From nobody Fri Jul 24 04:54:36 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-1.web.codeaurora.org [10.30.226.201]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 3C56A1F1537; Fri, 24 Jul 2026 00:23:28 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=10.30.226.201 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784852608; cv=none; b=AbzNr8xYM9CeBJxBcSX9LTUEPMu1VXBvcl///19bjfZdQcVG5X15h8NZxPhuPadjjliHgW66NPP5Kt1n/B+hrLGnSCdRgzvFgB+DP3FntjO9n4HsgZENDpXFQHt3ZOMaC0JAoxhK0Hd0+/2evy+1EOGPfzXOykzZRax8EUFIvXA= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784852608; c=relaxed/simple; bh=4U931wxTAQmoZLnKF+f1/StB+kUujXXSkxuDOtR8rvs=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=s9Yq7MCpD7bd3swEuce0/42j0RDso7EHCWF2Ql/qxMt+uMplywnKRxY1CiCEGQTjWs3OP6iQtxW4smTrcYJXPDzZKfxOaZ3G2YJhm02nsnuGaUVaUpxwXFeuwcobCZ41L+CHXRSt/qUqx3woCkDK/PMtp/0HR5bajpWAe9g6eJs= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=HEo1G+FR; arc=none smtp.client-ip=10.30.226.201 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="HEo1G+FR" Received: by smtp.kernel.org (Postfix) with ESMTPS id CE7BBC2BCC9; Fri, 24 Jul 2026 00:23:27 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kernel.org; s=k20201202; t=1784852607; bh=4U931wxTAQmoZLnKF+f1/StB+kUujXXSkxuDOtR8rvs=; h=From:Date:Subject:References:In-Reply-To:To:Cc:Reply-To:From; b=HEo1G+FRo6pDKc0zcKK/b84USUFaWRY1ZpFIqGGdodnJ9cslb672BI1W7+VIvXovY Ykzvd3MgF46QPRwfmEQdyNiHnRNLOX2d1yBgfoeA+fWVAcG9HjyiRXjYJPIjvRVPlT SKyvabSH+8Q/qtuWXjnNErOTYZw5UeQaS/zx8chsKFScX1q87GwN7ZGQfM/pkeBpmA 5Ljd6bZYQqlH3Bf47uwGh8CzGMh3FJDKltUK+5mq6tny+3ia14JLPPEuLKSZk79y/Z FSryf8SIRnPfoHJzC5y07FJmRkpaDOUZhH/e+2d1rm89V8cB7roUWg85aEbFSVf8iz 4OFCFYKqgF2YA== Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id ACD86C531D0; Fri, 24 Jul 2026 00:23:27 +0000 (UTC) From: Bryam Vargas via B4 Relay Date: Thu, 23 Jul 2026 19:23:27 -0500 Subject: [PATCH net v5 1/3] net/smc: bound the wire-controlled producer cursor to the RMB Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260723-b4-disp-0d07164f-v5-1-6a9e235dbc4e@proton.me> References: <20260723-b4-disp-0d07164f-v5-0-6a9e235dbc4e@proton.me> In-Reply-To: <20260723-b4-disp-0d07164f-v5-0-6a9e235dbc4e@proton.me> To: Sidraya Jayagond , Jakub Kicinski , "D. Wythe" , "David S. Miller" , Wen Gu , Wenjia Zhang , Eric Dumazet , Tony Lu , Mahanta Jambigi , Dust Li , Paolo Abeni Cc: linux-s390@vger.kernel.org, linux-rdma@vger.kernel.org, Ursula Braun , netdev@vger.kernel.org, linux-kernel@vger.kernel.org, Stefan Raspl , Simon Horman X-Mailer: b4 0.15.2 X-Developer-Signature: v=1; a=ed25519-sha256; t=1784852606; l=3711; i=hexlabsecurity@proton.me; s=default; h=from:subject:message-id; bh=evfdLZhJwQ6ZMPc4z0HkxIgfLkW4b4DY7F1ZY4ekk4k=; b=7Qw/oy853Ph9hvxtrZ0JZoIoX89s7qlGw+z+8M8wFc6WHh+oTRgnrlGwMCNSyJ1T2ix4sx16f nYmg/zXbcpFBcMyNn98z15C2UFQdO2lonmZ7S34wmVrM95bB+9wkEHc X-Developer-Key: i=hexlabsecurity@proton.me; a=ed25519; pk=xw1AhCtQdvuoQc+bOQIYy9o8G++cp4/VniI2G/tc3G8= X-Endpoint-Received: