <20190913130510.727515099@linuxfoundation.org> User-Agent: quilt/0.66 MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Sender: linux-kernel-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org From: Michael S. Tsirkin commit a89db445fbd7f1f8457b03759aa7343fa530ef6b upstream. iovec addresses coming from vhost are assumed to be pre-validated, but in fact can be speculated to a value out of range. Userspace address are later validated with array_index_nospec so we can be sure kernel info does not leak through these addresses, but vhost must also not leak userspace info outside the allowed memory table to guests. Following the defence in depth principle, make sure the address is not validated out of node range. Signed-off-by: Michael S. Tsirkin Cc: stable@vger.kernel.org Acked-by: Jason Wang Tested-by: Jason Wang Signed-off-by: Greg Kroah-Hartman --- drivers/vhost/vhost.c | 6 ++++-- 1 file changed, 4 insertions(+), 2 deletions(-) --- a/drivers/vhost/vhost.c +++ b/drivers/vhost/vhost.c @@ -1965,8 +1965,10 @@ static int translate_desc(struct vhost_v _iov = iov + ret; size = node->size - addr + node->start; _iov->iov_len = min((u64)len - s, size); - _iov->iov_base = (void __user *)(unsigned long) - (node->userspace_addr + addr - node->start); + _iov->iov_base = (void __user *) + ((unsigned long)node->userspace_addr + + array_index_nospec((unsigned long)(addr - node->start), + node->size)); s += size; addr += size; ++ret;