mirror of
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git
synced 2026-08-28 15:47:16 -04:00
random_recv_done() stores the device-reported used.len directly into vi->data_avail. copy_data() then indexes vi->data[] using vi->data_idx (advanced by previous copy_data() calls) and issues a memcpy() without re-validating either value against the posted buffer size sizeof(vi->data) (SMP_CACHE_BYTES bytes, typically 32 or 64). A malicious or buggy virtio-rng backend can set used.len beyond sizeof(vi->data), steering the memcpy() past the end of the inline array into adjacent kmalloc-1k slab bytes. hwrng_fillfn() mixes those bytes into the guest RNG, and guest root can also observe them directly via /dev/hwrng. Concrete impact is inside the guest: - Memory-safety / hardening: any virtio-rng backend that over-reports used.len causes the driver to read past vi->data into unrelated slab contents. hwrng_fillfn() is a kernel thread that runs as soon as the device is probed; no guest userspace interaction is required to first-trigger the OOB. - Cross-boundary leak (confidential-compute threat model): a malicious hypervisor cooperating with a malicious or compromised guest root userspace can use /dev/hwrng as a leak channel for guest-kernel heap data. The host sets a large used.len, guest root reads /dev/hwrng, and the returned bytes contain guest kernel slab contents that were adjacent to vi->data. In practice, confidential-compute guests (SEV-SNP, TDX) usually disable virtio-rng entirely, so this path is narrow, but the fix is still worth carrying because the underlying memory-safety bug contaminates the guest RNG on any host. KASAN confirms the OOB on a 7.1-rc4 guest whose virtio-rng backend has been patched to report used.len = 0x10000: BUG: KASAN: slab-out-of-bounds in virtio_read+0x394/0x5d0 Read of size 64 at addr ffff88800ae0ba20 by task hwrng/52 Call Trace: __asan_memcpy+0x23/0x60 virtio_read+0x394/0x5d0 hwrng_fillfn+0xb2/0x470 kthread+0x2cc/0x3a0 Allocated by task 1: probe_common+0xa5/0x660 virtio_dev_probe+0x549/0xbc0 The buggy address belongs to the object at ffff88800ae0b800 which belongs to the cache kmalloc-1k of size 1024 The buggy address is located 0 bytes to the right of allocated 544-byte region [ffff88800ae0b800, ffff88800ae0ba20) Same class of bug as commitc04db81cd0("net/9p: Fix buffer overflow in USB transport layer"), which hardened usb9pfs_rx_complete() against unchecked device-reported length in the USB 9p transport. With the clamp at point of use and array_index_nospec() in place, the same harness boots cleanly: copy_data() returns zero for the bogus report, the device-supplied bytes after data_idx are discarded, and the driver issues a fresh request. Fixes:f7f510ec19("virtio: An entropy device, as suggested by hpa.") Cc: stable@vger.kernel.org Suggested-by: Michael S. Tsirkin <mst@redhat.com> Signed-off-by: Michael Bommarito <michael.bommarito@gmail.com> Assisted-by: Claude:claude-opus-4-8 Signed-off-by: Michael S. Tsirkin <mst@redhat.com> Message-ID: <20260531142251.2792061-1-michael.bommarito@gmail.com>
282 lines
6.1 KiB
C
282 lines
6.1 KiB
C
// SPDX-License-Identifier: GPL-2.0-or-later
|
|
/*
|
|
* Randomness driver for virtio
|
|
* Copyright (C) 2007, 2008 Rusty Russell IBM Corporation
|
|
*/
|
|
|
|
#include <asm/barrier.h>
|
|
#include <linux/err.h>
|
|
#include <linux/hw_random.h>
|
|
#include <linux/nospec.h>