by B4 Relay for hexlabsecurity@proton.me/default with auth_id=893 X-Original-From: Bryam Vargas Reply-To: hexlabsecurity@proton.me From: Bryam Vargas smcr_cdc_msg_to_host() and smcd_cdc_msg_to_host() import a peer's producer cursor from the wire into conn->local_rx_ctrl.prod without bounding it against the receive buffer. The urgent-data path in smc_cdc_msg_recv_action() then uses that count as a raw index into the RMB, so a peer that advertises a producer cursor past rmb_desc->len reads out of bounds of the RMB allocation in the receive tasklet and can disclose adjacent kernel memory. Bound the producer cursor count to rmb_desc->len at the wire-to-host conversion, for both SMC-R and SMC-D. Bound only the producer cursor: the consumer cursor indexes the peer's RMB and is bounded by peer_rmbe_size, so clamping it to our rmb_desc->len would under-credit peer_rmbe_space and stall transmit to a peer with a larger RMB. Conforming peers are unaffected. Fixes: de8474eb9d50 ("net/smc: urgent data support") Cc: stable@vger.kernel.org Signed-off-by: Bryam Vargas Reviewed-by: Dust Li --- net/smc/smc_cdc.h | 27 ++++++++++++++++++++++++--- 1 file changed, 24 insertions(+), 3 deletions(-) diff --git a/net/smc/smc_cdc.h b/net/smc/smc_cdc.h index 696cc11f2303..ca76ef630356 100644 --- a/net/smc/smc_cdc.h +++ b/net/smc/smc_cdc.h @@ -221,7 +221,8 @@ static inline void smc_host_msg_to_cdc(struct smc_cdc_m= sg *peer, =20 static inline void smc_cdc_cursor_to_host(union smc_host_cursor *local, union smc_cdc_cursor *peer, - struct smc_connection *conn) + struct smc_connection *conn, + int max_count) { union smc_host_cursor temp, old; union smc_cdc_cursor net; @@ -235,6 +236,15 @@ static inline void smc_cdc_cursor_to_host(union smc_ho= st_cursor *local, if ((old.wrap =3D=3D temp.wrap) && (old.count > temp.count)) return; + /* The peer producer cursor is wire-controlled and is later used as a + * raw index into our RMB by the urgent path; bound its count to the + * RMB. max_count =3D=3D 0 leaves the consumer cursor unbounded here: it + * indexes the peer's RMB (bounded by peer_rmbe_size, not our + * rmb_desc->len), so clamping it to rmb_desc->len would under-credit + * peer_rmbe_space and stall transmit to peers with a larger RMB. + */ + if (max_count && temp.count > max_count) + temp.count =3D max_count; smc_curs_copy(local, &temp, conn); } =20 @@ -246,8 +256,13 @@ static inline void smcr_cdc_msg_to_host(struct smc_hos= t_cdc_msg *local, local->len =3D peer->len; local->seqno =3D ntohs(peer->seqno); local->token =3D ntohl(peer->token); - smc_cdc_cursor_to_host(&local->prod, &peer->prod, conn); - smc_cdc_cursor_to_host(&local->cons, &peer->cons, conn); + /* bound the wire-controlled producer cursor to our RMB (used as a raw + * index by the urgent path); leave the consumer cursor unbounded -- it + * indexes the peer's RMB and is bounded by peer_rmbe_size. + */ + smc_cdc_cursor_to_host(&local->prod, &peer->prod, conn, + conn->rmb_desc->len); + smc_cdc_cursor_to_host(&local->cons, &peer->cons, conn, 0); local->prod_flags =3D peer->prod_flags; local->conn_state_flags =3D peer->conn_state_flags; } @@ -260,6 +275,12 @@ static inline void smcd_cdc_msg_to_host(struct smc_hos= t_cdc_msg *local, =20 temp.wrap =3D peer->prod.wrap; temp.count =3D peer->prod.count; + /* the peer producer cursor is wire-controlled and is used as a raw + * index into our RMB by the urgent path; bound it to the RMB. The + * consumer cursor below indexes the peer's RMB and is left unbounded. + */ + if (temp.count > conn->rmb_desc->len) + temp.count =3D conn->rmb_desc->len; smc_curs_copy(&local->prod, &temp, conn); =20 temp.wrap =3D peer->cons.wrap; --=20 2.55.0 From nobody Fri Jul 24 04:54:36 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-1.web.codeaurora.org [10.30.226.201]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 3C4D01F12F8; Fri, 24 Jul 2026 00:23:28 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=10.30.226.201 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784852608; cv=none; b=PXphK+T84lF7KNZRyCUTrc82BJJ39Rc3lxtsoxzUOVAp8iLmudsc2CDKrYW/MB0XKnfw/Wb0ULLi2jnkIc7v7yBFvJVe6lxIY1Ae8EjZsENP3YIUsH+ia2pMBm+emd/OR5U3f4qwCN2dD6CRZIDTYufyDZ4LN48JFbwAws/pGCk= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784852608; c=relaxed/simple; bh=wtIBtTyP/+rwa75zuMxIQgpfe6IECDYlolre7EIzHWY=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=I5p/axDkWIyoyNOys3yJ4vTXl2W0gs0jZSbk+AVErJZe5+0bdw5Jv45QdruMKOAu517MYzPNDeH9VU36j8g9vgfWOF0/+ekvnAnUUXiDfo8sH6MtJIEEgm12GKu+RhDuWmq3GEAuKoFLPz0ADkvmJJ4uX/TLvawc7px5/8UfHzo= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=TetauBhM; arc=none smtp.client-ip=10.30.226.201 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="TetauBhM" Received: by smtp.kernel.org (Postfix) with ESMTPS id DD3A5C2BCC7; Fri, 24 Jul 2026 00:23:27 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kernel.org; s=k20201202; t=1784852607; bh=wtIBtTyP/+rwa75zuMxIQgpfe6IECDYlolre7EIzHWY=; h=From:Date:Subject:References:In-Reply-To:To:Cc:Reply-To:From; b=TetauBhM7nd3lLfgT967nfKOdpNvFizey+JP8P0Hoy9uh9x9U0UPnI9Zqnw3yjAsE NSeQ043mFMVYOtZzr+v7Sm6thnl1KMYmZQ+gpaFVjqKfTnRbzt4PjQ/mxTdJgLUc4i B+yi2Dd1DvhosRnwNRZs9ndxRW8XRdjZI9smFU8/gU44DMOVNfyjy1s8D9qo3Q5KQ1 wWcOnkf5yMM78quTL2yq3mD9jBH5QOmS/B2do2nkueWczZ+acjDOlK4bp5nj791mye XEtmHAF53VxUBq0O5JZrlJ08dxDhZ6r31VWtsGQgq+ZsKzceYOac70r6jHMO952MC9 G8oeigE34MmZg== Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id BE884C531CC; Fri, 24 Jul 2026 00:23:27 +0000 (UTC) From: Bryam Vargas via B4 Relay Date: Thu, 23 Jul 2026 19:23:28 -0500 Subject: [PATCH net v5 2/3] net/smc: bound the receive length to the RMB in smc_rx_recvmsg() Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260723-b4-disp-0d07164f-v5-2-6a9e235dbc4e@proton.me> References: <20260723-b4-disp-0d07164f-v5-0-6a9e235dbc4e@proton.me> In-Reply-To: <20260723-b4-disp-0d07164f-v5-0-6a9e235dbc4e@proton.me> To: Sidraya Jayagond , Jakub Kicinski , "D. Wythe" , "David S. Miller" , Wen Gu , Wenjia Zhang , Eric Dumazet , Tony Lu , Mahanta Jambigi , Dust Li , Paolo Abeni Cc: linux-s390@vger.kernel.org, linux-rdma@vger.kernel.org, Ursula Braun , netdev@vger.kernel.org, linux-kernel@vger.kernel.org, Stefan Raspl , Simon Horman X-Mailer: b4 0.15.2 X-Developer-Signature: v=1; a=ed25519-sha256; t=1784852606; l=2495; i=hexlabsecurity@proton.me; s=default; h=from:subject:message-id; bh=zm+DwFi/hrFlsMaixwWDBBXKLevUgGKVa9KJqBjGNh8=; b=1jKt0ih0NXm8Ad9+veJJYvSZ2OkqjzWmQHosnqe+bTJKHQ2WmWBmNifIbvfTRWtCWE3fZQgP8 mWwjS5BIA8kCL2hQWENk1XVnk/1MFhjx8IuilEXmGOS8QqRffLCF1Nm X-Developer-Key: i=hexlabsecurity@proton.me; a=ed25519; pk=xw1AhCtQdvuoQc+bOQIYy9o8G++cp4/VniI2G/tc3G8= X-Endpoint-Received: by B4 Relay for hexlabsecurity@proton.me/default with auth_id=893 X-Original-From: Bryam Vargas Reply-To: hexlabsecurity@proton.me From: Bryam Vargas conn->bytes_to_rcv is accumulated in the receive tasklet from the peer's wire-controlled producer cursor via smc_curs_diff(), whose differing-wrap branch can exceed rmb_desc->len; a forged cursor drives bytes_to_rcv past the RMB, and over many CDC messages overflows the signed counter negative. smc_rx_recvmsg() reads it as the readable length and does a wrap-around copy whose second chunk is not re-bounded to rmb_desc->len, reading past the RMB into adjacent kernel memory and disclosing it to the peer. The nearby readable >=3D rmb_desc->len test only feeds SMC_STAT_RMB_RX_FULL on a separate earlier read; it does not bound the copy. Bound the readable length to rmb_desc->len at the consumer, treating a negative (sign-overflowed) value as out of range too, so the copy can never exceed the ring. This enforces the documented 0 <=3D bytes_to_rcv <=3D rmb_desc->len invariant where it is race-free against the producer update in the tasklet; conforming peers are unaffected. Fixes: 952310ccf2d8 ("smc: receive data from RMBE") Cc: stable@vger.kernel.org Signed-off-by: Bryam Vargas Reviewed-by: Dust Li --- net/smc/smc_rx.c | 12 ++++++++++++ 1 file changed, 12 insertions(+) diff --git a/net/smc/smc_rx.c b/net/smc/smc_rx.c index c1d9b923938d..f461cf10b085 100644 --- a/net/smc/smc_rx.c +++ b/net/smc/smc_rx.c @@ -442,6 +442,18 @@ int smc_rx_recvmsg(struct smc_sock *smc, struct msghdr= *msg, /* initialize variables for 1st iteration of subsequent loop */ /* could be just 1 byte, even after waiting on data above */ readable =3D smc_rx_data_available(conn, peeked_bytes); + /* bytes_to_rcv is accumulated from the peer's wire-controlled + * producer cursor; a forged cursor can drive it past the RMB, + * or overflow the signed accumulator to a negative value across + * many CDC messages (which a plain "> len" check would miss + * before the size_t cast below turns it huge). Bound it to the + * RMB in either case so the wrap-around copy cannot run past + * rmb_desc->len. This enforces the documented + * 0 <=3D bytes_to_rcv <=3D rmb_desc->len invariant at the