Re: [PATCH v4 0/1] Fix buffer over-read in cca_cipher2protkey
Vasily Gorbik <[email protected]>
| Newsgroups | org.kernel.vger.linux-s390 |
|---|---|
| Message-ID | <[email protected]> |
On Wed, Jul 29, 2026 at 01:40:08PM +0200, Harald Freudenberger wrote: > Add validation of both the actual key buffer size and token length > fields in all the cca_check_sec*token() functions. Additionally check > in cca_gencipherkey() for possible underflow with returned key size. > > The CCA token structures contain user-controlled len fields that > were used in operations without proper validation against both the > actual buffer size and minimum token structure size. An attacker > could set this field larger than the actual buffer size, leading to > reading beyond buffer boundaries. This may result in a kernel crash or > exposure of memory via sending this as part of a request down to the > crypto card. Also an attacker could have used a very small len value > and thus enforce a buffer under-run which may produce similar effects > as a over-read. > > So now a key must > - key buf length must be at least sizeof the token struct > - the key len field inside the token must fit into the range of > sizeof key token struct ... key buf length > > Changelog: > v1 - initial version > v2 - extend the length check to all cca_check_sec*token() functions, > also check for min given buffer length and token length field. > v3 - there was still a possibility to under-run the length checks in > function cca_gencipherkey(). Fixed as suggested by Ingo. > v4 - Reviewd-by from Ingo added. > > Harald Freudenberger (1): > s390/zcrypt: Fix buffer over-read in cca_cipher2protkey > > drivers/s390/crypto/pkey_cca.c | 15 +++---- > drivers/s390/crypto/zcrypt_ccamisc.c | 64 +++++++++++++++++++++++----- > drivers/s390/crypto/zcrypt_ccamisc.h | 6 +-- > 3 files changed, 62 insertions(+), 23 deletions(-) Applied, thank you!