Re: [PATCH v1 2/2] iommu/virtio: Reject short event buffers

Will Deacon <[email protected]>
Newsgroups dev.linux.lists.iommu,dev.linux.lists.virtualization,org.kernel.vger.linux-kernel
Message-ID <amE5Id5R6tGuIlRg@willie-the-truck>
On Tue, Jul 14, 2026 at 10:59:14AM +0800, weimin xiong wrote:
> From: Xiong Weimin <[email protected]>
> 
> viommu_event_handler() only rejects event buffers that are larger than
> struct viommu_event. A short buffer is also invalid, but the handler
> would still read evt->head and, for fault events, the rest of evt->fault.
> 
> Require the used length to match the event buffer size before looking at
> the event contents.
> 
> Signed-off-by: Xiong Weimin <[email protected]>
> ---
>  drivers/iommu/virtio-iommu.c | 2 +-
>  1 file changed, 1 insertion(+), 1 deletion(-)
> 
> diff --git a/drivers/iommu/virtio-iommu.c b/drivers/iommu/virtio-iommu.c
> index 4c91a82d2..4b7f0dcfa 100644
> --- a/drivers/iommu/virtio-iommu.c
> +++ b/drivers/iommu/virtio-iommu.c
> @@ -635,7 +635,7 @@ static void viommu_event_handler(struct virtqueue *vq)
>  	struct viommu_dev *viommu = vq->vdev->priv;
>  
>  	while ((evt = virtqueue_get_buf(vq, &len)) != NULL) {
> -		if (len > sizeof(*evt)) {
> +		if (len != sizeof(*evt)) {
>  			dev_err(viommu->dev,
>  				"invalid event buffer (len %u != %zu)\n",
>  				len, sizeof(*evt));

See Jean-Phillipe's previous reply to an identical patch:

https://lore.kernel.org/all/[email protected]/

Will
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.