consumer, + * race-free against the producer update in the receive tasklet. + */ + if (readable < 0 || readable > conn->rmb_desc->len) + readable =3D conn->rmb_desc->len; splbytes =3D atomic_read(&conn->splice_pending); if (!readable || (msg && splbytes)) { if (splbytes) --=20 2.55.0 From nobody Fri Jul 24 04:54:36 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-1.web.codeaurora.org [10.30.226.201]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 3C4721F09AD; Fri, 24 Jul 2026 00:23:28 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=10.30.226.201 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784852608; cv=none; b=JO3rU8dFiAbZhFeFUIlVeTEyzkLE8lWggGW1j9/UaerOIipILhu6jUDeecSVuGm5W/EVHSu1lTt/gmdU+xgFco2oWOmk3jN6fyM5hVRfkcDsXX6o+0/ZQV4Nw8y7GVKSykv9iTr1pQ3NSFhRhg7TCsa6VOhCURUNrREosZcjntE= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784852608; c=relaxed/simple; bh=lFbH1CCvij/4i9LKAdaYnKbFIWlJgCM95xj9koGcN2Y=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=RzPdOHQbYxdXE2piVhr22Bt2Km8PSZlJWwlzIK1MvJyHHedqhwljVSyCNEsiZZolLYjqWkFLLvJvo8fPsFqm0ko0c9yhVzFt/IgecMqSlzHHgLhWGaPBs42b3US/prIeSl1/dFz4w+yQjNvXhg8zTbXN8n5hMKUs+ACsBTHZasc= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=cFuk8oda; arc=none smtp.client-ip=10.30.226.201 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="cFuk8oda" Received: by smtp.kernel.org (Postfix) with ESMTPS id E9C98C2BCFC; Fri, 24 Jul 2026 00:23:27 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kernel.org; s=k20201202; t=1784852608; bh=lFbH1CCvij/4i9LKAdaYnKbFIWlJgCM95xj9koGcN2Y=; h=From:Date:Subject:References:In-Reply-To:To:Cc:Reply-To:From; b=cFuk8oda5P6rog7Fx07nz874DDh53uLOvVC84pwqQACoHA2nTknE84X296sbP1HeM H/nk5/P6ta9SjBiaJ6Ok+m+f3GhP/Bs/2O9vdJLB1fnVdb7qXPgPOqJeOZotk5CeTZ FbDiAC3TFdH77+qraOlnEsG7Idi/92anaKgyoigu39+mZiY5H+4vUoo4E9vRlKUcZM 5gBZNvALxLsNInS5dTnzIoSPppdRcVQQmk4Vi7O2OqaPC85u/KNL8xlJENvKo2KV3n 16A94wUqVFZ0a6PX54PQeAHQVX/EXwrLNDREkWLanj5ZvReLhE0HcfYT5D+zL74I0z vQQl3H/coDVwQ== Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id CF231C53200; Fri, 24 Jul 2026 00:23:27 +0000 (UTC) From: Bryam Vargas via B4 Relay Date: Thu, 23 Jul 2026 19:23:29 -0500 Subject: [PATCH net v5 3/3] net/smc: bound the send length to the send buffer in smc_tx_sendmsg() Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260723-b4-disp-0d07164f-v5-3-6a9e235dbc4e@proton.me> References: <20260723-b4-disp-0d07164f-v5-0-6a9e235dbc4e@proton.me> In-Reply-To: <20260723-b4-disp-0d07164f-v5-0-6a9e235dbc4e@proton.me> To: Sidraya Jayagond , Jakub Kicinski , "D. Wythe" , "David S. Miller" , Wen Gu , Wenjia Zhang , Eric Dumazet , Tony Lu , Mahanta Jambigi , Dust Li , Paolo Abeni Cc: linux-s390@vger.kernel.org, linux-rdma@vger.kernel.org, Ursula Braun , netdev@vger.kernel.org, linux-kernel@vger.kernel.org, Stefan Raspl , Simon Horman X-Mailer: b4 0.15.2 X-Developer-Signature: