mirror of
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git
synced 2025-12-27 10:01:39 -05:00
blkdev_pr_read_keys() takes num_keys from userspace and uses it to
calculate the allocation size for keys_info via struct_size(). While
there is a check for SIZE_MAX (integer overflow), there is no upper
bound validation on the allocation size itself.
A malicious or buggy userspace can pass a large num_keys value that
doesn't trigger overflow but still results in an excessive allocation
attempt, causing a warning in the page allocator when the order exceeds
MAX_PAGE_ORDER.
Fix this by introducing PR_KEYS_MAX to limit the number of keys to
a sane value. This makes the SIZE_MAX check redundant, so remove it.
Also switch to kvzalloc/kvfree to handle larger allocations gracefully.
Fixes: 22a1ffea5f ("block: add IOC_PR_READ_KEYS ioctl")
Tested-by: syzbot+660d079d90f8a1baf54d@syzkaller.appspotmail.com
Reported-by: syzbot+660d079d90f8a1baf54d@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=660d079d90f8a1baf54d
Link: https://lore.kernel.org/all/20251212013510.3576091-1-kartikey406@gmail.com/T/ [v1]
Signed-off-by: Deepanshu Kartikey <kartikey406@gmail.com>
Reviewed-by: Martin K. Petersen <martin.petersen@oracle.com>
Reviewed-by: Stefan Hajnoczi <stefanha@redhat.com>
Signed-off-by: Jens Axboe <axboe@kernel.dk>
85 lines
1.9 KiB
C
85 lines
1.9 KiB
C
/* SPDX-License-Identifier: GPL-2.0 WITH Linux-syscall-note */
|
|
#ifndef _UAPI_PR_H
|
|
#define _UAPI_PR_H
|
|
|
|
#include <linux/types.h>
|
|
|
|
enum pr_status {
|
|
PR_STS_SUCCESS = 0x0,
|
|
/*
|
|
* The following error codes are based on SCSI, because the interface
|
|
* was originally created for it and has existing users.
|
|
*/
|
|
/* Generic device failure. */
|
|
PR_STS_IOERR = 0x2,
|
|
PR_STS_RESERVATION_CONFLICT = 0x18,
|
|
/* Temporary path failure that can be retried. */
|
|
PR_STS_RETRY_PATH_FAILURE = 0xe0000,
|
|
/* The request was failed due to a fast failure timer. */
|
|
PR_STS_PATH_FAST_FAILED = 0xf0000,
|
|
/* The path cannot be reached and has been marked as failed. */
|
|
PR_STS_PATH_FAILED = 0x10000,
|
|
};
|
|
|
|
enum pr_type {
|
|
PR_WRITE_EXCLUSIVE = 1,
|
|
PR_EXCLUSIVE_ACCESS = 2,
|
|
PR_WRITE_EXCLUSIVE_REG_ONLY = 3,
|
|
PR_EXCLUSIVE_ACCESS_REG_ONLY = 4,
|
|
PR_WRITE_EXCLUSIVE_ALL_REGS = 5,
|
|
PR_EXCLUSIVE_ACCESS_ALL_REGS = 6,
|
|
};
|
|
|
|
struct pr_reservation {
|
|
__u64 key;
|
|
__u32 type;
|
|
__u32 flags;
|
|
};
|
|
|
|
struct pr_registration {
|
|
__u64 old_key;
|
|
__u64 new_key;
|
|
__u32 flags;
|
|
__u32 __pad;
|
|
};
|
|
|
|
struct pr_preempt {
|
|
__u64 old_key;
|
|
__u64 new_key;
|
|
__u32 type;
|
|
__u32 flags;
|
|
};
|
|
|
|
struct pr_clear {
|
|
__u64 key;
|
|
__u32 flags;
|
|
__u32 __pad;
|
|
};
|
|
|
|
struct pr_read_keys {
|
|
__u32 generation;
|
|
__u32 num_keys;
|
|
__u64 keys_ptr;
|
|
};
|
|
|
|
struct pr_read_reservation {
|
|
__u64 key;
|
|
__u32 generation;
|
|
__u32 type;
|
|
};
|
|
|
|
#define PR_FL_IGNORE_KEY (1 << 0) /* ignore existing key */
|
|
|
|
#define IOC_PR_REGISTER _IOW('p', 200, struct pr_registration)
|
|
#define IOC_PR_RESERVE _IOW('p', 201, struct pr_reservation)
|
|
#define IOC_PR_RELEASE _IOW('p', 202, struct pr_reservation)
|
|
#define IOC_PR_PREEMPT _IOW('p', 203, struct pr_preempt)
|
|
#define IOC_PR_PREEMPT_ABORT _IOW('p', 204, struct pr_preempt)
|
|
#define IOC_PR_CLEAR _IOW('p', 205, struct pr_clear)
|
|
#define IOC_PR_READ_KEYS _IOWR('p', 206, struct pr_read_keys)
|
|
#define IOC_PR_READ_RESERVATION _IOR('p', 207, struct pr_read_reservation)
|
|
|
|
#define PR_KEYS_MAX (1u << 16)
|
|
|
|
#endif /* _UAPI_PR_H */
|