From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from dpdk.org (dpdk.org [92.243.14.124]) by inbox.dpdk.org (Postfix) with ESMTP id AA17AA0527 for ; Mon, 9 Nov 2020 19:43:44 +0100 (CET) Received: from [92.243.14.124] (localhost [127.0.0.1]) by dpdk.org (Postfix) with ESMTP id 9FADD6A1C; Mon, 9 Nov 2020 19:43:43 +0100 (CET) Received: from mail-wr1-f49.google.com (mail-wr1-f49.google.com [209.85.221.49]) by dpdk.org (Postfix) with ESMTP id 08F8E6883 for ; Mon, 9 Nov 2020 19:43:40 +0100 (CET) Received: by mail-wr1-f49.google.com with SMTP id s8so2779025wrw.10 for ; Mon, 09 Nov 2020 10:43:40 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=from:to:cc:subject:date:message-id:in-reply-to:references :mime-version:content-transfer-encoding; bh=TiBnQ8pViUCzW4qhLr089UGgIRdpmhKOCZfBN9kmphQ=; b=j6EOEyAKP9GLsZFTbuvn0etjvwBMvqtg+wmE13dzNjeM394rrxPejREbgMGte/gjb6 l/PdY3ki30devj/DimtkXnsYHe+HvPKEwPf4PSfE8rowu8VDDE9/V+11eRUfU8Qcvndf ILC3BbqKHKnvwwONN2801vOd3zYb/WSbfWX4EhBBxoGPuwcaiQaG6CatKlxsGsL7dGqh Cykp6gbgr1vI6HhG7MAEJVJbFSRp69oPsC7mxYpRzLfjfVLJ2howTd2DtUsa+htHelbt xfrN05bSAHDZ8TtS0g+zm5swtjE8eyYQgCLobacjqLJpgk8jDFQGntcB6hvLbZN45kT3 7ZZQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:from:to:cc:subject:date:message-id:in-reply-to :references:mime-version:content-transfer-encoding; bh=TiBnQ8pViUCzW4qhLr089UGgIRdpmhKOCZfBN9kmphQ=; b=gje3a/VGsKG7A0O2CJI1IJSeZrqHF0/rTEEooVuOHFeUXnuIYB67CXa4GI3dtTMkXD eazZNnINXxlvMXn/KcOcHiDDShIH+f4xuPp8T3ykgFWckd6k6k0+h4gQ1emXLcZZA0Xs k7BbOfgAuKdG7f8Z1s0RcVIq53E8rJwK8BOCnpmkmzi2DUKuw25HaAQZoSKC6cQvdSkU 47SppX4vhaZ5fQFe58QZ27WiLU0eqYO/4ctvvvIRX+oCSVizjcqa6Y+4Fste9mS3i3QC GGnYJfh87d4yje4SJPTLU0IwHQFLozt5zrbC2eFhrNF9nCYO5B4w0NZLHI5MR7EPtgtx HGHw== X-Gm-Message-State: AOAM5331G70rrbXMH9h3DR3+meTJosccGTjyyf+S/5xz955WCExFR+je b/wcT/TD3fRzwrWaANoThIU= X-Google-Smtp-Source: ABdhPJwqfP29CiilojWLe4bQpwkHfNqugho1Rvk3CPiUK5P9MH5v5qjQ+XGlhvGiqLKj49IJQhsjFg== X-Received: by 2002:adf:ea50:: with SMTP id j16mr14193475wrn.283.1604947419844; Mon, 09 Nov 2020 10:43:39 -0800 (PST) Received: from localhost ([88.98.246.218]) by smtp.gmail.com with ESMTPSA id s8sm10177857wrn.33.2020.11.09.10.43.39 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 09 Nov 2020 10:43:39 -0800 (PST) From: luca.boccassi@gmail.com To: Maxime Coquelin Cc: Chenbo Xia , dpdk stable Date: Mon, 9 Nov 2020 18:40:30 +0000 Message-Id: <20201109184111.3463090-42-luca.boccassi@gmail.com> X-Mailer: git-send-email 2.27.0 In-Reply-To: <20201109184111.3463090-1-luca.boccassi@gmail.com> References: <20201028104606.3504127-207-luca.boccassi@gmail.com> <20201109184111.3463090-1-luca.boccassi@gmail.com> MIME-Version: 1.0 Content-Transfer-Encoding: 8bit Subject: [dpdk-stable] patch 'vhost: validate index in guest notification API' has been queued to stable release 19.11.6 X-BeenThere: stable@dpdk.org X-Mailman-Version: 2.1.15 Precedence: list List-Id: patches for DPDK stable branches List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: stable-bounces@dpdk.org Sender: "stable" Hi, FYI, your patch has been queued to stable release 19.11.6 Note it hasn't been pushed to http://dpdk.org/browse/dpdk-stable yet. It will be pushed if I get no objections before 11/11/20. So please shout if anyone has objections. Also note that after the patch there's a diff of the upstream commit vs the patch applied to the branch. This will indicate if there was any rebasing needed to apply to the stable branch. If there were code changes for rebasing (ie: not only metadata diffs), please double check that the rebase was correctly done. Queued patches are on a temporary branch at: https://github.com/bluca/dpdk-stable This queued commit can be viewed at: https://github.com/bluca/dpdk-stable/commit/ed20f3a8ddd90b419d93d383765f6b4f6c93f3f9 Thanks. Luca Boccassi --- >From ed20f3a8ddd90b419d93d383765f6b4f6c93f3f9 Mon Sep 17 00:00:00 2001 From: Maxime Coquelin Date: Mon, 19 Oct 2020 19:34:11 +0200 Subject: [PATCH] vhost: validate index in guest notification API [ upstream commit 366374054b656e049188216e2fa44831749c2a21 ] This patch validates the queue index parameter, in order to ensure neither out-of-bound accesses nor NULL pointer dereferencing happen. Fixes: 9eed6bfd2efb ("vhost: allow to enable or disable features") Signed-off-by: Maxime Coquelin Reviewed-by: Chenbo Xia --- lib/librte_vhost/vhost.c | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/lib/librte_vhost/vhost.c b/lib/librte_vhost/vhost.c index 0f6c1ef8de..2d23de598e 100644 --- a/lib/librte_vhost/vhost.c +++ b/lib/librte_vhost/vhost.c @@ -1333,7 +1333,12 @@ rte_vhost_enable_guest_notification(int vid, uint16_t queue_id, int enable) if (!dev) return -1; + if (queue_id >= VHOST_MAX_VRING) + return -1; + vq = dev->virtqueue[queue_id]; + if (!vq) + return -1; rte_spinlock_lock(&vq->access_lock); -- 2.27.0 --- Diff of the applied patch vs upstream commit (please double-check if non-empty: --- --- - 2020-11-09 18:40:12.843697404 +0000 +++ 0042-vhost-validate-index-in-guest-notification-API.patch 2020-11-09 18:40:11.167311842 +0000 @@ -1 +1 @@ -From 366374054b656e049188216e2fa44831749c2a21 Mon Sep 17 00:00:00 2001 +From ed20f3a8ddd90b419d93d383765f6b4f6c93f3f9 Mon Sep 17 00:00:00 2001 @@ -5,0 +6,2 @@ +[ upstream commit 366374054b656e049188216e2fa44831749c2a21 ] + @@ -11 +12,0 @@ -Cc: stable@dpdk.org @@ -20 +21 @@ -index 193dafc369..801a1a5098 100644 +index 0f6c1ef8de..2d23de598e 100644 @@ -23 +24 @@ -@@ -1352,7 +1352,12 @@ rte_vhost_enable_guest_notification(int vid, uint16_t queue_id, int enable) +@@ -1333,7 +1333,12 @@ rte_vhost_enable_guest_notification(int vid, uint16_t queue_id, int enable)