v=1; a=ed25519-sha256; t=1784852606; l=2658; i=hexlabsecurity@proton.me; s=default; h=from:subject:message-id; bh=8C3EH0KfsseVdj0wFDorSSLeXucgic78NU8CwLD1UGY=; b=2mSEnlOyc3Atj5qvzKHW+F9fZj1VNtAgW6zuSNokT8fhXO1Dc3GNz0knM819b1+j/3aQmZJ3j FA0ny6jpKjACzMFFaf6urMjbGvgMUvxBZtZbNVMp+DGaNyEDAt5Lni2 X-Developer-Key: i=hexlabsecurity@proton.me; a=ed25519; pk=xw1AhCtQdvuoQc+bOQIYy9o8G++cp4/VniI2G/tc3G8= X-Endpoint-Received: by B4 Relay for hexlabsecurity@proton.me/default with auth_id=893 X-Original-From: Bryam Vargas Reply-To: hexlabsecurity@proton.me From: Bryam Vargas On the SMC-D DMB-merge (nocopy) path, smc_cdc_msg_recv_action() advances conn->sndbuf_space from the peer's wire-controlled consumer cursor via smc_curs_diff(), which can return more than sndbuf_desc->len; a forged cursor drives sndbuf_space past the send buffer, and over many CDC messages overflows the signed counter negative. smc_tx_sendmsg() reads it as the write space and does a wrap-around copy whose second chunk is not re-bounded to sndbuf_desc->len, spilling the local sender's outbound data past the send buffer at a peer-controlled length: a heap out-of-bounds write. The nearby len > sndbuf_desc->len test only feeds SMC_STAT_RMB_TX_SIZE_SMALL on the user length; it does not bound the copy. Bound the write space to sndbuf_desc->len at the consumer, treating a negative (sign-overflowed) value as out of range too, so the copy can never exceed the ring. This enforces the documented 0 <=3D sndbuf_space <=3D sndbuf_desc->len invariant where it is race-free against the CDC tasklet; conforming peers are unaffected. Fixes: cc0ab806fc52 ("net/smc: adapt cursor update when sndbuf and peer DMB= are merged") Cc: stable@vger.kernel.org Signed-off-by: Bryam Vargas Reviewed-by: Dust Li --- net/smc/smc_tx.c | 13 +++++++++++++ 1 file changed, 13 insertions(+) diff --git a/net/smc/smc_tx.c b/net/smc/smc_tx.c index 3144b4b1fe29..5916f02060fb 100644 --- a/net/smc/smc_tx.c +++ b/net/smc/smc_tx.c @@ -233,6 +233,19 @@ int smc_tx_sendmsg(struct smc_sock *smc, struct msghdr= *msg, size_t len) /* initialize variables for 1st iteration of subsequent loop */ /* could be just 1 byte, even after smc_tx_wait above */ writespace =3D atomic_read(&conn->sndbuf_space); + /* sndbuf_space is advanced from the peer's wire-controlled + * consumer cursor on the SMC-D DMB-merge path; a forged cursor + * can inflate it past the send buffer, or overflow the signed + * accumulator to a negative value across many CDC messages + * (which a plain "> len" check would miss before the size_t + * cast below turns it huge). Bound it to the send buffer in + * either case so the wrap-around write cannot run past + * sndbuf_desc->len. This enforces the documented + * 0 <=3D sndbuf_space <=3D sndbuf_desc->len invariant at the + * producer, race-free against the CDC tasklet. + */ + if (writespace < 0 || writespace > conn->sndbuf_desc->len) + writespace =3D conn->sndbuf_desc->len; /* not more than what user space asked for */ copylen =3D min_t(size_t, send_remaining, writespace); /* determine start of sndbuf */ --=20 2.55.0