Received: by 2002:a25:c593:0:0:0:0:0 with SMTP id v141csp1105727ybe; Fri, 13 Sep 2019 11:06:39 -0700 (PDT) X-Google-Smtp-Source: APXvYqxYdypeXQROyPRzmbrYR22Tuam4sp0AKaWy71WxAZCFw3sMQHBPBaKztne0cDecv5YvsXiD X-Received: by 2002:a50:fc17:: with SMTP id i23mr15612595edr.287.1568397999205; Fri, 13 Sep 2019 11:06:39 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1568397999; cv=none; d=google.com; s=arc-20160816; b=TjmvT/xabwgKbYQwi363c0N58W/IjFZ8IrTngKJpeSArHaTfwH++bt/w9o1L/ijr7C Mj3qlTl7hcl+TUjlRZixt/6K3Mp4x6WmV1YczM4fpib1fOFhMU/hIjw1tUhLYgj8+Map STK3re7oAeVoTDAyRU1YBJ6MAe9fgv2MYZg8eIUIM9weA+Bb6l7fh0SZgBzz8UcVzpGv Xbh33MWBtiCMctgnaX4lWY7RRYW1uNrFBkqswEQhMC6lP/yBgo+k7zDsT82lmrHJKpan NBpDSBPJ9bgNVbgN4sy+PDERxeAVkXQrlQZ80oJdFwerAqBOb/xTkkeQFjdVRf/EPDlK kiqQ== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:sender:content-transfer-encoding:mime-version :user-agent:references:in-reply-to:message-id:date:subject:cc:to :from:dkim-signature; bh=/4cFmCoC5fnXB3zl6CKMDLPdB24rjZ8VR1PySu9WdvM=; b=ZTMJSt1rejdugWMWMzYerzBEVGOV43JHAggKwxcotuRNT+WjK7vA6dyv1U9a0xcyGG zESyLkkKDKeWlWOefxuX2O0+FmkABr2Mzct1H2MmS7tdrz2+NJJtJUu26CmcCAY5Ahvr dbKFoL6t8yV6tr2GS/je810XVhFjXm+Ej9mKeUjOMkdfgmeXDxHuXFjPAIthL/245Re/ aXnAEdXsA3Ma6Ju9AkFrb+5GXnsxmefSoDQjXKKcr+tBb3rW/aKEF4w5uKTFTk6o1AqC pWcXRIMjSVKp2ApF5ktpBQjin9tu+OtcY7aBeIvshF/t9524y3EQ01wRy8Ay7ZQNf3Me TPxA== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@kernel.org header.s=default header.b="tUT/35CX"; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org Return-Path: Received: from vger.kernel.org (vger.kernel.org. [209.132.180.67]) by mx.google.com with ESMTP id h24si16963313ejl.55.2019.09.13.11.06.14; Fri, 13 Sep 2019 11:06:39 -0700 (PDT) Received-SPF: pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) client-ip=209.132.180.67; Authentication-Results: mx.google.com; dkim=pass header.i=@kernel.org header.s=default header.b="tUT/35CX"; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S2388784AbfIMNKc (ORCPT + 99 others); Fri, 13 Sep 2019 09:10:32 -0400 Received: from mail.kernel.org ([198.145.29.99]:35356 "EHLO mail.kernel.org" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S2388773AbfIMNKa (ORCPT ); Fri, 13 Sep 2019 09:10:30 -0400 Received: from localhost (unknown [104.132.45.99]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by mail.kernel.org (Postfix) with ESMTPSA id 7DCEA208C0; Fri, 13 Sep 2019 13:10:29 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kernel.org; s=default; t=1568380230; bh=t7lhY3uoey2pv2XPZ+VGGKmYEYqcQkcrF/ccCBqj/dw=; h=From:To:Cc:Subject:Date:In-Reply-To:References:From; b=tUT/35CXt1mFqIhhJkacjyfoAohcMeALImB1MuVsl2z09AroeX+VQ3M2UmB0X/ZV0 5qwsR8PGXS/Y5TY1DE4lDfdgRqJCColfNXu6BiOf57k7MTO7Y2ZOUmYAKrPNBibSRc CzaSai0uo9EjYNS+Y2XEz5Hl40+kWA8WBmfE9PpY= From: Greg Kroah-Hartman To: linux-kernel@vger.kernel.org Cc: Greg Kroah-Hartman , stable@vger.kernel.org, "Michael S. Tsirkin" , Jason Wang Subject: [PATCH 4.14 20/21] vhost: block speculation of translated descriptors Date: Fri, 13 Sep 2019 14:07:13 +0100 Message-Id: <20190913130509.381176459@linuxfoundation.org> X-Mailer: git-send-email 2.23.0 In-Reply-To: <20190913130501.285837292@linuxfoundation.org> References: <20190913130501.285837292@linuxfoundation.org> User-Agent: quilt/0.66 MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Sender: linux-kernel-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org From: Michael S. Tsirkin commit a89db445fbd7f1f8457b03759aa7343fa530ef6b upstream. iovec addresses coming from vhost are assumed to be pre-validated, but in fact can be speculated to a value out of range. Userspace address are later validated with array_index_nospec so we can be sure kernel info does not leak through these addresses, but vhost must also not leak userspace info outside the allowed memory table to guests. Following the defence in depth principle, make sure the address is not validated out of node range. Signed-off-by: Michael S. Tsirkin Cc: stable@vger.kernel.org Acked-by: Jason Wang Tested-by: Jason Wang Signed-off-by: Greg Kroah-Hartman --- drivers/vhost/vhost.c | 6 ++++-- 1 file changed, 4 insertions(+), 2 deletions(-) --- a/drivers/vhost/vhost.c +++ b/drivers/vhost/vhost.c @@ -1954,8 +1954,10 @@ static int translate_desc(struct vhost_v _iov = iov + ret; size = node->size - addr + node->start; _iov->iov_len = min((u64)len - s, size); - _iov->iov_base = (void __user *)(unsigned long) - (node->userspace_addr + addr - node->start); + _iov->iov_base = (void __user *) + ((unsigned long)node->userspace_addr + + array_index_nospec((unsigned long)(addr - node->start), + node->size)); s += size; addr += size; ++ret;