[PATCH] virtio: virtio_ring: prevent potential null dereference on per-desc state

Roi L <[email protected]>
Newsgroups org.kernel.vger.linux-kernel,dev.linux.lists.virtualization
Message-ID <SN6PR05MB5806027A02B2C001C8E600FDDDD42@SN6PR05MB5806.namprd05.prod.outlook.com>
When accessing the per-descriptor state structure, we could overflow
desc_state[] because id can be accessed by the host and the guest
at the same time, as described by the packed implementation.

'commit 32fe1de5c124 ("virtio_ring: Add READ_ONCE annotations for device-writable fields")'

The commit mentions these are legitimate races, so I assume id might
get corrupted? "id" is actually just ""last_used"" in some contexts,
and at the path where last_used gets manipulated, KCSAN reports these races.

I'm not sure if this is the right approach though, maybe we should handle it
differently other than just return?

Signed-off-by: Roi L <[email protected]>
---
 drivers/virtio/virtio_ring.c | 2 ++
 1 file changed, 2 insertions(+)

diff --git a/drivers/virtio/virtio_ring.c b/drivers/virtio/virtio_ring.c
index b438dc2ce1b8..1d99b75f3bd7 100644
--- a/drivers/virtio/virtio_ring.c
+++ b/drivers/virtio/virtio_ring.c
@@ -2025,6 +2025,8 @@ static void detach_buf_packed_in_order(struct vring_virtqueue *vq,
 	unsigned int i, curr;
 
 	state = &vq->packed.desc_state[id];
+	if (unlikely(!state))
+		return;
 
 	/* Clear data ptr. */
 	state->data = NULL;
-- 
2.55.0
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.