|
|
#include <linux/scatterlist.h>
|
|
#include <linux/spinlock.h>
|
|
#include <linux/virtio.h>
|
|
#include <linux/virtio_rng.h>
|
|
#include <linux/dma-mapping.h>
|
|
#include <linux/module.h>
|
|
#include <linux/slab.h>
|
|
|
|
static DEFINE_IDA(rng_index_ida);
|
|
|
|
struct virtrng_info {
|
|
struct hwrng hwrng;
|
|
struct virtqueue *vq;
|
|
char name[25];
|
|
int index;
|
|
bool hwrng_register_done;
|
|
bool hwrng_removed;
|
|
/* data transfer */
|
|
struct completion have_data;
|
|
unsigned int data_avail;
|
|
unsigned int data_idx;
|
|
/* minimal size returned by rng_buffer_size() */
|
|
__dma_from_device_group_begin();
|
|
#if SMP_CACHE_BYTES < 32
|
|
u8 data[32];
|
|
#else
|
|
u8 data[SMP_CACHE_BYTES];
|
|
#endif
|
|
__dma_from_device_group_end();
|
|
};
|
|
|
|
static void random_recv_done(struct virtqueue *vq)
|
|
{
|
|
struct virtrng_info *vi = vq->vdev->priv;
|
|
unsigned int len;
|
|
|
|
/* We can get spurious callbacks, e.g. shared IRQs + virtio_pci. */
|
|
if (!virtqueue_get_buf(vi->vq, &len))
|
|
return;
|
|
|
|
smp_store_release(&vi->data_avail, len);
|
|
complete(&vi->have_data);
|
|
}
|
|
|
|
static void request_entropy(struct virtrng_info *vi)
|
|
{
|
|
struct scatterlist sg;
|
|
|
|
reinit_completion(&vi->have_data);
|
|
vi->data_idx = 0;
|
|
|
|
sg_init_one(&sg, vi->data, sizeof(vi->data));
|
|
|
|
/* There should always be room for one buffer. */
|
|
virtqueue_add_inbuf(vi->vq, &sg, 1, vi->data, GFP_KERNEL);
|
|
|
|
virtqueue_kick(vi->vq);
|
|
}
|
|
|
|
static unsigned int copy_data(struct virtrng_info *vi, void *buf,
|
|
unsigned int size)
|
|
{
|
|
unsigned int idx, avail;
|
|
|
|
/*
|
|
* vi->data_avail was set from the device-reported used.len and
|
|
* vi->data_idx was advanced by previous copy_data() calls. A
|
|
* malicious or buggy virtio-rng backend can drive either past
|
|
* sizeof(vi->data). Clamp at point of use and harden the index
|
|
* with array_index_nospec() so the memcpy() below cannot be
|
|
* steered into adjacent slab memory, including under
|
|
* speculation.
|
|
*/
|
|
avail = min_t(unsigned int, vi->data_avail, sizeof(vi->data));
|
|
if (vi->data_idx >= avail) {
|
|
vi->data_avail = 0;
|
|
request_entropy(vi);
|
|
return 0;
|
|
}
|
|
size = min_t(unsigned int, size, avail - vi->data_idx);
|
|
idx = array_index_nospec(vi->data_idx, sizeof(vi->data));
|
|
memcpy(buf, vi->data + idx, size);
|
|
vi->data_idx += size;
|
|
vi->data_avail -= size;
|
|
if (vi->data_avail == 0)
|
|
request_entropy(vi);
|
|
return size;
|
|
}
|
|
|
|
static int virtio_read(struct hwrng *rng, void *buf, size_t size, bool wait)
|
|
{
|
|
int ret;
|
|
struct virtrng_info *vi = (struct virtrng_info *)rng->priv;
|
|
unsigned int chunk;
|
|
size_t read;
|
|
|
|
if (vi->hwrng_removed)
|
|
return -ENODEV;
|
|
|
|
read = 0;
|
|
|
|
/* copy available data */
|
|
if (smp_load_acquire(&vi->data_avail)) {
|
|
chunk = copy_data(vi, buf, size);
|
|
size -= chunk;
|
|
read += chunk;
|
|
}
|
|
|
|
if (!wait)
|
|
return read;
|
|
|
|
/* We have already copied available entropy,
|
|
* so either size is 0 or data_avail is 0
|
|
*/
|
|
while (size != 0) {
|
|
/* data_avail is 0 but a request is pending */
|
|
ret = wait_for_completion_killable(&vi->have_data);
|
|
if (ret < 0)
|
|
return ret;
|
|
/* if vi->data_avail is 0, we have been interrupted
|
|
* by a cleanup, but buffer stays in the queue
|
|
*/
|
|
