[PATCH 5.10] io_uring: prevent opcode speculation
Alexey Panov <[email protected]>
| Newsgroups | org.kernel.vger.io-uring,org.kernel.vger.linux-kernel,org.kernel.vger.stable |
|---|---|
| Message-ID | <[email protected]> |
From: Pavel Begunkov <[email protected]> commit 1e988c3fe1264708f4f92109203ac5b1d65de50b upstream. sqe->opcode is used for different tables, make sure we santitise it against speculations. Cc: [email protected] Fixes: d3656344fea03 ("io_uring: add lookup table for various opcode needs") Signed-off-by: Pavel Begunkov <[email protected]> Reviewed-by: Li Zetao <[email protected]> Link: https://lore.kernel.org/r/7eddbf31c8ca0a3947f8ed98271acc2b4349c016.1739568408.git.asml.silence@gmail.com Signed-off-by: Jens Axboe <[email protected]> [ Alexey: Sanitize req->opcode directly because io_init_req() in linux-5.10.y has no local opcode variable and subsequent lookups use it. ] Signed-off-by: Alexey Panov <[email protected]> --- Backport fix for CVE-2025-21863 io_uring/io_uring.c | 2 ++ 1 file changed, 2 insertions(+) diff --git a/io_uring/io_uring.c b/io_uring/io_uring.c index 2ca09e2dbd3d..51262d48a4a1 100644 --- a/io_uring/io_uring.c +++ b/io_uring/io_uring.c @@ -7193,6 +7193,8 @@ static int io_init_req(struct io_ring_ctx *ctx, struct io_kiocb *req, return -EINVAL; if (unlikely(req->opcode >= IORING_OP_LAST)) return -EINVAL; + req->opcode = array_index_nospec(req->opcode, IORING_OP_LAST); + if (!io_check_restriction(ctx, req, sqe_flags)) return -EACCES; -- 2.47.3