mirror of
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git
synced 2026-08-30 15:43:08 -04:00
virtio_console: take a kref in find_port_by_vq() to fix port UAF
find_port_by_vq() returns a raw struct port pointer without taking a reference on it, unlike find_port_by_devt_in_portdev() which does. find_port_by_vq()'s only two callers, in_intr() and out_intr(), run as virtqueue interrupt callbacks, entirely independent of and possibly concurrently with unplug_port(), which itself runs from a workqueue when the host sends a VIRTIO_CONSOLE_PORT_REMOVE control message. unplug_port() removes the port from portdev->ports under ports_lock, then later drops its last reference with kref_put(), freeing it via remove_port(). find_port_by_vq() also walks portdev->ports under ports_lock, so if it finds the port still on the list, the list removal, and therefore the eventual kref_put(), has not happened yet, and taking a reference at that point is always safe. Without doing so, in_intr()/out_intr() can be left holding a pointer to a port that unplug_port() frees on another core before they are done using it. Both triggers are host-controlled as the host decides when to send the PORT_REMOVE control message and when to kick the port's data vq. So a malicious backend could race the two on purpose, without any guest side cooperation. The freed object is a generic kmalloc allocation containing a wait_queue_head_t, which in_intr()/out_intr() pass to wake_up_interruptible() after touching the stale pointer. wake_up_interruptible() invokes a function pointer read out of the wait queue's entries. If the freed slab slot is reclaimed with attacker influenced content before that call, then this is an arbitrary function call primitive rather than just undefined behaviour. Take a reference in find_port_by_vq() while still holding ports_lock, matching find_port_by_devt_in_portdev(), and release it in in_intr() and out_intr() once they are done with the port. Signed-off-by: Hari Mishal <harimishal1@gmail.com> Link: https://patch.msgid.link/20260717150622.23636-1-harimishal1@gmail.com Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
This commit is contained in:
committed by
Greg Kroah-Hartman
parent
48c7907d92
commit
18dd0b4e48
@@ -304,6 +304,12 @@ static struct port *find_port_by_id(struct ports_device *portdev, u32 id)
|
||||
return port;
|
||||
}
|
||||
|
||||
/*
|
||||
* Finds a port by the virtqueue and returns a pointer to struct port
|
||||
* with the reference count incremented.
|
||||
*
|
||||
* Callers MUST decrement it when finished.
|
||||
*/
|
||||
static struct port *find_port_by_vq(struct ports_device *portdev,
|
||||
struct virtqueue *vq)
|
||||
{
|
||||
@@ -312,8 +318,10 @@ static struct port *find_port_by_vq(struct ports_device *portdev,
|
||||
|
||||
spin_lock_irqsave(&portdev->ports_lock, flags);
|
||||
list_for_each_entry(port, &portdev->ports, list)
|
||||
if (port->in_vq == vq || port->out_vq == vq)
|
||||
if (port->in_vq == vq || port->out_vq == vq) {
|
||||
kref_get(&port->kref);
|
||||
goto out;
|
||||
}
|
||||
port = NULL;
|
||||
out:
|
||||
spin_unlock_irqrestore(&portdev->ports_lock, flags);
|
||||
@@ -1708,6 +1716,7 @@ static void out_intr(struct virtqueue *vq)
|
||||
}
|
||||
|
||||
wake_up_interruptible(&port->waitqueue);
|
||||
kref_put(&port->kref, remove_port);
|
||||
}
|
||||
|
||||
static void in_intr(struct virtqueue *vq)
|
||||
@@ -1753,6 +1762,8 @@ static void in_intr(struct virtqueue *vq)
|
||||
|
||||
if (is_console_port(port) && hvc_poll(port->cons.hvc))
|
||||
hvc_kick();
|
||||
|
||||
kref_put(&port->kref, remove_port);
|
||||
}
|
||||
|
||||
static void control_intr(struct virtqueue *vq)
|
||||
|
||||
Reference in New Issue
Block a user