if (vi->data_avail == 0)
|
|
return read;
|
|
|
|
chunk = copy_data(vi, buf + read, size);
|
|
size -= chunk;
|
|
read += chunk;
|
|
}
|
|
|
|
return read;
|
|
}
|
|
|
|
static void virtio_cleanup(struct hwrng *rng)
|
|
{
|
|
struct virtrng_info *vi = (struct virtrng_info *)rng->priv;
|
|
|
|
complete(&vi->have_data);
|
|
}
|
|
|
|
static int probe_common(struct virtio_device *vdev)
|
|
{
|
|
int err, index;
|
|
struct virtrng_info *vi = NULL;
|
|
|
|
vi = kzalloc_obj(struct virtrng_info);
|
|
if (!vi)
|
|
return -ENOMEM;
|
|
|
|
vi->index = index = ida_alloc(&rng_index_ida, GFP_KERNEL);
|
|
if (index < 0) {
|
|
err = index;
|
|
goto err_ida;
|
|
}
|
|
sprintf(vi->name, "virtio_rng.%d", index);
|
|
init_completion(&vi->have_data);
|
|
|
|
vi->hwrng = (struct hwrng) {
|
|
.read = virtio_read,
|
|
.cleanup = virtio_cleanup,
|
|
.priv = (unsigned long)vi,
|
|
.name = vi->name,
|
|
};
|
|
vdev->priv = vi;
|
|
|
|
/* We expect a single virtqueue. */
|
|
vi->vq = virtio_find_single_vq(vdev, random_recv_done, "input");
|
|
if (IS_ERR(vi->vq)) {
|
|
err = PTR_ERR(vi->vq);
|
|
goto err_find;
|
|
}
|
|
|
|
virtio_device_ready(vdev);
|
|
|
|
/* we always have a pending entropy request */
|
|
request_entropy(vi);
|
|
|
|
return 0;
|
|
|
|
err_find:
|
|
ida_free(&rng_index_ida, index);
|
|
err_ida:
|
|
kfree(vi);
|
|
return err;
|
|
}
|
|
|
|
static void remove_common(struct virtio_device *vdev)
|
|
{
|
|
struct virtrng_info *vi = vdev->priv;
|
|
|
|
vi->hwrng_removed = true;
|
|
vi->data_avail = 0;
|
|
vi->data_idx = 0;
|
|
complete(&vi->have_data);
|
|
if (vi->hwrng_register_done)
|
|
hwrng_unregister(&vi->hwrng);
|
|
virtio_reset_device(vdev);
|
|
vdev->config->del_vqs(vdev);
|
|
ida_free(&rng_index_ida, vi->index);
|
|
kfree(vi);
|
|
}
|
|
|
|
static int virtrng_probe(struct virtio_device *vdev)
|
|
{
|
|
return probe_common(vdev);
|
|
}
|
|
|
|
static void virtrng_remove(struct virtio_device *vdev)
|
|
{
|
|
remove_common(vdev);
|
|
}
|
|
|
|
static void virtrng_scan(struct virtio_device *vdev)
|
|
{
|
|
struct virtrng_info *vi = vdev->priv;
|
|
int err;
|
|
|
|
err = hwrng_register(&vi->hwrng);
|
|
if (!err)
|
|
vi->hwrng_register_done = true;
|
|
}
|
|
|
|
static int virtrng_freeze(struct virtio_device *vdev)
|
|
{
|
|
remove_common(vdev);
|
|
return 0;
|
|
}
|
|
|
|
static int virtrng_restore(struct virtio_device *vdev)
|
|
{
|
|
int err;
|
|
|
|
err = probe_common(vdev);
|
|
if (!err) {
|
|
struct virtrng_info *vi = vdev->priv;
|
|
|
|
/*
|
|
* Set hwrng_removed to ensure that virtio_read()
|
|
* does not block waiting for data before the
|
|
* registration is complete.
|
|
*/
|
|
vi->hwrng_removed = true;
|
|
err = hwrng_register(&vi->hwrng);
|
|
if (!err) {
|
|
vi->hwrng_register_done = true;
|
|
vi->hwrng_removed = false;
|
|
}
|
|
}
|
|
|
|
return err;
|
|
}
|
|
|
|
static const struct virtio_device_id id_table[] = {
|
|
{ VIRTIO_ID_RNG, VIRTIO_DEV_ANY_ID },
|
|
{ 0 },
|
|
};
|
|
|
|
static struct virtio_driver virtio_rng_driver = {
|
|
.driver.name = KBUILD_MODNAME,
|
|
.id_table = id_table,
|
|
.probe = virtrng_probe,
|
|
.remove = virtrng_remove,
|
|
.scan = virtrng_scan,
|
|
.freeze = pm_sleep_ptr(virtrng_freeze),
|
|
.restore = pm_sleep_ptr(virtrng_restore),
|
|
};
|
|
|
|
module_virtio_driver(virtio_rng_driver);
|
|
MODULE_DEVICE_TABLE(virtio, id_table);
|
|
MODULE_DESCRIPTION("Virtio random number driver");
|
|
MODULE_LICENSE("GPL");
|